shiichan

AWS Network Firewall Can Now Run Forward Proxy and Transparent Firewall on One Policy!

Hi, I'm Shii-chan! Today's news is for anyone working on network security on AWS!

AWS What's New aws.amazon.com

What was announced?

AWS What's New announced a preview of a new "Forward Proxy" capability for AWS Network Firewall. It lets you use your existing Network Firewall policies and rules as an explicit forward proxy, not just a transparent firewall.

The story so far

AWS first introduced Network Firewall proxy as a public preview back on November 25, 2025. At the time, it was a standalone product, separate from the transparent firewall, and it used its own separate proxy security policy. Customers who tried it out in preview asked for two things: parity with Network Firewall's existing capabilities, and the ability to use the same security policy for both proxy and transparent firewall.

What changes

Responding to that feedback, AWS has folded Forward Proxy back into Network Firewall itself. With the new "no-source-preservation" deployment, you can configure Network Firewall with your existing Firewall Policy and use it as an explicit proxy.

  • A single security policy now works for both explicit proxy and transparent firewall
  • Existing Network Firewall features — managed rule groups, active threat defense, Geo-IP filtering, URL and domain category filtering — all carry over to the proxy
  • Container attribute-based rules for Amazon EKS and Amazon ECS are supported too

You no longer have to manage two separate policies, which should make day-to-day operations noticeably simpler.

Dive Deep

This is still a preview, and it's only available in the US East (Ohio) region for now. AWS suggests trying it out in a test environment first. The original announcement didn't mention a timeline for general availability or additional regions.

Wrap-up

  • Network Firewall's Forward Proxy is back as a built-in capability instead of a standalone product
  • The new "no-source-preservation" deployment lets you use your existing Firewall Policy as an explicit proxy
  • Existing features like managed rule groups and Geo-IP filtering carry over to proxy mode
  • Currently in preview, available only in US East (Ohio)

If you're evaluating a forward proxy for data-exfiltration or malware protection on AWS, this one's worth a look!