The explicit proxy firewall uses the HTTP CONNECT method to direct outbound web traffic through a unified, secure, and compliant egress proxy gateway. This gateway supports native integration with public networks, private networks, and EPG Egress Proxy Gateway (EPG), and applies consistent access control, threat detection, and data protection for both agent and HTTP/HTTPS traffic.
The explicit proxy firewall feature is currently in public preview. More features will be available in future releases.
Feature overview
Configuring clients with an HTTP proxy steers their outbound HTTP/HTTPS traffic to a proxy firewall instance. This instance inspects traffic from connection setup to response delivery before forwarding it to its public or private destination.
Key capabilities include:
Full-lifecycle HTTP/HTTPS inspection: Covers all phases from DNS and TLS inspection to request and response. It supports TLS Man-in-the-Middle (MITM) decryption, domain-based inspection exceptions, and Server Name Indication (SNI) validation to meet encrypted traffic auditing and compliance requirements.
Granular control and threat detection: Allows you to configure access control rules based on criteria such as domain, URL, application, HTTP method, region, and request headers. It also integrates with threat intelligence to identify and block access to known malicious websites.
AI security guardrail and data protection: Inspects requests and responses for AI applications to identify prompt injection attacks and sensitive data risks. It can block or mask the exfiltration of sensitive information.
Unified public and private proxy: The public proxy reuses your existing public NAT gateway or EPG Egress Proxy Gateway for internet access. The private proxy accesses internal services that are reachable through your Virtual Private Cloud (VPC). You can configure specific applications or workloads to use the proxy via environment variables without modifying routing tables.
Key concepts
Before you use the explicit proxy firewall, you must understand the following core concepts and their relationships:
Proxy firewall instance: The smallest deployment unit. It is bound to a VPC, a public NAT gateway, or an egress proxy gateway. It provides public and private egress IP addresses and receives and forwards HTTP proxy traffic.
Instance configuration: A policy orchestration container that defines the default action, application identification settings, associated rule groups, security modules, and header rewrite rules. Multiple instances can share the same configuration.
Access control rule group: A collection of ordered rules that match traffic based on priority and then apply an action, such as Allow, Observe, or Block.
Threat intelligence: Automatically blocks known malicious assets based on URL, IP, and domain intelligence feeds.
AI security guardrail: Invokes AI security guardrail detection templates to assess risks in AI application requests and responses and then applies the corresponding actions.
TLS inspection: Decrypts HTTPS traffic using a Man-in-the-Middle (MITM) approach, allowing the firewall to inspect Layer 7 fields such as URLs and headers. Without TLS inspection, you cannot control HTTPS traffic.
Relationships
A proxy firewall instance must be associated with an instance configuration. The instance configuration, in turn, must be associated with a rule group, threat intelligence policy, or AI security guardrail policy for protection to take effect.
Applicability
Traffic scope: Only applies to outbound HTTP/HTTPS traffic from assets within a VPC.
Creation method
Requires public network access: You can create an instance only through a public NAT gateway or an EPG Egress Proxy Gateway.
Does not require public network access: Create an instance by binding it to a VPC.
Region support
Public/private proxy: China (Beijing), China (Hangzhou), China (Shanghai), China (Hong Kong), and Singapore.
EPG Egress Proxy Gateway: China (Shanghai).
Procedure
Step 1: Create a proxy firewall instance
Log on to the Cloud Firewall console. In the left-side navigation pane, choose .
Select a creation method.
Public/private proxy
Click Create Instance and configure the following parameters.
Parameter
Description
Instance Name and Description
Enter a descriptive name and description for the instance.
Region
Select the region where your public NAT gateway or VPC is located.
Account
The current account is used by default. If you have configured multi-account management, you can select another managed account.
Public Network Access
Select whether your services require access to the public network.
Required: Select a public IP address of the NAT gateway. The Static Public IP Address method is not currently supported.
Not required: Select the VPC to which the firewall is bound.
After you make a selection, configure a vSwitch and security group. You must select two vSwitches and one security group for the corresponding NAT gateway or VPC.
NoteThis security group controls which servers can forward traffic to the firewall. We recommend that you create a dedicated security group that allows traffic only from trusted internal services to prevent unauthorized access to the firewall instance.
Associated Instance Configuration
Proceed to the next step to configure policies, and then associate them here. The firewall is inactive if no policies are associated.
TLS Inspection
Use the switch to enable or disable TLS inspection for this proxy firewall instance. If you enable it, you must select and associate an existing TLS inspection policy.
After you enable TLS inspection, the firewall can inspect the content of HTTPS traffic. To configure a TLS inspection policy, see TLS inspection.
EPG Egress Proxy Gateway
NoteWe recommend that you enable TLS interception configuration for the EPG instance. Otherwise, the firewall will not inspect HTTPS traffic after the proxy firewall instance is created.
Find the created EPG Egress Proxy Gateway instance in the instance list.
In the Actions column, click Create and configure the following parameters.
Parameter
Description
Instance Name and Description
Enter a descriptive name and description for the instance.
Associated Instance Configuration
Proceed to the next step to configure policies, and then associate them here. The firewall is inactive if no policies are associated.
Alternatively, log on to the EPG console, navigate to the Basic Information tab of the target instance, and in the Cloud Firewall Protection section, click Enable Protection to create a proxy firewall instance.
Step 2: Configure and associate policies
By default, an explicit proxy firewall instance provides no protection. To enable protection, you must create and associate policies with your instance.
Create an instance configuration: In the left-side navigation pane of the Cloud Firewall console, choose . Then, click Create Configuration and set the following parameters.
Parameter
Description
Configuration Name and Description
Enter a descriptive name and description for the configuration.
APP-ID Identification
Specifies whether to enable application identification. We recommend that you enable this feature so that the firewall can identify application types, allowing for application-based access control and security inspection.
Traffic Rewrite
Lets you add or delete HTTP request headers. You can configure up to 20 rules. Click Add Rule to add a rule.
Default Action
Sets the action for traffic that does not match any policy.
Allow: Allows the traffic and logs it.
Block: Blocks the traffic, logs it, and returns a block page to the client. Before you select this mode, configure access control policies to allow necessary traffic to avoid disrupting your services.
Associated Rule Group
Click Add Associated Rule Group, select the rule groups you want to apply, and set their priorities. A smaller number indicates a higher priority. After you configure policies in the next step, return here to complete the association.
Security Module
Configure the status of the Threat Intelligence and AI Security Guardrail modules. After you configure these policies in the next step, return here to complete the association.
Create policies: In the left-side navigation pane of the Cloud Firewall console, choose and create policies based on your business requirements.
Access Control Rule Group: Provides granular access control based on traffic characteristics. You can match traffic by using conditions such as IP, port, region, request header, and URI Path, and then configure an action to meet your network and application layer access control needs.
Security Module Policy > Threat Intelligence: Automatically blocks malicious assets based on known threat intelligence. It supports URL, IP, and domain intelligence to protect against known malicious websites, IP addresses, and domains.
Security Module Policy > AI Security Guardrail: Integrates with the AI security guardrail service to protect request and response traffic for AI applications. You can select a detection template to inspect traffic for risks and configure corresponding actions based on the risk level to ensure content security for AI applications.
Access Control Rule Group
Create a rule group: On the Policy Configuration page, go to the Access Control Rule Group tab, click Create Rule Group, and enter a name and description.
Create a rule within a rule group: In the Actions column for the rule group, click Edit. On the Rule Group Details page, click Add Rule and configure the following parameters.
NoteA single rule group can contain up to 1,000 rules.
Parameter
Description
Rule Name and Description
Enter a descriptive name and description for the rule.
Priority
Set a custom priority from 1 to 99,999. A smaller number indicates a higher priority.
Match Conditions
Click Add Match Condition to set the criteria for matching traffic. You can match traffic based on conditions such as IP, port, region, request header, and URI Path. For more information, see Appendix: Match conditions.
A single rule can have up to 5 match conditions.
Multiple match conditions within a rule are joined by a logical AND. Traffic must meet all conditions to match the rule.
Action
Set the action to take when traffic matches the rule.
Allow: Allows the traffic and logs it.
Monitor: Allows the traffic and logs it. After a period of monitoring, you can analyze the logs and change the action to Allow or Block.
Block: Blocks the traffic, logs it, and returns a block page to the client.
Status
Enabled by default. Only enabled policies take effect.
Validity
Always: The policy is permanently active.
Single Time Period: The policy is active within a specified start and end time, after which it automatically expires.
Recurrence: The policy is active on a recurring schedule within a specified date range and time period.
Security Module Policy > Threat Intelligence
On the Policy Configuration page, go to the Security Module Policy tab, select Threat Intelligence, click Create Policy, and configure the following parameters.
Parameter
Description
Policy Name
Enter an easy-to-identify name for the policy.
Status
Enabled by default. Only enabled policies take effect.
Intelligence Type Configuration
Supports URL Intelligence, IP Intelligence, and Domain Intelligence. By default, all intelligence types are disabled. Go to each sub-tab, select the intelligence types you need, and set a custom action.
Monitor: Allows the traffic and logs it. After a period of monitoring, you can analyze the logs and change the action to Block.
Block: Blocks the traffic, logs it, and returns a block page to the client.
Associated Instance Configuration
Select an existing Instance Configuration to associate with the policy. You can also modify this association later on the Instance Configuration page.
Security Module Policy > AI Security Guardrail
On the Policy Configuration page, go to the Security Module Policy tab, select AI Security Guardrail, click Create Policy, and configure the following parameters.
NoteThis policy configuration depends on the AI Security Guardrail service. If you have not activated this service, do so first.
Parameter
Description
Template Name
Enter an easy-to-identify name for the policy.
Status
Enabled by default. Only enabled policies take effect.
Detection Template
Select a detection template from the AI security guardrail service. This template is applied to both request and response inspection.
Risk Level and Action
Configure policies for Request Detection and Response Detection. Set actions for different risk levels as determined by the selected detection template.
Allow: Allows the traffic and logs it.
Monitor: Allows the traffic and logs it. The system appends a risk alert to the end of the response content to notify the client of the risk. After a period of monitoring, you can analyze the logs and change the action to Allow or Block.
Block: Blocks the traffic and logs it. The system replaces the response content with a risk alert, preventing the client from receiving the original content.
Associated Instance Configuration
Select an existing Instance Configuration to associate with the policy. You can also modify this association later on the Instance Configuration page.
Step 3: Establish policy associations
After you create the explicit proxy firewall instance, Instance Configuration, and policies, you must ensure they are correctly associated. Otherwise, the policies will not take effect.
Associate the proxy instance with an instance configuration: Go to the Proxy Instance page, find the target proxy instance, and click Edit in the Actions column. Verify that the correct Associated Instance Configuration is selected in the Instance Configuration field.
Associate the instance configuration with policies: Go to the Instance Configuration page, find the target instance configuration, and click Edit in the Actions column. On the Policy Configuration tab, verify that the Associated Rule Group, Threat Intelligence, and AI Security Guardrail policies are correctly associated.
Step 4: Connect clients
After you create a proxy firewall instance, the system automatically creates an endpoint in the vSwitches associated with the instance and generates a fully qualified domain name (FQDN) as the proxy listener address. Go to the Proxy Instance page, click the ID of the target instance to view its details, and complete the following configurations:
View the Public Egress IP and Private Egress IP Address. Add these addresses to the allowlist of the security group, firewall, or NAT boundary firewall on the destination server to ensure that traffic forwarded by the proxy firewall can access the server.
View the Listener Address (FQDN). Clients must use this FQDN in their proxy settings to route traffic through the proxy firewall. For specific configuration methods, see Connect clients to an explicit proxy firewall.
When you create a firewall instance by binding it to a public NAT gateway, the firewall automatically maintains SNAT entries to translate the private egress IP address to the bound public egress IP address. Do not manually manage SNAT entries in the public NAT gateway console, as this may disrupt public network access.
Routine operations
Manage proxy firewall instances
Go to the Proxy Instance page to perform the following actions:
View overview: The information bar at the top of the page displays an overview of your proxy firewall, including statistics on the number of proxy instances, instance configurations, and policy configurations.
Control protection status: New instances are enabled by default. An instance is active only when the switch in the Protection Status column is enabled. You can use this switch to manually start or stop protection.
Edit an instance: Click Actions in the Edit column to modify the Associated Instance Configuration and the TLS Inspection settings.
Delete an instance: Click Actions in the Delete column to remove the proxy firewall instance. After deletion, all connected traffic is immediately interrupted, which may affect your services. Before proceeding, confirm this action will not disrupt your services.
Manage instance configurations
Go to the Instance Configuration page to perform the following actions:
Edit a configuration: Click Actions in the Edit column for a target configuration to modify its basic information and policy settings.
Delete a configuration: Click Actions in the Delete column for a target configuration to remove it.
Manage policies
Go to the Policy Configuration page to perform the following actions for Access Control Rule Group, Threat Intelligence, and AI Security Guardrail policies:
Edit a policy: Click Actions in the Edit column.
Delete a policy: Click Actions in the Delete column.
Quotas and limits
Traffic that passes through the explicit proxy firewall does not support EIP affinity.
The default bandwidth for a single explicit proxy firewall instance is 5 Gbps. To request higher bandwidth, contact your account manager.
For proxy firewall instances with TLS inspection enabled, sensitive information such as API keys in request headers is masked after HTTPS traffic is decrypted. However, other Authorization information might still be visible.
You can create a maximum of 100 Access Control Rule Group. Each rule group can contain up to 1,000 rules.
You can create a maximum of 10 policies within each Security Module Policy.
Appendix: Match conditions
Match field | Supported operators | Description |
Source IP |
| Select an address book or manually enter source IP CIDR blocks. Separate multiple values with line breaks. |
Region (Country/Province) |
| Select the destination region of the traffic. Both domestic and international regions are supported. |
Application ID |
| Select the application types to match from the application category list. |
SNI |
| Enter the Server Name Indication value from the TLS handshake. Separate multiple values with line breaks. |
Destination IP |
| Select an address book or manually enter destination IP CIDR blocks. Separate multiple values with line breaks. |
Destination Port |
| Enter a destination port number or port range. Separate multiple values with line breaks. The port range format is |
Full URL |
| Enter the full request URL. Separate multiple values with line breaks. For example, |
URI Path |
| Enter the URI path of the request. Separate multiple values with line breaks. For example, |
Filename |
| Enter the filename from the request URL. Separate multiple values with line breaks. For example, |
File Name Extension |
| Enter the file extension. Separate multiple values with line breaks. For example, |
HTTP Method (Http-Method) |
| Select an HTTP request method from the list. |
Request Header |
| Enter a request header field name and its value to match. |
Query Parameter |
| Enter a URL query parameter name and its value to match. |
Cookie Name |
| Enter a cookie name and its value to match. |