Forward proxy (client-side)
A forward proxy intercepts outbound requests from clients inside a network.
Forward proxy use cases
- Corporate egress — employees access the internet through a controlled gateway.
- Anonymity / geo bypass — client IP hidden from destination (VPN-like).
- Content filtering — block categories of sites on corporate networks.
- Caching — cache frequently requested external resources for many internal users.
[Laptop] → [Forward proxy] → [Internet] → [api.github.com]
(company policy,
logging, cache)
Clients must be configured to use the proxy (browser settings, HTTP_PROXY env var).
export HTTP_PROXY=http://proxy.corp.example:8080
export HTTPS_PROXY=http://proxy.corp.example:8080
curl https://api.github.com/user
# Request exits via proxy; GitHub sees proxy IP
Reverse proxy (server-side)
A reverse proxy accepts inbound traffic from the internet and forwards it to internal servers.
Corporate firewall, VPN egress.
Load balancing, TLS termination, caching.
Reverse proxy responsibilities
| Feature | Benefit |
|---|---|
| TLS termination | Centralised cert management; backends run plain HTTP |
| Load balancing | Distribute across upstream pool |
| Caching | Serve static responses without hitting app |
| Rate limiting | Protect backends from abuse |
| WAF / filtering | Block SQL injection, bot traffic |
| Compression | gzip/brotli at the edge |
TLS termination
BenefitCentralised cert management; backends run plain HTTPLoad balancing
BenefitDistribute across upstream poolCaching
BenefitServe static responses without hitting appRate limiting
BenefitProtect backends from abuseWAF / filtering
BenefitBlock SQL injection, bot trafficCompression
Benefitgzip/brotli at the edge
NGINX, HAProxy, Envoy, and cloud ALBs all act as reverse proxies in production architectures.
NGINX reverse proxy example
upstream streamhub_upstream {
server 10.0.1.10:8080;
server 10.0.1.11:8080;
keepalive 16;
}
server {
listen 443 ssl http2;
server_name api.streamhub.com;
ssl_certificate /etc/ssl/streamhub.crt;
ssl_certificate_key /etc/ssl/streamhub.key;
location /api/ {
proxy_pass http://streamhub_upstream;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /static/ {
alias /var/www/static/;
expires 7d;
}
}
X-Forwarded-* headers let backends know the original client IP and protocol.
Forward vs reverse — side by side
| Aspect | Forward proxy | Reverse proxy |
|---|---|---|
| Sits near | Client | Server |
| Configured by | Client admin | Server / platform team |
| Hides | Client identity from internet | Server topology from internet |
| Typical product | Squid, corporate proxy | NGINX, ALB, Cloudflare |
Sits near
Forward proxyClientReverse proxyServerConfigured by
Forward proxyClient adminReverse proxyServer / platform teamHides
Forward proxyClient identity from internetReverse proxyServer topology from internetTypical product
Forward proxySquid, corporate proxyReverse proxyNGINX, ALB, Cloudflare
API gateway as reverse proxy++
Modern API gateways (Kong, AWS API Gateway, Envoy) are reverse proxies with auth, routing, and observability built in:
# Conceptual gateway route
routes:
- path: /v1/videos/*
upstream: streamhub-video-service
plugins:
- rate-limit: 1000/min
- jwt-auth: required
- prometheus-metrics: enabled
When to mention each in interviews
- Public API design — reverse proxy / API gateway at the edge.
- Microservices — reverse proxy routes
/usersvs/ordersto different services. - Corporate / B2B integrations — client may require forward proxy for outbound webhooks.
- CDN — reverse proxy at edge PoPs caching static content (see CDN article).
Quick recall
Everything you need if you only revisit this box.
- Forward proxy protects clients going outbound; reverse proxy protects servers from inbound traffic.
- Reverse proxies handle TLS, load balancing, caching, rate limits, and WAF rules.
- NGINX and cloud ALBs are reverse proxies; configure X-Forwarded-* for client metadata.
- API gateways extend reverse proxies with auth, routing, and metrics plugins.
- Forward proxies require client configuration; reverse proxies are transparent to clients.
- Place reverse proxies at the public edge; mention forward proxies only for corporate egress scenarios.
Test yourself
Answer these before moving on — recall is what makes it stick.