Proxies & Reverse Proxies
Forward, reverse and transparent: who is really talking to whom, who sees the client address, who ends TLS, and how to read a 502, a 503 and a 407.
An interactive Networking lesson: 21 steps, about 32 minutes, on a live simulation in your browser.
The shop runs on three servers, web-1, web-2 and web-3, and customers know a single address: 203.0.113.80, on the proxy. Switch it to layer 7 and send one request. The client's connection ends at the proxy, which reads the request and opens its own connection to web-1.
This machine is a reverse proxy: it speaks for the servers. Clients configure nothing and address only the proxy; it chooses a backend per request. (How it picks, and its layer-4 mode, belong to Load Balancers: L4 vs L7. Here the questions are: who sees what, and who ends TLS.)
What you will learn
One door in front of the shop
- The shop moves behind one door: A reverse proxy speaks for the server: clients address only the proxy, and it makes a new request of its own to a backend.
- What does the backend log?
- Two proxies, opposite directions: Reverse speaks for the server and is invisible to the client. Forward speaks for the client and is invisible to the server.
Who sees the client?
- The header that names the client: Behind a reverse proxy the backend's peer is always the proxy. The client's address survives only inside the request, in X-Forwarded-For.
- Who can lie in X-Forwarded-For?: X-Forwarded-For is a chain, and anyone can prepend to it. Trust only the entry your own proxy appended.
- Logging the real address
Where TLS ends
- TLS ends at the proxy: A reverse proxy that reads requests terminates TLS: the client encrypts to the proxy, and the proxy talks plain HTTP behind it.
- Plain HTTP behind the proxy
- Drill: whose certificate is this?
Reading 502 and 503
- 502: the backend it asked failed
- 503: nobody left to ask
- Break it: the API goes dark alone
The office forward proxy
- A proxy for the staff: A forward proxy is chosen by the client: browsers point at it, and servers cannot tell it is there.
- Drill: send curl via the proxy
- CONNECT: a tunnel, not a request: CONNECT asks the proxy for a tunnel to host:port. After 200, the proxy copies TLS bytes it cannot read.
- What does CONNECT hide?: A forward proxy sees who you connect to, never what you say there: hostname in the clear, everything else under TLS.
- Break it: who are you?
Request shapes and Via
- absolute-URI vs origin-form: To a forward proxy: GET the full URL. To the origin: GET the path. Via records every proxy the response crossed.
- Which proxy, and the third kind: Reverse publishes sites; forward supervises clients; transparent intercepts without being asked, and only reads what clients trust it with.
Recap & playground
- Cheat sheet
- Playground