Proxy Spectrum Lab (Interactive)
Switch between direct, forward, and reverse proxy paths and see exactly which IP each side ever learns. Compare client-side (Squid egress) and server-side (Nginx ingress) proxies. Quantify TLS CPU offload, cache savings, egress filtering, and the one-hop latency tax.
Forward vs Reverse Proxy Spectrum
Same machinery, opposite allegiance: forward proxies represent clients, reverse proxies represent servers.
Public users
Browsers 🌍
oblivious: proxy IS the site
Middlebox
Reverse VIP
🔒 TLS term · ⚖️ LB · ⚡ cache
Private backends
10.0.4.21 · 10.0.4.22 · 10.0.4.23
target sees nothing of the client topology
IP EXPOSURE TRACE
› Clients think the proxy is the origin server itself.
› Targets see public users reach only the proxy VIP.
› Public clients never learn 3 private pod IPs — topology shielded from port scans.
Capabilities
Proxy negotiates TLS 1.3 once; backends get cheap internal HTTP/mTLS.
How It Works Under the Hood
A forward proxy sits in front of clients: employees or VPC workloads explicitly route through it, so the internet only ever sees the proxy IP while the proxy filters content, enforces DLP, and caches outbound downloads. A reverse proxy sits in front of servers: clients believe the proxy IS the origin, never learning private pod IPs, while it terminates TLS, load balances, serves cached static assets, and absorbs DDoS. Both add one network hop, and service meshes put a reverse-proxy Envoy sidecar next to every microservice for mTLS.
Core Architectural Principles
- Forward proxy protects clients: hides client IPs, filters egress, caches outbound assets for WAN savings.
- Reverse proxy protects servers: TLS termination, load balancing, WAF, response caching, path rewriting.
- Clients are explicitly configured for forward proxies but completely unaware of reverse proxies.
Lead with the mnemonic: forward proxies represent clients, reverse proxies represent servers. Then quantify the reverse-proxy wins in your design: centralized TLS termination freeing backend CPU, static caching, and topology shielding. Mention Envoy sidecar mTLS if the question moves to service meshes.
Proxies centralize security and caching economics but add ~0.2-1.0ms per hop and can leak internal headers if misconfigured.