All Products
Search
Document Center

Cloud Firewall:Connect clients to an explicit proxy firewall

Last Updated:Sep 18, 2026

This topic explains how to configure clients to forward HTTP and HTTPS traffic through an explicit proxy firewall. It covers configurations for various environments, including Linux curl, Linux environment variables, the Windows system proxy, and agent-based tools like OpenCode.

Note

The configurations described in this topic apply only to application-layer proxies. Only applications that recognize these settings will forward traffic through the explicit proxy firewall. To route all TCP/UDP traffic through a proxy, use the Internet Firewall solution instead.

Prerequisites

  • Configure an explicit proxy firewall in the Cloud Firewall console. For instructions, see explicit proxy firewall.

  • Obtain and record the required proxy information by clicking a proxy instance ID on the Explicit Proxy > Proxy Instance page.

Example proxy information

The examples in this topic use a sample explicit proxy address. Replace it with the address from your actual environment.

Parameter

Example value

Proxy instance listening address

fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com

Proxy instance listening port

10001

Proxy protocol

HTTP proxy

Proxy URL

http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001

General placeholders:

Placeholder

Description

<proxy_host>

The proxy address, for example, fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com

<proxy_port>

The proxy port, for example, 10001

<proxy_protocol>

The protocol prefix in the proxy address. This indicates the protocol used by the client to connect to the proxy. Currently, only http:// is supported. https:// is not supported.

Proxy environment variable fields:

  • HTTP_PROXY / http_proxy: The http_proxy environment variable specifies the proxy for HTTP target requests. The http:// prefix in the proxy address indicates that the client connects to the proxy over the HTTP protocol.

  • HTTPS_PROXY / https_proxy: The https_proxy environment variable specifies a proxy for HTTPS target requests. However, the protocol for the proxy address itself currently supports only http://, which means the client connects to the proxy by using the HTTP protocol. The https:// protocol, which means the client connects to the proxy by using TLS, is not supported.

  • NO_PROXY / no_proxy: A comma-separated list of hostnames or IP addresses to exclude from proxying. Common values include localhost,127.0.0.1,::1.

Specify a proxy in Linux with curl

Important

A client can connect to a proxy instance in the following ways, depending on its network location:

  • Same VPC: The client connects directly using the DNS domain name of the proxy instance as the proxy address.

  • Cross-VPC: The client can also use the DNS domain name of the proxy instance as its proxy address, provided that the proxy instance is routable from the client. The domain name resolves to the private IP address of the proxy instance.

Access an HTTP site

curl -sS -v -m 20 -x http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001 http://www.aliyun.com

Generic command:

curl -x http://<proxy_host>:<proxy_port> http://example.com

Access an HTTPS site

curl -sS -v -m 20 -x http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001 https://example.com

Generic command:

curl -x http://<proxy_host>:<proxy_port> https://example.com

Inspect the proxy connection process

curl -v -x http://<proxy_host>:<proxy_port> https://example.com

If HTTPS traffic is successfully routed through the proxy, the output typically includes the following lines:

CONNECT example.com:443 HTTP/1.1
HTTP/1.1 200 Connection established

Configure proxy with environment variables in Linux

Configure a temporary shell proxy

This configuration applies only to the current shell session and its child processes.

export http_proxy="http://<proxy_host>:<proxy_port>"
export https_proxy="http://<proxy_host>:<proxy_port>"
export HTTP_PROXY="http://<proxy_host>:<proxy_port>"
export HTTPS_PROXY="http://<proxy_host>:<proxy_port>"

It is recommended to also configure addresses to bypass the proxy:

export no_proxy="localhost,127.0.0.1,::1"
export NO_PROXY="localhost,127.0.0.1,::1"

Common bypass addresses:

Address

Description

localhost, 127.0.0.1, ::1

Localhost access

Verify the configuration:

curl -v https://example.com

Configure a permanent user proxy

  1. Edit the shell configuration file:

    vim ~/.bashrc # For Bash users
    vim ~/.zshrc # For Zsh users
  2. Append the following lines to the file:

    export http_proxy="http://<proxy_host>:<proxy_port>"
    export https_proxy="http://<proxy_host>:<proxy_port>"
    export HTTP_PROXY="http://<proxy_host>:<proxy_port>"
    export HTTPS_PROXY="http://<proxy_host>:<proxy_port>"
    export no_proxy="localhost,127.0.0.1,::1"
    export NO_PROXY="localhost,127.0.0.1,::1"
  3. Apply the changes:

    source ~/.bashrc # For Bash users
    source ~/.zshrc  # For Zsh users

Configure a permanent, system-wide proxy

  1. Create a system-wide proxy configuration file:

    sudo vim /etc/profile.d/proxy.sh
  2. Add the following content:

    export http_proxy="http://<proxy_host>:<proxy_port>"
    export https_proxy="http://<proxy_host>:<proxy_port>"
    export HTTP_PROXY="http://<proxy_host>:<proxy_port>"
    export HTTPS_PROXY="http://<proxy_host>:<proxy_port>"
    export no_proxy="localhost,127.0.0.1,::1"
    export NO_PROXY="localhost,127.0.0.1,::1"
  3. To apply the changes, log out and log back in, or run the following command for the current session:

    source /etc/profile.d/proxy.sh

Configure proxy for agent or OpenCode

When using an agent, verify which proxy settings it reads, as this can vary.

Start an agent in an interactive CLI

The following example uses the OpenCode interactive CLI:

export HTTP_PROXY=http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001; export HTTPS_PROXY=http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001; timeout 300 opencode run --auto 'what is the weather in Hangzhou tomorrow'

OpenCode reads system environment variables. If you have already configured the variables as described in the Linux environment variables section, you can start the interactive session directly. The agent traffic will automatically be routed through the explicit proxy:

timeout 300 opencode run --auto 'what is the weather in Hangzhou tomorrow'

Configure the system proxy in Windows

Configure the proxy in Windows Settings

These steps are for Windows Server 2025. The procedure might differ on other Windows versions.

  1. Open Settings.

  2. Go to Network & Internet.

  3. Go to Proxy.

  4. Under Manual proxy setup, click Set up.

  5. Enable Use a proxy server.

  6. Set Address to <proxy_host>.

  7. Set Port to <proxy_port>.

  8. In the Use the proxy server except for addresses that start with the following entries box, enter exception addresses, such as localhost;127.0.0.1;::1.

  9. Click Save.

This configuration applies to web browsers and other applications that respect the system proxy settings.