What Is a Proxy Server?
A proxy server sits between clients and the destinations they talk to, forwarding requests on their behalf. That middle position makes proxies natural control points — places to filter, cache, log, and inspect traffic. Two kinds matter, distinguished by which side they face: forward proxies front clients, reverse proxies front servers.
Forward vs reverse proxies#
| Forward proxy | Reverse proxy | |
|---|---|---|
| Sits in front of | Clients | Servers |
| Handles | Outbound requests | Inbound requests |
| Typical uses | Filtering, caching, egress control | Load balancing, TLS termination, WAF |
| Hides | The client from the destination | The servers from the client |
A forward proxy is how an organization controls and monitors what its users reach — enforcing egress filtering and blocking known-bad destinations. A reverse proxy is how services present a single hardened front door: terminating TLS, absorbing load and attacks, and hiding the back-end topology.
Why do proxies matter for security?#
Because a chokepoint is a control point. Traffic funneled through a proxy can be inspected, logged, filtered, and rate-limited in one place. A reverse proxy also shrinks the attack surface of the servers behind it, which never face the internet directly.
Proxies are foundational network infrastructure, closely tied to firewalls and WAFs. More at the Network Security hub.
Frequently asked questions#
What is the difference between a forward and reverse proxy?
A forward proxy sits in front of clients and forwards their outbound requests — used for filtering, caching, or hiding client identity. A reverse proxy sits in front of servers and handles inbound requests on their behalf — used for load balancing, TLS termination, caching, and shielding back-end servers. The direction they face is the difference.
How do proxies help security?
Forward proxies enforce outbound policy: filtering malicious sites, logging egress, and enabling egress filtering. Reverse proxies protect servers by terminating TLS, hiding internal structure, absorbing attacks, and hosting a web application firewall. Both act as controlled chokepoints where traffic can be inspected and policy applied.