PrepZone Logo
PrepZone

Proxy vs Reverse Proxy

Forward proxies hide clients; reverse proxies protect servers — and both show up in real architectures.

Read these first

Forward proxy (client-side)

A forward proxy intercepts outbound requests from clients inside a network.

Forward proxy use cases

  • Corporate egress — employees access the internet through a controlled gateway.
  • Anonymity / geo bypass — client IP hidden from destination (VPN-like).
  • Content filtering — block categories of sites on corporate networks.
  • Caching — cache frequently requested external resources for many internal users.
Java
[Laptop] → [Forward proxy] → [Internet] → [api.github.com]
           (company policy,
            logging, cache)

Clients must be configured to use the proxy (browser settings, HTTP_PROXY env var).

Java
export HTTP_PROXY=http://proxy.corp.example:8080
export HTTPS_PROXY=http://proxy.corp.example:8080
curl https://api.github.com/user
# Request exits via proxy; GitHub sees proxy IP

Reverse proxy (server-side)

A reverse proxy accepts inbound traffic from the internet and forwards it to internal servers.

Forward
Forward proxyclient-side

Corporate firewall, VPN egress.

Reverse
Reverse proxyserver-side

Load balancing, TLS termination, caching.

Forward hides the client; reverse hides the server fleet.

Reverse proxy responsibilities

FeatureBenefit
TLS terminationCentralised cert management; backends run plain HTTP
Load balancingDistribute across upstream pool
CachingServe static responses without hitting app
Rate limitingProtect backends from abuse
WAF / filteringBlock SQL injection, bot traffic
Compressiongzip/brotli at the edge
  • TLS termination

    BenefitCentralised cert management; backends run plain HTTP
  • Load balancing

    BenefitDistribute across upstream pool
  • Caching

    BenefitServe static responses without hitting app
  • Rate limiting

    BenefitProtect backends from abuse
  • WAF / filtering

    BenefitBlock SQL injection, bot traffic
  • Compression

    Benefitgzip/brotli at the edge

NGINX, HAProxy, Envoy, and cloud ALBs all act as reverse proxies in production architectures.

NGINX reverse proxy example

Java
upstream streamhub_upstream {
  server 10.0.1.10:8080;
  server 10.0.1.11:8080;
  keepalive 16;
}

server {
  listen 443 ssl http2;
  server_name api.streamhub.com;

  ssl_certificate     /etc/ssl/streamhub.crt;
  ssl_certificate_key /etc/ssl/streamhub.key;

  location /api/ {
    proxy_pass http://streamhub_upstream;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
  }

  location /static/ {
    alias /var/www/static/;
    expires 7d;
  }
}

X-Forwarded-* headers let backends know the original client IP and protocol.

Forward vs reverse — side by side

AspectForward proxyReverse proxy
Sits nearClientServer
Configured byClient adminServer / platform team
HidesClient identity from internetServer topology from internet
Typical productSquid, corporate proxyNGINX, ALB, Cloudflare
  • Sits near

    Forward proxyClient
    Reverse proxyServer
  • Configured by

    Forward proxyClient admin
    Reverse proxyServer / platform team
  • Hides

    Forward proxyClient identity from internet
    Reverse proxyServer topology from internet
  • Typical product

    Forward proxySquid, corporate proxy
    Reverse proxyNGINX, ALB, Cloudflare

API gateway as reverse proxy++

Modern API gateways (Kong, AWS API Gateway, Envoy) are reverse proxies with auth, routing, and observability built in:

Java
# Conceptual gateway route
routes:
  - path: /v1/videos/*
    upstream: streamhub-video-service
    plugins:
      - rate-limit: 1000/min
      - jwt-auth: required
      - prometheus-metrics: enabled

When to mention each in interviews

  • Public API design — reverse proxy / API gateway at the edge.
  • Microservices — reverse proxy routes /users vs /orders to different services.
  • Corporate / B2B integrations — client may require forward proxy for outbound webhooks.
  • CDN — reverse proxy at edge PoPs caching static content (see CDN article).

Quick recall

Everything you need if you only revisit this box.

  • Forward proxy protects clients going outbound; reverse proxy protects servers from inbound traffic.
  • Reverse proxies handle TLS, load balancing, caching, rate limits, and WAF rules.
  • NGINX and cloud ALBs are reverse proxies; configure X-Forwarded-* for client metadata.
  • API gateways extend reverse proxies with auth, routing, and metrics plugins.
  • Forward proxies require client configuration; reverse proxies are transparent to clients.
  • Place reverse proxies at the public edge; mention forward proxies only for corporate egress scenarios.

Test yourself

Answer these before moving on — recall is what makes it stick.