Home/Labs/Forward vs Reverse Proxy
All 280 Labs
INTERACTIVE LAB🔀

Proxy Spectrum Lab (Interactive)

Switch between direct, forward, and reverse proxy paths and see exactly which IP each side ever learns. Compare client-side (Squid egress) and server-side (Nginx ingress) proxies. Quantify TLS CPU offload, cache savings, egress filtering, and the one-hop latency tax.

Forward vs Reverse Proxy Spectrum

Same machinery, opposite allegiance: forward proxies represent clients, reverse proxies represent servers.

Public users

Browsers 🌍

oblivious: proxy IS the site

Middlebox

Reverse VIP

🔒 TLS term · ⚖️ LB · ⚡ cache

Private backends

10.0.4.21 · 10.0.4.22 · 10.0.4.23

target sees nothing of the client topology

IP EXPOSURE TRACE

› Clients think the proxy is the origin server itself.

› Targets see public users reach only the proxy VIP.

› Public clients never learn 3 private pod IPs — topology shielded from port scans.

Mnemonic: Forward = protects CLIENTS (filtering, anonymity, egress caching). Reverse = protects SERVERS (TLS termination, WAF, load balancing, response caching). Service meshes put a reverse-proxy sidecar (Envoy) on every pod for mTLS.

Capabilities

Proxy negotiates TLS 1.3 once; backends get cheap internal HTTP/mTLS.

Backend TLS cores0.00 cores
Proxy hop latency+0.6ms
Cache hit ratio70%
Bandwidth saved56.0 Mbps
Blocked egress requests/min: 0 · offered load: 1,000 req/s

How It Works Under the Hood

A forward proxy sits in front of clients: employees or VPC workloads explicitly route through it, so the internet only ever sees the proxy IP while the proxy filters content, enforces DLP, and caches outbound downloads. A reverse proxy sits in front of servers: clients believe the proxy IS the origin, never learning private pod IPs, while it terminates TLS, load balances, serves cached static assets, and absorbs DDoS. Both add one network hop, and service meshes put a reverse-proxy Envoy sidecar next to every microservice for mTLS.

Core Architectural Principles

  • Forward proxy protects clients: hides client IPs, filters egress, caches outbound assets for WAN savings.
  • Reverse proxy protects servers: TLS termination, load balancing, WAF, response caching, path rewriting.
  • Clients are explicitly configured for forward proxies but completely unaware of reverse proxies.
Interview Round Script

Lead with the mnemonic: forward proxies represent clients, reverse proxies represent servers. Then quantify the reverse-proxy wins in your design: centralized TLS termination freeing backend CPU, static caching, and topology shielding. Mention Envoy sidecar mTLS if the question moves to service meshes.

Key Trade-Offs

Proxies centralize security and caching economics but add ~0.2-1.0ms per hop and can leak internal headers if misconfigured.

Related Curriculum Chapter

Reverse Proxy vs Forward Proxy

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs