Skip to content

NKCODE TECH GEEK ZONE

  • RSS - Posts
Menu
  • Home
  • Cloud
    • Azure
    • Alibaba
    • AWS
  • Hardware
  • Linux
  • Network
  • Security
  • Windows Client / Servers
    • SQL
    • Windows Client OS
      • Windows 10
    • Windows Servers
      • Windows 2008R2
      • Windows Server 2012R2
      • Windows Server 2016
      • Windows Server 2019
  • VMWARE
  • Free Tools
  • About Me
    • Disclaimer
Menu

Azure Firewall Explicit Proxy: Architecture, Configuration Guide, and Enterprise Deployment

Posted on October 3, 2026

Introduction

As organizations migrate workloads to Microsoft Azure, controlling outbound internet traffic has become an essential part of their cloud security strategy. Organizations need visibility into outbound connections, centralized traffic filtering, application-level access control, and detailed logging to meet security and compliance requirements.

Azure Firewall Explicit Proxy provides a way to address these requirements by allowing applications, virtual machines, and other proxy-aware clients to send HTTP and HTTPS traffic directly to Azure Firewall using its private IP address.

Unlike traditional transparent firewall deployments, which rely on User Defined Routes (UDRs) to direct traffic through the firewall, Explicit Proxy allows applications to specify Azure Firewall as their forward proxy. This enables centralized outbound traffic control without requiring UDR-based redirection for those proxy-configured connections.

This article explains Azure Firewall Explicit Proxy, its architecture, configuration using the Azure portal and Azure CLI, client-side proxy settings, security considerations, monitoring, and troubleshooting.

1. What is Azure Firewall Explicit Proxy?

Azure Firewall Explicit Proxy is a forward proxy capability that allows HTTP and HTTPS-aware applications to connect to Azure Firewall through a configured proxy address.

In a conventional transparent firewall deployment, network traffic is routed through the firewall using UDRs. The client does not need to know that a firewall is intercepting its traffic.

With Explicit Proxy, the application is explicitly configured to use the firewall’s private IP address and designated proxy port.

Transparent proxy vs. Explicit Proxy

Feature

Transparent firewall

Explicit Proxy

Client configuration

Not required

Required

Traffic steering

Typically uses UDRs

Application proxy settings

Protocol support

Depends on firewall rules and configuration

HTTP and HTTPS

Application awareness

No proxy configuration needed

Proxy-aware application

Centralized filtering

Yes

Yes, through application rules

PAC file support

Not applicable to transparent routing

Supported

Application-level proxy selection

No

Yes

Azure Firewall Explicit Proxy is configured through an associated Firewall Policy and is supported by Azure Firewall Standard and Premium.

2. Azure Firewall Explicit Proxy Architecture

The following architecture illustrates how workload applications connect to Azure Firewall through an explicit proxy endpoint, how firewall policy controls outbound access, and how an optional Proxy Auto-Configuration (PAC) file can distribute client proxy settings.

Architecture components

  • Workload subnet: Contains Windows and Linux virtual machines, application servers, and proxy-aware applications.

  • Azure Virtual Network (VNet): Provides private connectivity between workloads and Azure Firewall.

  • Azure Firewall: Receives explicit HTTP/HTTPS proxy requests on its configured private IP address and proxy ports.

  • Firewall Policy: Defines application rules, allowed destination FQDNs, protocols, and traffic governance.

  • Azure Blob Storage (optional): Hosts a PAC file that clients can use to determine which traffic should go through the proxy.

  • Internet and SaaS applications: External destinations such as websites, Microsoft 365, and other approved cloud services.

  • Azure Monitor: Collects diagnostic and application rule logs for visibility, auditing, and troubleshooting.

Traffic flow

  1. A workload application is configured to use Azure Firewall’s private IP and explicit proxy port, either manually or through a PAC file.
  2. The application sends an HTTP request or HTTPS CONNECT request to the proxy listener.
  3. Azure Firewall evaluates the request against the associated Firewall Policy and application rules.
  4. If the destination and protocol are permitted, Azure Firewall forwards the request to the external destination.
  5. The response returns through Azure Firewall to the originating application, while diagnostic logs provide visibility into the connection.

Unlike transparent traffic interception, only applications configured to use the explicit proxy follow this path. Other traffic requires its own routing and security controls.

3. Prerequisites

Before configuring Azure Firewall Explicit Proxy, ensure that the following components are available.

Component

Requirement

Azure subscription

Active subscription with deployment permissions

Azure Firewall

Standard or Premium

Firewall Policy

Associated with the firewall

Virtual Network

Deployed with workload connectivity

Proxy-aware client

Browser, application, or operating system supporting HTTP/HTTPS proxy

Application rules

Configured to allow the required destinations

Azure Storage

Optional, for PAC file hosting

User-assigned managed identity

Required for the documented managed identity-based PAC hosting configuration

Azure CLI

Installed and authenticated for CLI configuration

You should also verify that the relevant Azure region, SKU, and subscription support the configuration you intend to deploy.

4. Configuring Azure Firewall Explicit Proxy

This section walks through enabling Explicit Proxy on an existing Azure Firewall using the Azure portal and Azure CLI.

Step 1: Open Azure Firewall Policy

  1. Sign in to the Azure portal

  2. Navigate to Firewall Manager or search for Firewall Policies.

  3. Select the Firewall Policy associated with your Azure Firewall.

  4. Open the Explicit Proxy configuration pane, where available.

Explicit Proxy is configured in the Firewall Policy rather than directly on the firewall resource.

Step 2: Enable Explicit Proxy

Enable Explicit Proxy and configure the proxy listener ports.

Example configuration

Setting

Example value

Enable Explicit Proxy

Enabled

HTTP port

8080

HTTPS proxy port

8443

Enable PAC file

Optional

PAC file port

8081 (example)

These are illustrative values. Confirm the exact supported port fields in your current Azure portal and API version.

Save the configuration and wait for the Firewall Policy update to complete.

Note that the explicit proxy listener uses the firewall’s private IP address. Clients must have network connectivity to that IP and port.

Step 3: Configure application rules

Application rules determine which outbound HTTP and HTTPS destinations are allowed through the firewall.

Navigate to the associated Firewall Policy and open Application Rules.

Create an application rule collection with the following example configuration:

Setting

Example

Rule collection name

Allow-Web-Proxy

Priority

200

Action

Allow

Rule name

Allow-Approved-Websites

Source

10.0.2.0/24

Protocol

http:80, https:443

Destination

*.microsoft.com, *.example.com

Replace the sample source subnet and destination domains with those appropriate to your environment. Ensure the rule collection priority and any existing rules are consistent with your security policy.

For production deployments, use a destination allowlist rather than permitting unrestricted internet access.

Step 4: Configure Explicit Proxy using Azure CLI

You can also configure Explicit Proxy through Azure CLI.

First, authenticate and select the appropriate subscription:

az login

az account set \
  --subscription "<SUBSCRIPTION_ID>"

Set the deployment variables:

RESOURCE_GROUP="rg-network-prod"
POLICY_NAME="afw-policy-prod"

Enable Explicit Proxy on the existing Firewall Policy:

az network firewall policy update \
  --resource-group "$RESOURCE_GROUP" \
  --name "$POLICY_NAME" \
  --explicit-proxy \
    enable-explicit-proxy=true \
    http-port=8080 \
    enable-pac-file=false

This is an illustrative CLI configuration based on the Microsoft Learn Explicit Proxy documentation. Verify the installed Azure CLI version and its supported parameters before running the command.

You can review the policy configuration with:

az network firewall policy show \
  --resource-group "$RESOURCE_GROUP" \
  --name "$POLICY_NAME" \
  --output json

Confirm that Explicit Proxy is enabled and the configured port matches the client settings.

Step 5: Configure client proxy settings

Once the firewall policy is updated, configure the workload applications to use the firewall’s private IP address.

For example, assume:

  • Azure Firewall private IP: 10.0.1.4

  • HTTP proxy port: 8080

For Linux systems using environment variables:

export HTTP_PROXY="http://10.0.1.4:8080"
export HTTPS_PROXY="http://10.0.1.4:8080"
export NO_PROXY="localhost,127.0.0.1"

For a basic connectivity test:

curl -v \
  --proxy http://10.0.1.4:8080 \
  https://www.microsoft.com

The client sends HTTPS traffic using the HTTP proxy’s CONNECT method. The proxy URL scheme remains http:// in this example, even when the requested destination is HTTPS.

For Windows, you can configure the proxy in the operating system’s network proxy settings, through Group Policy, or within individual applications that support proxy configuration.

For Microsoft Edge, for example, proxy settings can be applied through supported operating system or enterprise policy configurations.

5. Configuring a PAC File (Optional)

A Proxy Auto-Configuration (PAC) file enables clients to select a proxy automatically based on the destination URL or hostname.

This is particularly useful in enterprise environments with multiple networks, internal services, and external SaaS applications.

Step 1: Create a PAC file

Create a file named proxy.pac with an example configuration:

function FindProxyForURL(url, host) {

    // Bypass proxy for local resources
    if (isPlainHostName(host) ||
        shExpMatch(host, "*.internal.example.com")) {
        return "DIRECT";
    }

    // Use Azure Firewall for external traffic
    return "PROXY 10.0.1.4:8080; DIRECT";
}

This example sends matching external traffic through the proxy and specifies a direct fallback. In a security-sensitive deployment, consider removing DIRECT fallback for external destinations to prevent proxy bypass.

Step 2: Upload the PAC file to Azure Blob Storage

  • Create or select an Azure Storage account.

  • Create a blob container for PAC files.

  • Upload proxy.pac.

  • Configure access according to the supported PAC retrieval method.

Step 3: Configure managed identity

For the managed identity-based PAC configuration documented by Microsoft:

  1. Create a user-assigned managed identity.

  2. Assign the required Storage Blob Data Contributor and Storage Blob Data Reader roles on the relevant storage account.

  3. Associate the identity with the Firewall Policy.

  4. Configure the PAC file URL and enable PAC file hosting in Explicit Proxy.

Use the identity and PAC configuration flow supported by the current Azure portal or CLI version. Microsoft’s documentation has evolved over time, so verify the latest PAC retrieval and authorization requirements before deploying.

Step 4: Configure client PAC settings

Configure supported client applications to use the PAC file URL provided by the proxy configuration.

Test the PAC file from a client and confirm that it returns the expected proxy selection for internal and external destinations.

6. Security Best Practices

Azure Firewall Explicit Proxy can provide centralized outbound access control, but it should be deployed as part of a layered network security strategy.

  • Restrict access to the listener: Use subnet-level controls and network security policies to limit which workloads can connect to the proxy ports.

  • Use application allowlists: Permit only required FQDNs and protocols in application rules.

  • Prevent proxy bypass: Manage client settings centrally and restrict direct outbound connectivity where appropriate.

  • Use least privilege: Assign only the permissions required for firewall policy administration and PAC file retrieval.

  • Protect PAC configuration: Avoid exposing sensitive network details in PAC files and review access to the hosted configuration.

  • Enable diagnostic logging: Send relevant firewall logs to Log Analytics or another supported monitoring destination.

  • Use separate policies and subnets where appropriate: Segregate workload types to simplify policy enforcement and auditing.

  • Plan for failover: Ensure clients have an approved response if the proxy becomes unavailable rather than unintentionally bypassing security controls.

Important security consideration

Explicit Proxy is not a replacement for all network-layer security controls. It only applies to applications configured to use the proxy. Do not assume that all outbound traffic is automatically inspected or filtered by enabling this feature.

Also, Explicit Proxy does not provide TLS inspection. HTTPS proxying does not, by itself, decrypt the encrypted application payload for inspection.

7. Monitoring and Logging

Azure Firewall diagnostic logs provide visibility into proxied application traffic and policy decisions.

Configure diagnostic settings on Azure Firewall to send logs to a Log Analytics workspace, then use Azure Monitor to investigate traffic patterns and denied requests.

For example, the following Kusto Query Language (KQL) query can be used to explore application rule logs in the resource-specific AZFWApplicationRule table:

AZFWApplicationRule
| where TimeGenerated > ago(24h)
| project
    TimeGenerated,
    SourceIp,
    Fqdn,
    Action,
    Protocol,
    RuleCollection,
    Rule
| order by TimeGenerated desc

The exact schema may vary depending on your diagnostic settings and logging configuration.

To investigate denied connections:

AZFWApplicationRule
| where TimeGenerated > ago(24h)
| where Action == "Deny"
| summarize DeniedRequests = count()
    by SourceIp, Fqdn, Rule
| order by DeniedRequests desc

These queries help identify blocked destinations, investigate application misconfigurations, and review policy enforcement.

8. Troubleshooting Azure Firewall Explicit Proxy

Issue

Possible cause

Recommended action

Connection timeout

Network connectivity or incorrect proxy port

Verify subnet routing, network controls, IP address, and listener port

HTTP 403 or blocked request

Application rule denies the destination

Review rule collection priorities and FQDN allowlists

HTTPS CONNECT failure

Incorrect proxy configuration or destination rule

Check the client proxy URL, CONNECT behavior, and HTTPS application rules

PAC file not loading

Invalid PAC URL, identity, or permissions

Verify blob availability, identity role assignments, and PAC configuration

Some applications bypass the proxy

Application-specific proxy settings

Configure supported client proxy policies and restrict direct egress

No logs available

Diagnostic settings not configured

Enable application rule diagnostics and verify the Log Analytics destination

DNS-related errors

Incorrect name resolution or destination configuration

Verify DNS resolution and destination FQDN requirements

For basic testing, use:

curl -v \
  --proxy http://10.0.1.4:8080 \
  https://www.microsoft.com

Then inspect the corresponding firewall application rule logs to confirm whether the connection was allowed or denied.

Microsoft’s documentation also provides configuration guidance and troubleshooting details for explicit proxy scenarios.Azure Firewall Explicit Proxy documentation

9. Enterprise Deployment Considerations

For larger Azure environments, Explicit Proxy can be incorporated into a centralized outbound security architecture.

Recommended enterprise design

  • Deploy Azure Firewall in a dedicated hub VNet and connect workload VNets through VNet peering or a supported hub-and-spoke design.
  • Configure explicit proxy settings consistently across proxy-aware workloads using approved endpoint management mechanisms.
  • Use Firewall Policy inheritance and rule collections to support centralized governance.
  • Maintain separate outbound security controls for non-proxy-aware applications and other protocols.
  • Use Azure Monitor and Log Analytics to support centralized audit and operational monitoring.

For hybrid environments, on-premises servers can also use Azure Firewall Explicit Proxy when appropriate private connectivity, such as ExpressRoute or site-to-site VPN, is available. Azure Arc scenarios have additional configuration requirements and documented limitations.

10. Azure Firewall Explicit Proxy vs. Traditional Proxy Solutions

Capability

Azure Firewall Explicit Proxy

Traditional dedicated forward proxy

Azure-native integration

Yes

Depends on vendor

HTTP/HTTPS proxy

Yes

Commonly supported

Application rules

Azure Firewall Policy

Vendor-specific policies

Centralized Azure governance

Azure Policy and Firewall Policy

Depends on integration

PAC file support

Yes

Commonly supported

TLS inspection

Not supported by Explicit Proxy

Depends on product

Azure Monitor integration

Supported

Depends on connector

Infrastructure management

Azure-managed service

Often requires separate management

Non-HTTP/HTTPS traffic

Requires other firewall controls

Depends on product

The choice depends on the organization’s existing security architecture, inspection requirements, application compatibility, operational model, and cost considerations. Explicit Proxy is a forward-proxy capability, not a complete substitute for dedicated secure web gateways where advanced web inspection or user-level controls are required.

11. Conclusion

Azure Firewall Explicit Proxy provides an application-aware way to control outbound HTTP and HTTPS traffic in Azure environments. By configuring proxy-aware clients to use the firewall’s private IP address, organizations can apply centralized application rules, manage destination access, and monitor permitted and denied connections.

Its integration with Firewall Policy, optional PAC file configuration, and Azure Monitor can help simplify outbound security management for suitable workloads.

Successful deployment depends on correct client configuration, carefully scoped application rules, appropriate controls for direct outbound traffic, and ongoing monitoring. Organizations should validate the feature against their specific Azure environment and current Microsoft documentation before adopting it for production workloads.

References

  • Microsoft Learn — Azure Firewall Explicit Proxy
  • Microsoft Learn — Azure Firewall Policy Rule Sets
  • Microsoft Learn — Azure Monitor Diagnostic Settings
  • Microsoft Learn — Access Azure Services over Azure Firewall Explicit Proxy

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Reddit (Opens in new window) Reddit
  • Email a link to a friend (Opens in new window) Email

Like this:

Like Loading…

Related

Welcome to Teck Geek Zone

Alibaba & Azure Cloud with a free trial worth $200-1200 USD Click below Cloud Providers

  • Azure Firewall Explicit Proxy: Architecture, Configuration Guide, and Enterprise Deployment
  • Integrating VMware Avi into Purdue and NIST Frameworks for the Marine Industry
  • Securing the Industrial Edge: A Guide to Microsoft Defender for IoT
  • IACS UR E26 and E27 Guidance: Maritime Cybersecurity Framework for Modern Ships
  • Understanding OT, ICS, and SCADA: A Complete Guide to Industrial Technology and Cybersecurity

Categories

  • Cloud (204)
    • Alibaba (39)
    • AWS (46)
    • Azure (125)
  • Free Tools (5)
  • Hardware (17)
  • Linux (13)
  • Network (30)
  • Security (23)
  • VMWARE (59)
  • Windows OS (44)
    • Windows 10 (7)
  • Windows Servers (69)
    • SQL (3)
    • Windows 2008R2 (7)
    • Windows Server 2012R2 (15)
    • Windows Server 2016 (20)
    • Windows Server 2019 (10)

Subscribe to our newsletter

©2026 NKCODE TECH GEEK ZONE | Design: Newspaperly WordPress Theme
Loading Comments...
%d