A proxy, properly called a forward proxy, sits in front of clients and makes requests to the internet on their behalf. A reverse proxy sits in front of servers and accepts requests from the internet on their behalf.
The mechanics are the same: a proxy server ends one connection and opens another. What differs is whose side it is on. A forward proxy controls and hides the users. A reverse proxy protects and hides the servers, and it is the one most businesses operate, often without calling it that.
- A forward proxy works for the client. A reverse proxy works for the server
- Clients are configured to use a forward proxy. Nobody configures anything to use a reverse proxy
- Web filters and secure web gateways are forward proxies
- Load balancers, WAFs and CDNs are reverse proxies with a specialty
- Any business with a public website or web app is behind a reverse proxy somewhere
On this page
Forward proxyWhat a forward proxy does
A forward proxy is an intermediary between internal clients and servers on the internet. The browser sends its request to the proxy server instead of to the website. The proxy checks it against policy, makes the request itself and hands the response back. The website sees the proxy's IP address, not the user's.
The client has to know the proxy is there. That happens through proxy settings in the browser or operating system, a PAC file that tells the browser which proxy to use for which site, or a firewall that redirects web traffic transparently.
For HTTPS, the browser asks the proxy to open a tunnel with the HTTP CONNECT method.
Organizations use forward proxies for a short list of reasons:
- Content filtering. Block categories of sites, known malware hosts and downloads by type.
- Logging and accountability. One record of which user requested which site.
- Privacy and egress control. Internal IP addresses stay hidden, and servers with no direct route out can still fetch updates through one controlled point.
- Caching. Keep copies of frequently requested files, which mattered more when web traffic was unencrypted.
- TLS inspection. Decrypt, scan and encrypt again, which requires a trusted certificate on every client.
The consumer meaning of the word, a service that hides your address from a website, is the same mechanism pointed at a different goal. The page on VPN vs proxy covers that use.
Reverse proxyWhat a reverse proxy does
A reverse proxy is the mirror image. It sits in front of one or more backend servers, owns the public IP address and the DNS name, and receives client requests from the internet. It picks the backend that should answer, forwards the request over a second connection and returns the response as its own.
The client needs no configuration and cannot tell. To a browser, the reverse proxy is the website. The servers behind it can sit on private addresses with no direct exposure to the internet, which is the first security benefit and the reason the pattern is everywhere.
Because every request passes through it, a reverse proxy is the natural place for work that would otherwise be repeated on each server:
- TLS termination. Certificates live in one place. The proxy handles encryption on port 443 and talks to the backends however the design requires.
- Load balancing. Spread incoming traffic across multiple servers and stop sending to one that fails its health check.
- Routing by host and path. One IP address serves several applications, with each hostname or URL path sent to a different backend server.
- Caching and compression. Serve static content from the proxy and spare the application.
- Request filtering and authentication. Rate limits, IP allow lists, single sign-on in front of an application that has none.
Nginx, HAProxy, Apache with its proxy modules, Caddy and Traefik are the common software choices. Most hardware and cloud load balancers do the same job as a product.
The differenceThe difference is whose side the proxy is on
In a proxy vs reverse proxy comparison the technology is nearly identical, and some software can run in either role. Both terminate a connection and start a new one. Both can cache, log, filter and hide IP addresses. What separates them is who deploys the proxy and whose interests it serves.
A forward proxy belongs to the client side. The organization that owns the users runs it, to control what leaves the network. It faces many unknown servers.
A reverse proxy belongs to the server side. The organization that owns the application runs it, to control what reaches the servers. It faces many unknown clients.
A quick test for any diagram: who configured the proxy? If the answer is the people browsing, it is a forward proxy. If the answer is the people hosting, it is a reverse proxy. One request can pass through both: out through the office web filter, in through the site's CDN.
In practiceWhich one a small business actually runs into
Most articles on forward proxy vs reverse proxy treat the two as equally common. For a small or midsize business they are not.
The forward proxy has mostly become a feature. A small office rarely needs a standalone proxy server. The function comes inside the firewall as web filtering, as a cloud secure web gateway that laptops reach from anywhere, or is replaced by DNS filtering.
You meet the forward proxy as a proxy setting, a PAC file or a certificate that has to be trusted.
The reverse proxy is what you operate or buy. A public website behind Cloudflare or another CDN is behind a reverse proxy. A web application with Nginx in front of it is behind one. So is anything published through a load balancer, a WAF, or the reverse proxy feature of a NAS.
Publishing an internal application is the usual first contact. The old method was a port forward on the firewall straight to the server. A reverse proxy in between gives you one place for TLS, authentication and logging, and keeps the server itself off the internet.
Cloud access proxies go one step further. Microsoft's documentation for Entra application proxy says its connector uses only outbound connections, so no inbound ports are opened on the firewall. The reverse proxy runs in the vendor's cloud, and a small agent inside the network dials out to it.
Related toolsWhere a load balancer, a WAF and a CDN sit
All three are reverse proxies with a specialty, which is why reverse proxy vs load balancer comparisons feel circular. A request to a well built public application can cross all of them, in this order from the client inward.
The CDN is the outermost reverse proxy. It is a fleet of proxies spread across many locations. It answers from cache where it can, absorbs volumetric attacks, and forwards the rest to your origin server. DNS points at the CDN, not at you.
The WAF comes next. A web application firewall is a reverse proxy that reads each HTTP request and blocks the ones that look like attacks. It is often a feature of the CDN or of the load balancer instead of a separate box.
The load balancer is closest to the servers. It picks a healthy backend for each request. A layer 7 load balancer is a reverse proxy that emphasizes choosing among multiple servers. A layer 4 load balancer forwards TCP connections without reading the HTTP requests inside them, so it cannot route by path or filter requests.
A plain reverse proxy is what remains when there is one backend and no need to balance. In small deployments a single Nginx or HAProxy instance does TLS, routing, basic filtering and balancing at once.
PitfallsWhere people go wrong
Leaving the origin server reachable directly. A reverse proxy, WAF or CDN protects only the path through it. If the backend still answers on its own public address, an attacker skips the proxy. Allow inbound web traffic from the proxy's addresses only.
Losing the client IP address. Behind a reverse proxy, every request appears to come from the proxy. Logs, rate limits and geolocation break unless the proxy passes the original address in the X-Forwarded-For or Forwarded header and the application is told to trust that header from the proxy alone.
Trusting forwarded headers from anyone. The same header can be forged by a client. An application that believes X-Forwarded-For from any source lets a visitor claim to be any address.
Treating a forward proxy as anonymity. The proxy operator sees every request, and with TLS inspection sees inside it. Inside a company that is the purpose. On a free public proxy it is the risk.
Forgetting what breaks under TLS inspection. Applications with pinned certificates fail through an inspecting forward proxy. Plan an exception list before turning inspection on, not after the help desk calls start.
Making the reverse proxy a single point of failure. Everything now depends on one instance. Run two, or use a managed service, before putting every application behind it.
ComparisonForward proxy and reverse proxy, and whose side each one is on
| Criterion | Forward proxy | Reverse proxy |
|---|---|---|
| Sits in front of | Clients | Servers |
| Deployed by | The organization that owns the users | The organization that owns the application |
| Client configuration | Proxy settings, PAC file or transparent redirect | None |
| Hides | Client IP addresses | Backend servers and their addresses |
| Faces | Any server on the internet | Any client on the internet |
| Main security job | Control what users can reach | Control what reaches the servers |
| Typical features | Filtering, logging, TLS inspection | TLS termination, load balancing, caching, WAF |
| Where a small business meets it | Inside the firewall or a cloud web gateway | In front of every public site or app |
The rows on deployment and client configuration settle most reverse proxy vs proxy confusion. If users had to be pointed at it, or a certificate had to be pushed to their machines, it is a forward proxy. If it has a public DNS name and visitors never hear about it, it is a reverse proxy.
FAQFrequently asked questions
What is a reverse proxy?
A reverse proxy is a server that sits in front of one or more web servers and receives requests from clients on their behalf. It forwards each request to a backend, returns the response and hides the backend servers. It commonly handles TLS, load balancing and caching.
What is a forward proxy?
A forward proxy is a server that sits between internal clients and the internet and makes requests on the clients' behalf. It lets an organization filter and log web access and hides client IP addresses from the sites being visited.
What is the difference in forward proxy vs reverse proxy?
A forward proxy acts for clients and controls outbound requests. A reverse proxy acts for servers and controls inbound requests. Clients must be configured or redirected to use a forward proxy, while a reverse proxy is invisible to the clients that reach it.
Is "proxy" the same as "forward proxy"?
Yes. When people say proxy or proxy server without a qualifier, they almost always mean a forward proxy. The word forward was added later to distinguish it from a reverse proxy.
What is the difference in reverse proxy vs load balancer?
A load balancer distributes requests across multiple servers. A reverse proxy sits in front of servers and handles requests for them, even a single one. A layer 7 load balancer is a reverse proxy with balancing as its main feature, and most products do both.
Is a CDN a reverse proxy?
Yes. A content delivery network is a large set of reverse proxies placed in many locations. Visitors connect to the nearest one, which serves cached content or fetches it from the origin server. Many CDNs also include WAF and DDoS protection.
Is a WAF a reverse proxy?
In most deployments, yes. A web application firewall terminates the client connection, inspects the HTTP request and forwards it to the application only if it passes. That is reverse proxy behavior with security inspection as the specialty.
Is a VPN a forward proxy?
No, though both hide your IP address from the destination. A VPN tunnels all traffic from a device at the network level. A forward proxy handles specific protocols, usually web traffic, and can inspect and filter individual requests.
Does a small business need a reverse proxy?
If it hosts any web application that people reach from the internet, yes, in some form. That can be a CDN, a cloud access proxy or a small Nginx server. Exposing an application server directly through a port forward is the option to avoid.
Can one server be both a forward and a reverse proxy?
The same software often can. Nginx, Apache and HAProxy can be configured for either role. Running both roles on one instance is unusual, because they face opposite directions and belong in different parts of the network.
Does a reverse proxy improve security?
It helps. Backend servers are not exposed directly, TLS and authentication are enforced in one place, and bad requests can be dropped early. It does not fix a vulnerable application, and it adds nothing if the backend remains reachable around it.
How does a server see the real client IP behind a reverse proxy?
The proxy adds the original address to a request header, usually X-Forwarded-For or the standardized Forwarded header. The application reads that header, and should accept it only from the proxy's own address.
Keep readingRelated concepts
Read next · Remote access VPN vs Proxy The consumer side of the word proxy: what a proxy hides, and what a VPN adds. Open this next13 min- Infrastructure · 12 min What a Load Balancer Does, and the Two Decisions Behind It How a load balancer picks a healthy server, and when layer 4 is enough.
- Network security · 14 min What Is a WAF? What a web application firewall inspects in each request, and what it misses.