Skip to content
Article

What Is a Proxy Server? Forward vs Reverse Proxy

A proxy sits between client and server and forwards traffic for them. We explain how organizations use proxies, how they differ from VPNs and their limits.

Oğuzhan Gerçek··8 min read
What Is a Proxy Server? Forward vs Reverse Proxy

Short answer: A proxy is an intermediary that sits between a client and the destination server and forwards requests on their behalf. There are two main types. A forward proxy sits in front of users, and organizations use it to filter, cache and log internet access. A reverse proxy sits in front of servers: it spreads incoming traffic, terminates TLS connections and shields the application from attacks. Unlike a VPN, a proxy does not put all of a device's traffic into a tunnel; it only handles the traffic of applications that are pointed at it.

What is a proxy?

RFC 9110 (June 2022), which defines how HTTP works, describes a proxy as a message-forwarding agent chosen by the client, usually via local configuration rules. In the same document, a gateway, also known as a reverse proxy, is an intermediary that acts as the origin server toward the outside but translates the requests it receives and forwards them inbound to one or more servers.

The difference between the two is whose side the proxy stands on. As Cloudflare puts it, a forward proxy sits in front of a group of client machines, while a reverse proxy sits in front of web servers. The first is set up by the users' organization, the second by whoever owns the servers.

How does a proxy work?

The client sends its request to the proxy rather than straight to the destination server. The proxy opens its own connection to the destination, gets the response and passes it back. As MDN notes, this can make requests appear to come from the proxy's IP address.

Browsers are pointed at a proxy either with a manually entered address or with a PAC (Proxy Auto-Configuration) file. According to MDN, a PAC file consists of a JavaScript function called FindProxyForURL that decides whether each request goes directly to its destination or through a proxy.

For HTTPS traffic, the browser uses the CONNECT method to ask the proxy to open a tunnel to the destination server, after which the proxy blindly forwards data in both directions. The proxy knows which server is being reached but cannot read the encrypted content.

There is also an option that is not tied to HTTP: SOCKS5, defined in RFC 1928 (March 1996), provides a general framework for client-server applications using TCP and UDP to pass through a firewall.

Forward proxy: the intermediary in front of users

According to RFC 9110, proxies are often used to route an organization's HTTP requests through a common intermediary for security services or shared caching. Web traffic leaving the organization's local network passes through this point. In an organization, the main jobs of a proxy server are:

  • Web filtering: Access to specific sites or site categories is blocked. Cloudflare also notes that a forward proxy can be set up to block a group of users from reaching certain sites.
  • Caching: Frequently requested content is kept on the proxy. According to MDN, the aim is to reduce and control the bandwidth the group uses.
  • Authentication: Users authenticate to the proxy before going out to the internet; a request without valid credentials gets a 407 Proxy Authentication Required response.
  • Logging: Who visited which site and when is recorded. We discuss which rules govern how long such records are kept in our log retention article.

Reverse proxy: the intermediary in front of servers

A reverse proxy becomes the only address clients see, and the servers behind it are never exposed directly to the internet. Its main benefits are:

  • Load balancing: Incoming traffic is spread across several servers. The NGINX documentation also lists distributing load among several servers first among the typical reasons for proxying. We go into detail in our load balancer article.
  • Hiding the origin: The IP addresses of the site's origin servers are not revealed, so attacks hit the proxy first.
  • TLS termination: Incoming requests are decrypted and outgoing responses encrypted at the proxy, so the servers behind it do not carry that load.
  • Caching and compression: Static content is cached and compressed at the proxy, taking load off the servers behind it.
  • Application security: According to Cloudflare, a WAF is itself a type of reverse proxy: clients pass through the WAF before they reach the server. We explain it in our WAF article and cover this layer in our application security (WAF) service.

What is a transparent proxy?

There is also a form of forward proxy that the client does not configure. RFC 9110 calls it an interception proxy and notes that it is commonly known as a transparent proxy. The difference is that the client does not choose it: outgoing TCP port 80 traffic (and occasionally other common ports) is filtered or redirected to the proxy by the network. According to the RFC, these proxies are commonly found on public network access points, to enforce account subscription before internet use, and within corporate firewalls to enforce network usage policies. We cover port numbers in our port article.

Proxy vs VPN

Both send traffic through an intermediary, but they work at different layers:

  • VPN: NIST SP 800-77 Rev. 1 (June 2020) defines a VPN as a virtual network built on top of existing physical networks that provides a secure communications mechanism for data transmitted between networks. A VPN working at the network layer, such as IPsec, protects the traffic of all applications without any change to them.
  • Proxy: Works at the application layer and only carries the traffic of the applications pointed at it. While the browser goes out through the proxy, another application on the same device can connect to the internet directly. Encryption is a matter for the protocol, not the proxy: HTTPS traffic stays encrypted end to end, while plain HTTP traffic passes through the proxy unencrypted.

The two can also be used together: a remote user can join the corporate network over a VPN and reach the internet through the organization's proxy.

Security and privacy: what does a proxy see?

Because traffic passes through it, a proxy is a powerful control point, and for the same reason it needs care:

  • HTTPS inspection: Organizations that want to see HTTPS content use inspection products that open the TLS connection at the proxy and re-encrypt it. According to a CISA alert of March 16, 2017, these products insert themselves into the connection as a man-in-the-middle and require a trusted certificate to be installed on client devices. CISA notes that many of them do not properly verify the server's certificate chain, and that clients have no way to check this themselves; it recommends confirming that the product validates certificate chains properly. Decrypting employees' encrypted traffic can mean accessing personal data, so the decision should be made together with the legal team.
  • Limited anonymity: A proxy can hide the client's IP address from the destination site, but whoever runs the proxy sees which sites are visited, and the content too when traffic is unencrypted. Some proxies pass the client's address on to the destination in an X-Forwarded-For or Forwarded header. RFC 7239 (June 2014) notes that the client IP address that may be carried in this header is considered privacy sensitive by many people.
  • Unknown proxies: Sending traffic through a proxy run by someone you cannot identify means showing that traffic to a stranger.

Proxy and internet egress policy fall under our network security service.

Frequently asked questions

What does proxy mean? An intermediary server that sits between a client and the destination server and forwards traffic on their behalf.

What is a proxy used for? On the organization's side, it filters, caches and logs internet access. On the server side, it spreads load, terminates TLS connections and protects the application.

Is a proxy the same as a VPN? No. A VPN carries a device's network traffic through a protected tunnel, while a proxy only mediates the traffic of applications pointed at it.

Does a proxy hide my IP address? The destination site usually sees the proxy's IP address. But whoever runs the proxy knows your address, and some proxies pass it on to the destination in an HTTP header.

What is a reverse proxy? A proxy that sits in front of servers, receives incoming requests and forwards them to the servers behind it. Load balancing, TLS termination and WAFs work at this layer.

What is a transparent proxy? A proxy that needs no client configuration because the network redirects traffic to it automatically. It is common on corporate networks and public networks.

Sources