Skip to main content

Side by side

Proxy ServervsReverse Proxy

What is the difference between a proxy and a reverse proxy?

Updated 2 min read7 differences

In short

A forward proxy sits in front of clients and sends their requests to the internet; a reverse proxy sits in front of servers and takes requests for them.

Proxy Server

A proxy server is an intermediary that receives network requests on behalf of clients or servers and passes them on, adding control, caching, or privacy.

Read the page on Proxy Server

Reverse Proxy

A reverse proxy is a server that sits in front of web servers, accepts client requests on their behalf, and forwards each request to the right backend server.

Read the page on Reverse Proxy

Proxy Server and Reverse Proxy compared

AspectProxy ServerReverse Proxy
Sits in front ofClientsServers
Works forThe users making requestsThe site or service receiving them
Set up byThe client side: browser, system or network settingsThe server side: the site's operators
HidesThe clients' addresses from the serversThe servers' addresses and layout from the clients
Typical jobsFiltering, caching downloads, logging, privacyHTTPS termination, load balancing, caching, protection
Visible to clients?Yes: clients are configured to use itNo: it looks like the website itself
ExamplesAn office web proxy, SquidNGINX in front of an app, a CDN, an API gateway

The difference, explained

Both are middlemen that pass traffic on, and the same software can often play either role. The difference is whose side they are on. A forward proxy, usually just called a proxy, works for a group of clients: an office or a school sends its outgoing web traffic through it. A reverse proxy works for a group of servers: every request from the internet to a website arrives at it first.

A forward proxy is what the outside world sees instead of the clients. It can filter which sites people may visit, cache popular downloads, log traffic and hide the clients' addresses. Clients are usually set up to use it, through browser or system settings, or the network sends traffic through it whether they know or not.

A reverse proxy is what clients see instead of the servers. It terminates HTTPS, spreads requests across several backend servers, caches and compresses responses, limits abusive clients and hides the internal layout of the system. Clients don't know it is there: to them, it is the website. Load balancers, API gateways and CDNs are all specialized reverse proxies.

One way to remember it: a forward proxy is like an assistant who makes calls for you, so the people called only see the assistant's number; a reverse proxy is like a company's switchboard, which answers every call and puts it through to the right department, so callers never see the internal extensions.

Which one should you use?

Choose Proxy Server when…

  • You need to control or log what a network's users reach on the internet.
  • Clients should reach outside services through one known address.
  • You want to cache downloads that many users on one network share.

Choose Reverse Proxy when…

  • You run a website or API and want one entry point in front of several servers.
  • You need HTTPS termination, load balancing or caching for your own service.
  • You want to hide internal servers and keep direct traffic away from them.

A client using a forward proxy, and a reverse proxy in front of an app

Proxy Servertext
# Forward proxy: the client is told to send its traffic through it
export HTTPS_PROXY=http://proxy.office.example:3128
curl https://example.com
# curl asks the proxy, which connects to example.com for it
Reverse Proxytext
# Reverse proxy: the site puts it in front of the app (NGINX)
server {
  listen 443 ssl;
  server_name shop.example.com;
  location / {
    proxy_pass http://app_servers;  # pass the request to the backend pool
  }
}

Readers ask

Is a VPN a kind of proxy?

Not quite. A VPN tunnels all of a device's traffic, encrypted and at the network level, while a proxy usually handles one application's traffic, such as the browser's. Both hide your address from the sites you visit.

Is a load balancer a reverse proxy?

Most are. A load balancer that works with HTTP is a reverse proxy whose main job is spreading requests across servers; a reverse proxy may do that among many other things.

Can one server be both?

Yes. Software such as NGINX can act as a forward proxy for one purpose and a reverse proxy for another, though in practice the two roles are usually run separately.

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings