Securing Egress Architectures with Network Firewall Proxy | Amazon Web Services

Securing Egress Architectures with Network Firewall Proxy | Amazon Web Services

Customers who control access out of their AWS environments using self-managed proxies often find it challenging to deploy, scale, and patch their EC2 or container-based proxy fleets. With the recent launch of AWS Network Firewall proxy preview, AWS is taking over the heavy lifting of proxy management and deployment, allowing customers to focus on just the security policies that control outbound access from their VPCs.

In this blog post, we cover the workings of the proxy along with the steps to set it up. The post will also discuss the network connectivity options for proxy and various architectural patterns. The proxy filters traffic before it’s allowed to reach destinations on the Internet, in AWS, or even on-premises.

Proxy Connectivity Components

Network Firewall proxy is directly integrated with the NAT Gateway service that runs inside the VPC and takes care of IP address translation for outbound traffic. Your applications can access the proxy…

https://aws.amazon.com/blogs/networking-and-content-delivery/securing-egress-architectures-with-network-firewall-proxy/