All Products
Search
Document Center

Cloud Firewall:Explicit proxy firewall

Last Updated:Sep 18, 2026

The explicit proxy firewall uses the HTTP CONNECT method to direct outbound web traffic through a unified, secure, and compliant egress proxy gateway. This gateway supports native integration with public networks, private networks, and EPG Egress Proxy Gateway (EPG), and applies consistent access control, threat detection, and data protection for both agent and HTTP/HTTPS traffic.

Note

The explicit proxy firewall feature is currently in public preview. More features will be available in future releases.

Feature overview

Configuring clients with an HTTP proxy steers their outbound HTTP/HTTPS traffic to a proxy firewall instance. This instance inspects traffic from connection setup to response delivery before forwarding it to its public or private destination.

image

Key capabilities include:

  • Full-lifecycle HTTP/HTTPS inspection: Covers all phases from DNS and TLS inspection to request and response. It supports TLS Man-in-the-Middle (MITM) decryption, domain-based inspection exceptions, and Server Name Indication (SNI) validation to meet encrypted traffic auditing and compliance requirements.

  • Granular control and threat detection: Allows you to configure access control rules based on criteria such as domain, URL, application, HTTP method, region, and request headers. It also integrates with threat intelligence to identify and block access to known malicious websites.

  • AI security guardrail and data protection: Inspects requests and responses for AI applications to identify prompt injection attacks and sensitive data risks. It can block or mask the exfiltration of sensitive information.

  • Unified public and private proxy: The public proxy reuses your existing public NAT gateway or EPG Egress Proxy Gateway for internet access. The private proxy accesses internal services that are reachable through your Virtual Private Cloud (VPC). You can configure specific applications or workloads to use the proxy via environment variables without modifying routing tables.

Key concepts

Before you use the explicit proxy firewall, you must understand the following core concepts and their relationships:

  • Proxy firewall instance: The smallest deployment unit. It is bound to a VPC, a public NAT gateway, or an egress proxy gateway. It provides public and private egress IP addresses and receives and forwards HTTP proxy traffic.

  • Instance configuration: A policy orchestration container that defines the default action, application identification settings, associated rule groups, security modules, and header rewrite rules. Multiple instances can share the same configuration.

  • Access control rule group: A collection of ordered rules that match traffic based on priority and then apply an action, such as Allow, Observe, or Block.

  • Threat intelligence: Automatically blocks known malicious assets based on URL, IP, and domain intelligence feeds.

  • AI security guardrail: Invokes AI security guardrail detection templates to assess risks in AI application requests and responses and then applies the corresponding actions.

  • TLS inspection: Decrypts HTTPS traffic using a Man-in-the-Middle (MITM) approach, allowing the firewall to inspect Layer 7 fields such as URLs and headers. Without TLS inspection, you cannot control HTTPS traffic.

Relationships

A proxy firewall instance must be associated with an instance configuration. The instance configuration, in turn, must be associated with a rule group, threat intelligence policy, or AI security guardrail policy for protection to take effect.

Applicability

  • Traffic scope: Only applies to outbound HTTP/HTTPS traffic from assets within a VPC.

  • Creation method

    • Requires public network access: You can create an instance only through a public NAT gateway or an EPG Egress Proxy Gateway.

    • Does not require public network access: Create an instance by binding it to a VPC.

  • Region support

    • Public/private proxy: China (Beijing), China (Hangzhou), China (Shanghai), China (Hong Kong), and Singapore.

    • EPG Egress Proxy Gateway: China (Shanghai).

Procedure

Step 1: Create a proxy firewall instance

  1. Log on to the Cloud Firewall console. In the left-side navigation pane, choose Explicit Proxy > Proxy Instance.

  2. Select a creation method.

    Public/private proxy

    Click Create Instance and configure the following parameters.

    Parameter

    Description

    Instance Name and Description

    Enter a descriptive name and description for the instance.

    Region

    Select the region where your public NAT gateway or VPC is located.

    Account

    The current account is used by default. If you have configured multi-account management, you can select another managed account.

    Public Network Access

    Select whether your services require access to the public network.

    • Required: Select a public IP address of the NAT gateway. The Static Public IP Address method is not currently supported.

    • Not required: Select the VPC to which the firewall is bound.

    After you make a selection, configure a vSwitch and security group. You must select two vSwitches and one security group for the corresponding NAT gateway or VPC.

    Note

    This security group controls which servers can forward traffic to the firewall. We recommend that you create a dedicated security group that allows traffic only from trusted internal services to prevent unauthorized access to the firewall instance.

    Associated Instance Configuration

    Proceed to the next step to configure policies, and then associate them here. The firewall is inactive if no policies are associated.

    TLS Inspection

    Use the switch to enable or disable TLS inspection for this proxy firewall instance. If you enable it, you must select and associate an existing TLS inspection policy.

    After you enable TLS inspection, the firewall can inspect the content of HTTPS traffic. To configure a TLS inspection policy, see TLS inspection.

    EPG Egress Proxy Gateway

    Note

    We recommend that you enable TLS interception configuration for the EPG instance. Otherwise, the firewall will not inspect HTTPS traffic after the proxy firewall instance is created.

    1. Find the created EPG Egress Proxy Gateway instance in the instance list.

    2. In the Actions column, click Create and configure the following parameters.

      Parameter

      Description

      Instance Name and Description

      Enter a descriptive name and description for the instance.

      Associated Instance Configuration

      Proceed to the next step to configure policies, and then associate them here. The firewall is inactive if no policies are associated.

    Alternatively, log on to the EPG console, navigate to the Basic Information tab of the target instance, and in the Cloud Firewall Protection section, click Enable Protection to create a proxy firewall instance.

Step 2: Configure and associate policies

By default, an explicit proxy firewall instance provides no protection. To enable protection, you must create and associate policies with your instance.

  1. Create an instance configuration: In the left-side navigation pane of the Cloud Firewall console, choose Explicit Proxy > Instance Configuration. Then, click Create Configuration and set the following parameters.

    Parameter

    Description

    Configuration Name and Description

    Enter a descriptive name and description for the configuration.

    APP-ID Identification

    Specifies whether to enable application identification. We recommend that you enable this feature so that the firewall can identify application types, allowing for application-based access control and security inspection.

    Traffic Rewrite

    Lets you add or delete HTTP request headers. You can configure up to 20 rules. Click Add Rule to add a rule.

    Default Action

    Sets the action for traffic that does not match any policy.

    • Allow: Allows the traffic and logs it.

    • Block: Blocks the traffic, logs it, and returns a block page to the client. Before you select this mode, configure access control policies to allow necessary traffic to avoid disrupting your services.

    Associated Rule Group

    Click Add Associated Rule Group, select the rule groups you want to apply, and set their priorities. A smaller number indicates a higher priority. After you configure policies in the next step, return here to complete the association.

    Security Module

    Configure the status of the Threat Intelligence and AI Security Guardrail modules. After you configure these policies in the next step, return here to complete the association.

  2. Create policies: In the left-side navigation pane of the Cloud Firewall console, choose Explicit Proxy > Policy Configuration and create policies based on your business requirements.

    • Access Control Rule Group: Provides granular access control based on traffic characteristics. You can match traffic by using conditions such as IP, port, region, request header, and URI Path, and then configure an action to meet your network and application layer access control needs.

    • Security Module Policy > Threat Intelligence: Automatically blocks malicious assets based on known threat intelligence. It supports URL, IP, and domain intelligence to protect against known malicious websites, IP addresses, and domains.

    • Security Module Policy > AI Security Guardrail: Integrates with the AI security guardrail service to protect request and response traffic for AI applications. You can select a detection template to inspect traffic for risks and configure corresponding actions based on the risk level to ensure content security for AI applications.

    Access Control Rule Group

    1. Create a rule group: On the Policy Configuration page, go to the Access Control Rule Group tab, click Create Rule Group, and enter a name and description.

    2. Create a rule within a rule group: In the Actions column for the rule group, click Edit. On the Rule Group Details page, click Add Rule and configure the following parameters.

      Note

      A single rule group can contain up to 1,000 rules.

      Parameter

      Description

      Rule Name and Description

      Enter a descriptive name and description for the rule.

      Priority

      Set a custom priority from 1 to 99,999. A smaller number indicates a higher priority.

      Match Conditions

      Click Add Match Condition to set the criteria for matching traffic. You can match traffic based on conditions such as IP, port, region, request header, and URI Path. For more information, see Appendix: Match conditions.

      • A single rule can have up to 5 match conditions.

      • Multiple match conditions within a rule are joined by a logical AND. Traffic must meet all conditions to match the rule.

      Action

      Set the action to take when traffic matches the rule.

      • Allow: Allows the traffic and logs it.

      • Monitor: Allows the traffic and logs it. After a period of monitoring, you can analyze the logs and change the action to Allow or Block.

      • Block: Blocks the traffic, logs it, and returns a block page to the client.

      Status

      Enabled by default. Only enabled policies take effect.

      Validity

      • Always: The policy is permanently active.

      • Single Time Period: The policy is active within a specified start and end time, after which it automatically expires.

      • Recurrence: The policy is active on a recurring schedule within a specified date range and time period.

    Security Module Policy > Threat Intelligence

    On the Policy Configuration page, go to the Security Module Policy tab, select Threat Intelligence, click Create Policy, and configure the following parameters.

    Parameter

    Description

    Policy Name

    Enter an easy-to-identify name for the policy.

    Status

    Enabled by default. Only enabled policies take effect.

    Intelligence Type Configuration

    Supports URL Intelligence, IP Intelligence, and Domain Intelligence. By default, all intelligence types are disabled. Go to each sub-tab, select the intelligence types you need, and set a custom action.

    • Monitor: Allows the traffic and logs it. After a period of monitoring, you can analyze the logs and change the action to Block.

    • Block: Blocks the traffic, logs it, and returns a block page to the client.

    Associated Instance Configuration

    Select an existing Instance Configuration to associate with the policy. You can also modify this association later on the Instance Configuration page.

    Security Module Policy > AI Security Guardrail

    On the Policy Configuration page, go to the Security Module Policy tab, select AI Security Guardrail, click Create Policy, and configure the following parameters.

    Note

    This policy configuration depends on the AI Security Guardrail service. If you have not activated this service, do so first.

    Parameter

    Description

    Template Name

    Enter an easy-to-identify name for the policy.

    Status

    Enabled by default. Only enabled policies take effect.

    Detection Template

    Select a detection template from the AI security guardrail service. This template is applied to both request and response inspection.

    Risk Level and Action

    Configure policies for Request Detection and Response Detection. Set actions for different risk levels as determined by the selected detection template.

    • Allow: Allows the traffic and logs it.

    • Monitor: Allows the traffic and logs it. The system appends a risk alert to the end of the response content to notify the client of the risk. After a period of monitoring, you can analyze the logs and change the action to Allow or Block.

    • Block: Blocks the traffic and logs it. The system replaces the response content with a risk alert, preventing the client from receiving the original content.

    Associated Instance Configuration

    Select an existing Instance Configuration to associate with the policy. You can also modify this association later on the Instance Configuration page.

Step 3: Establish policy associations

After you create the explicit proxy firewall instance, Instance Configuration, and policies, you must ensure they are correctly associated. Otherwise, the policies will not take effect.

  1. Associate the proxy instance with an instance configuration: Go to the Proxy Instance page, find the target proxy instance, and click Edit in the Actions column. Verify that the correct Associated Instance Configuration is selected in the Instance Configuration field.

  2. Associate the instance configuration with policies: Go to the Instance Configuration page, find the target instance configuration, and click Edit in the Actions column. On the Policy Configuration tab, verify that the Associated Rule Group, Threat Intelligence, and AI Security Guardrail policies are correctly associated.

Step 4: Connect clients

After you create a proxy firewall instance, the system automatically creates an endpoint in the vSwitches associated with the instance and generates a fully qualified domain name (FQDN) as the proxy listener address. Go to the Proxy Instance page, click the ID of the target instance to view its details, and complete the following configurations:

  • View the Public Egress IP and Private Egress IP Address. Add these addresses to the allowlist of the security group, firewall, or NAT boundary firewall on the destination server to ensure that traffic forwarded by the proxy firewall can access the server.

  • View the Listener Address (FQDN). Clients must use this FQDN in their proxy settings to route traffic through the proxy firewall. For specific configuration methods, see Connect clients to an explicit proxy firewall.

Note

When you create a firewall instance by binding it to a public NAT gateway, the firewall automatically maintains SNAT entries to translate the private egress IP address to the bound public egress IP address. Do not manually manage SNAT entries in the public NAT gateway console, as this may disrupt public network access.

Routine operations

Manage proxy firewall instances

Go to the Proxy Instance page to perform the following actions:

  • View overview: The information bar at the top of the page displays an overview of your proxy firewall, including statistics on the number of proxy instances, instance configurations, and policy configurations.

  • Control protection status: New instances are enabled by default. An instance is active only when the switch in the Protection Status column is enabled. You can use this switch to manually start or stop protection.

  • Edit an instance: Click Actions in the Edit column to modify the Associated Instance Configuration and the TLS Inspection settings.

  • Delete an instance: Click Actions in the Delete column to remove the proxy firewall instance. After deletion, all connected traffic is immediately interrupted, which may affect your services. Before proceeding, confirm this action will not disrupt your services.

Manage instance configurations

Go to the Instance Configuration page to perform the following actions:

  • Edit a configuration: Click Actions in the Edit column for a target configuration to modify its basic information and policy settings.

  • Delete a configuration: Click Actions in the Delete column for a target configuration to remove it.

Manage policies

Go to the Policy Configuration page to perform the following actions for Access Control Rule Group, Threat Intelligence, and AI Security Guardrail policies:

  • Edit a policy: Click Actions in the Edit column.

  • Delete a policy: Click Actions in the Delete column.

Quotas and limits

  • Traffic that passes through the explicit proxy firewall does not support EIP affinity.

  • The default bandwidth for a single explicit proxy firewall instance is 5 Gbps. To request higher bandwidth, contact your account manager.

  • For proxy firewall instances with TLS inspection enabled, sensitive information such as API keys in request headers is masked after HTTPS traffic is decrypted. However, other Authorization information might still be visible.

  • You can create a maximum of 100 Access Control Rule Group. Each rule group can contain up to 1,000 rules.

  • You can create a maximum of 10 policies within each Security Module Policy.

Appendix: Match conditions

Match field

Supported operators

Description

Source IP

  • IP/CIDR Block Match

  • No IP/CIDR Block Match

  • Address Book Hit

  • Address Book Not Matched

Select an address book or manually enter source IP CIDR blocks. Separate multiple values with line breaks.

Region (Country/Province)

  • Is One Of

  • Does Not Match Any

Select the destination region of the traffic. Both domestic and international regions are supported.

Application ID

  • Contains One Of

  • Does Not Contain Any

Select the application types to match from the application category list.

SNI

  • Equals

  • Is One Of

  • Suffix Match

  • Regex Match

Enter the Server Name Indication value from the TLS handshake. Separate multiple values with line breaks.

Destination IP

  • IP/CIDR Block Match

  • No IP/CIDR Block Match

  • Address Book Hit

  • Address Book Not Matched

Select an address book or manually enter destination IP CIDR blocks. Separate multiple values with line breaks.

Destination Port

  • Equals

  • Not Equal To

  • Is One Of

  • Does Not Match Any

  • In Port Range

  • Not in Port Range

Enter a destination port number or port range. Separate multiple values with line breaks.

The port range format is start_port/end_port, for example, 80/100.

Full URL

  • Equals

  • Is One Of

  • Contains

  • Prefix Match

  • Regex Match

Enter the full request URL. Separate multiple values with line breaks. For example, https://www.example.com/path/index.html?key=value.

URI Path

  • Equals

  • Is One Of

  • Contains

  • Prefix Match

  • Regex Match

Enter the URI path of the request. Separate multiple values with line breaks. For example, /path/index.html or /api/users.

Filename

  • Equals

  • Is One Of

  • Suffix Match

  • Regex Match

Enter the filename from the request URL. Separate multiple values with line breaks. For example, index.html or report.pdf.

File Name Extension

  • Equals

  • Is One Of

  • Does Not Match Any

Enter the file extension. Separate multiple values with line breaks. For example, html or exe.

HTTP Method (Http-Method)

  • Equals

  • Not Equal To

  • Is One Of

Select an HTTP request method from the list.

Request Header

  • Equals

  • Contains

  • Regex Match

  • Field Exists

  • Field Does Not Exist

Enter a request header field name and its value to match.

Query Parameter

  • Equals

  • Contains

  • Regex Match

  • Field Exists

  • Field Does Not Exist

Enter a URL query parameter name and its value to match.

Cookie Name

  • Equals

  • Contains

  • Regex Match

  • Field Exists

  • Field Does Not Exist

Enter a cookie name and its value to match.