Amazon 2026-08-06

Reintroducing Network Firewall Proxy for Secure Egress Connectivity

内容摘要

AWS is re-introducing the explicit proxy as a capability of AWS Network Firewall rather than as a standalone product. With this change, the explicit proxy inherits everything Network Firewall already offers, and you can use the same security policy, and even the same firewall, for both transparent firewalling and explicit proxying. There is no second rule language to learn, no duplicate policy to keep in sync, and no separate product to operate. Network Firewall is introducing a new deployment mode called no-source-preservation. In this mode, the firewall is attached to a NAT Gateway. The Firewall filters the traffic, masks the original source of the filtered traffic and uses the IP address of the attached NAT Gateway to communicate with the upstream destination on the client's behalf. Because the explicit proxy is now a function of Network Firewall, it supports the full breadth of Network Firewall capabilities including flexible stateful and stateless rules engine with Suricata-compatible rules for Layer 3 through Layer 7 filtering and deep packet inspection, intrusion detection and prevention (IDS/IPS), AWS managed rule groups, active threat defense powered by Amazon threat intelligence, geographic IP filtering, URL and domain category filtering, TLS inspection, and container attribute-based rules for Amazon EKS and Amazon ECS. This unified approach enables centralized egress security with a single policy model.
来源: 凤凰网
查看原文 →

觉得这篇分析有用?

每周收到3-5条AI基础设施关键信号 →

💬 评论 (0)