home/glossary/internal web proxy server

internal web proxy server

nounid 163535·updated Aug 30, 2026
verified

** A network intermediary deployed within an organization's trust boundary that terminates and re-originates outbound HTTP/HTTPS requests on behalf of internal clients, making it the sole authorized source of web traffic leaving the enterprise perimeter. It breaks the direct connection between client and server, accepting and forwarding traffic while closing the straight path between internal and external networks, which prevents external parties from observing internal addressing and topology details. In information flow enforcement practice, flow control restrictions include restricting requests to the Internet that are not from the internal web proxy server — meaning the server functions as a mandatory chokepoint: any outbound web request that did not originate from it is treated as a policy violation and blocked. Enforcement occurs in boundary protection devices such as gateways, routers, guards, and firewalls that employ rule sets or configuration settings to restrict system services and provide packet- or message-filtering capability. **VERDICT:** TERM_OF_ART --- **Sources cited:** - NIST SP 800-171 Rev. 2, §3.1.3 — *Control the flow of CUI in accordance with approved aut

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0179
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
that claims to be sourced from within the organization, restricting requests to the internet that are not from the internal webthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A network security control — specifically a forward-facing intermediary server — deployed within an organization's own network perimeter to mediate, authenticate, inspect, and constrain all outbound HTTP/HTTPS requests made by internal clients to external destinations on the internet. It acts as an intermediary for clients requesting resources from other servers, with client requests evaluated at the proxy to manage complexity and limit direct connectivity. In compliance frameworks it is referenced as the point from which outbound internet traffic is legitimately sourced, and as a mechanism for limiting information transfers between organizations. It functions as a centralized control point for security policy enforcement at the network boundary, implementing content filtering and URL categorization with policy-based blocking — a role formalized in guidance such as CIS Control 12.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.03 ¶ 2

Classifications

Entity Type

Network95%rule-basedr:entity.network.gear.v2

Sensitivity

Regulated85%rule-basedr:sens.regulated.framework.v1

Information Class

unclassified

Variants

plural
internal web proxy servers
possessive
internal web proxy server's
pluralpossessive
internal web proxy servers'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
** A network intermediary deployed within an organization's trust boundary that terminates and re-originates outbound HTTP/HTTPS requests on behalf of internal clients, making it the sole authorized source of web traffic leaving the enterprise perimeter. It breaks the direct connection between client and server, accepting and forwarding traffic while closing the straight path between internal and external networks, which prevents external parties from observing internal addressing and topology details. In information flow enforcement practice, flow control restrictions include restricting requests to the Internet that are not from the internal web proxy server — meaning the server functions as a mandatory chokepoint: any outbound web request that did not originate from it is treated as a policy violation and blocked. Enforcement occurs in boundary protection devices such as gateways, routers, guards, and firewalls that employ rule sets or configuration settings to restrict system services and provide packet- or message-filtering capability. **VERDICT:** TERM_OF_ART --- **Sources cited:** - NIST SP 800-171 Rev. 2, §3.1.3 — *Control the flow of CUI in accordance with approved aut
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.