Side by side
Proxy ServervsReverse Proxy
What is the difference between a proxy and a reverse proxy?
Updated 2 min read7 differences
In short
A forward proxy sits in front of clients and sends their requests to the internet; a reverse proxy sits in front of servers and takes requests for them.
Proxy Server
A proxy server is an intermediary that receives network requests on behalf of clients or servers and passes them on, adding control, caching, or privacy.
Read the page on Proxy ServerReverse Proxy
A reverse proxy is a server that sits in front of web servers, accepts client requests on their behalf, and forwards each request to the right backend server.
Read the page on Reverse ProxyProxy Server and Reverse Proxy compared
| Aspect | Proxy Server | Reverse Proxy |
|---|---|---|
| Sits in front of | Clients | Servers |
| Works for | The users making requests | The site or service receiving them |
| Set up by | The client side: browser, system or network settings | The server side: the site's operators |
| Hides | The clients' addresses from the servers | The servers' addresses and layout from the clients |
| Typical jobs | Filtering, caching downloads, logging, privacy | HTTPS termination, load balancing, caching, protection |
| Visible to clients? | Yes: clients are configured to use it | No: it looks like the website itself |
| Examples | An office web proxy, Squid | NGINX in front of an app, a CDN, an API gateway |
The difference, explained
Both are middlemen that pass traffic on, and the same software can often play either role. The difference is whose side they are on. A forward proxy, usually just called a proxy, works for a group of clients: an office or a school sends its outgoing web traffic through it. A reverse proxy works for a group of servers: every request from the internet to a website arrives at it first.
A forward proxy is what the outside world sees instead of the clients. It can filter which sites people may visit, cache popular downloads, log traffic and hide the clients' addresses. Clients are usually set up to use it, through browser or system settings, or the network sends traffic through it whether they know or not.
A reverse proxy is what clients see instead of the servers. It terminates HTTPS, spreads requests across several backend servers, caches and compresses responses, limits abusive clients and hides the internal layout of the system. Clients don't know it is there: to them, it is the website. Load balancers, API gateways and CDNs are all specialized reverse proxies.
One way to remember it: a forward proxy is like an assistant who makes calls for you, so the people called only see the assistant's number; a reverse proxy is like a company's switchboard, which answers every call and puts it through to the right department, so callers never see the internal extensions.
Which one should you use?
Choose Proxy Server when…
- You need to control or log what a network's users reach on the internet.
- Clients should reach outside services through one known address.
- You want to cache downloads that many users on one network share.
Choose Reverse Proxy when…
- You run a website or API and want one entry point in front of several servers.
- You need HTTPS termination, load balancing or caching for your own service.
- You want to hide internal servers and keep direct traffic away from them.
A client using a forward proxy, and a reverse proxy in front of an app
# Forward proxy: the client is told to send its traffic through it
export HTTPS_PROXY=http://proxy.office.example:3128
curl https://example.com
# curl asks the proxy, which connects to example.com for it# Reverse proxy: the site puts it in front of the app (NGINX)
server {
listen 443 ssl;
server_name shop.example.com;
location / {
proxy_pass http://app_servers; # pass the request to the backend pool
}
}Readers ask
Is a VPN a kind of proxy?
Not quite. A VPN tunnels all of a device's traffic, encrypted and at the network level, while a proxy usually handles one application's traffic, such as the browser's. Both hide your address from the sites you visit.
Is a load balancer a reverse proxy?
Most are. A load balancer that works with HTTP is a reverse proxy whose main job is spreading requests across servers; a reverse proxy may do that among many other things.
Can one server be both?
Yes. Software such as NGINX can act as a forward proxy for one purpose and a reverse proxy for another, though in practice the two roles are usually run separately.