Practice this topic in a realistic system design interview
When you open a website, your request doesn't always go directly from your browser to the application server. Sometimes, there's another server sitting in the middle.
If that server is acting on behalf of the client, it's called a forward proxy.
If it's acting on behalf of the backend servers, it's called a reverse proxy.
Both sit in the middle and forward traffic. What makes them different is whose side they are on.
The simulation below shows the same request flowing through each type.
Loading simulation...
A forward proxy sits between the client and the internet and acts on behalf of the client.
Instead of sending a request directly to the destination server, the client sends it to the forward proxy. The proxy then forwards that request to the server and returns the response back to the client.
Request flow:
From the destination server's point of view, the request appears to come from the proxy, not directly from the original client.
A proxy is not the same thing as a VPN.
No. Both can hide the client's IP address, but a VPN typically creates an encrypted tunnel for broader network traffic, while a proxy usually forwards traffic for specific protocols or applications.
So why would you put a forward proxy between clients and the internet? There are a few common reasons.
Since the destination server sees the proxy's IP address, the client's network address is not directly exposed to that server.
Hiding an IP address is not the same as anonymity, though. The proxy operator can still log who connects and where, and the destination site can still recognize you through cookies, logins, or browser fingerprints.
Organizations can use a forward proxy to block certain websites or restrict which external services employees can access.
Because outbound traffic passes through the proxy, the organization can track requests and enforce security policies.
If many users request the same resource, the proxy may cache the response and serve it directly, reducing bandwidth usage and latency.
A forward proxy can provide access through another network or location when direct access is restricted.
So forward proxies are mainly about controlling and managing outbound traffic from clients.
A reverse proxy sits in front of backend servers and acts on their behalf.
The client sends its request to the reverse proxy, often without even knowing that a proxy is involved. The reverse proxy then decides which backend server should handle the request, forwards it, receives the response, and sends that response back to the client.
Request flow:
From the client's point of view, it is simply talking to one endpoint. It doesn't need to know which backend server handled the request.
This gives you a single entry point in front of many backend servers, while keeping the internal architecture hidden from the client.
So why put a reverse proxy in front of your backend servers?
The biggest reason is traffic management. A reverse proxy can distribute incoming requests across multiple backend servers, helping the system handle more traffic and avoid overloading a single server.
Instead of every backend server managing HTTPS certificates and encryption, the reverse proxy can handle that in one place.
If the same response is requested frequently, the reverse proxy can serve a cached copy without sending every request to the backend.
Be careful with personalized responses. A cached copy of one user's data must never be served to another user.
A reverse proxy can provide security and access control by hiding backend servers from direct public access, enforcing rate limits, filtering requests, and applying authentication rules.
In systems with multiple services, a reverse proxy can perform request routing. For example, requests to /users can go to the User Service, while /payments goes to the Payment Service.
A reverse proxy and a load balancer are closely related, but they're not exactly the same thing.
A load balancer has one primary job: distribute incoming traffic across multiple backend servers.
A reverse proxy is a broader concept. It also sits in front of backend servers, but it can do much more than distribute traffic.
Many reverse proxies, such as NGINX, HAProxy, and Envoy, can also act as load balancers.
So a simple way to think about it: load balancing is one capability a reverse proxy can provide, but a reverse proxy can handle many other responsibilities as well.
There are several popular technologies that can act as reverse proxies.
A Layer 4 proxy forwards TCP or UDP connections without reading what is inside them. A Layer 7 proxy understands the application protocol, usually HTTP, so it can make decisions using paths, headers, or hostnames.
Envoy also handles service-to-service communication, which is why it often runs next to every service in a microservices system.
So in practice, you may not always deploy something explicitly called a "reverse proxy." A load balancer, API gateway, ingress controller, or CDN may already be performing reverse proxy behavior as part of the architecture.
Here is a small NGINX reverse proxy for an HTTP backend.
Start by installing NGINX, checking that the config is valid, and reloading the service.
This server block sends every request to one backend and sets headers that help the backend understand the original client request.
Adding an upstream block lets one proxy spread traffic across several backends. The failure settings help NGINX stop sending traffic to a server that is repeatedly failing.
NGINX uses round robin by default, which means it cycles through the backend servers. least_conn is useful when some requests take longer than others because it sends new requests to the server with the fewest active connections.
Sticky routing is possible, but use it carefully. It can hide the fact that the backend depends on local server state.
This example is intentionally small. Production configs also need HTTPS, access logs, request size limits, buffering choices, health checks or failure policy, compression, security headers, and timeouts that match the application.
The key idea is simple: a forward proxy represents the client, while a reverse proxy represents the server.
A forward proxy controls and manages outbound traffic from clients.
A reverse proxy gives many backend servers a single entry point, and load balancing is only one of the jobs it can take on.
10 quizzes