Forward proxy vs reverse proxy: which side the middleman stands in for
4 min read
A forward proxy stands in for the client and hides who is asking; a reverse proxy stands in for the servers and hides what is answering — it is the same box sitting in the middle, just facing the opposite direction. That single fact captures the difference between a forward proxy and a reverse proxy: not what the box does, but which side of the conversation it is standing in for. Get that straight and every other property — who it protects, who configures it, whose identity it conceals — falls out of it.

A proxy is a stand-in
Strip away the adjectives and a proxy is one thing: a stand-in that takes a request meant for one party and hands back the reply, so the two ends never talk directly. Both kinds of proxy sit in exactly the same place on the wire — between a client and a server. What changes is which end hired it, and therefore which end it hides.
The forward proxy hides the client
A forward proxy sits next to the client and works on the client's behalf. The client sends its request through the proxy, and the proxy makes the onward call, so the destination server only ever sees the proxy — never the real client. That is the defining move: the client's identity, and often its location, never reach the far end.
This is the proxy a network operator runs for the people inside it. A corporate egress proxy that filters and logs outbound traffic, a school content filter, a privacy or geo-shifting proxy, the caching forward proxy that keeps a shared copy of what everyone downloads — all of them are forward proxies, because all of them stand in for the client and configure the client (or its network) to route through them.
The reverse proxy hides the servers
A reverse proxy sits next to the servers and works on their behalf. Now it is the client that is kept in the dark: the client only ever talks to the proxy, and the real servers live behind it, out of sight. The client sends one request to one address; the proxy decides which of several backends actually answers, and the client never learns there was more than one.
That concealment is the point. Because the client is pinned to the proxy's address, the servers behind it can be added, replaced, restarted, or scaled without the client noticing anything. Nobody reconfigures a browser to reach a reverse proxy — the site's own operator puts it in front of their fleet, and to the outside world the proxy is the site.
What is a reverse proxy used for
So what is a reverse proxy used for? If a forward proxy is chosen by the side making requests, a reverse proxy is chosen by the side answering them, and its jobs follow from sitting at the front door of a fleet. A reverse proxy terminates TLS in one place, spreads incoming requests across many backend servers, caches and compresses responses, presents many internal services under one hostname and path scheme, and gives the outside world a single stable address while the machines behind it churn. Reach for one whenever you own the servers and want a controlled seam between them and the public — the moment you have more than one backend, or want to hide, protect, or reshape the ones you already run.
Reverse proxy vs load balancer
The reverse proxy vs load balancer question trips people up because the two overlap: spreading requests across backends is one of the jobs a reverse proxy does, and that job is exactly what a load balancer is for. The clean way to hold it: a load balancer is defined by one responsibility — distributing traffic across a pool — while a reverse proxy is the broader role that can also do TLS termination, caching, routing, and header rewriting. Most modern reverse proxies load-balance, and most standalone load balancers are, structurally, reverse proxies. It is a question of which capability you are naming, not two rival boxes.
Forward Proxy vs Reverse Proxy in a system design interview
An interviewer asking this is checking whether you can place the box, not recite a definition. The crisp answer: both sit between client and server, but a forward proxy acts for the client and hides the client from the server, while a reverse proxy acts for the servers and hides them from the client. The tell that you actually understand it is knowing who configures each — the client (or its network) points itself at a forward proxy, whereas a reverse proxy is deployed by the service owner and is invisible to callers. Expect the natural follow-up — "so is that just a load balancer?" — and answer it with the section above: load balancing is one thing a reverse proxy can do, not a synonym for the whole role.





