learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Proxies & Reverse Proxies

Forward, reverse and transparent: who is really talking to whom, who sees the client address, who ends TLS, and how to read a 502, a 503 and a 407.

An interactive Networking lesson: 21 steps, about 32 minutes, on a live simulation in your browser.

The shop runs on three servers, web-1, web-2 and web-3, and customers know a single address: 203.0.113.80, on the proxy. Switch it to layer 7 and send one request. The client's connection ends at the proxy, which reads the request and opens its own connection to web-1.

This machine is a reverse proxy: it speaks for the servers. Clients configure nothing and address only the proxy; it chooses a backend per request. (How it picks, and its layer-4 mode, belong to Load Balancers: L4 vs L7. Here the questions are: who sees what, and who ends TLS.)

What you will learn

  1. One door in front of the shop

    • The shop moves behind one door: A reverse proxy speaks for the server: clients address only the proxy, and it makes a new request of its own to a backend.
    • What does the backend log?
    • Two proxies, opposite directions: Reverse speaks for the server and is invisible to the client. Forward speaks for the client and is invisible to the server.
  2. Who sees the client?

    • The header that names the client: Behind a reverse proxy the backend's peer is always the proxy. The client's address survives only inside the request, in X-Forwarded-For.
    • Who can lie in X-Forwarded-For?: X-Forwarded-For is a chain, and anyone can prepend to it. Trust only the entry your own proxy appended.
    • Logging the real address
  3. Where TLS ends

    • TLS ends at the proxy: A reverse proxy that reads requests terminates TLS: the client encrypts to the proxy, and the proxy talks plain HTTP behind it.
    • Plain HTTP behind the proxy
    • Drill: whose certificate is this?
  4. Reading 502 and 503

    • 502: the backend it asked failed
    • 503: nobody left to ask
    • Break it: the API goes dark alone
  5. The office forward proxy

    • A proxy for the staff: A forward proxy is chosen by the client: browsers point at it, and servers cannot tell it is there.
    • Drill: send curl via the proxy
    • CONNECT: a tunnel, not a request: CONNECT asks the proxy for a tunnel to host:port. After 200, the proxy copies TLS bytes it cannot read.
    • What does CONNECT hide?: A forward proxy sees who you connect to, never what you say there: hostname in the clear, everything else under TLS.
    • Break it: who are you?
  6. Request shapes and Via

    • absolute-URI vs origin-form: To a forward proxy: GET the full URL. To the origin: GET the path. Via records every proxy the response crossed.
    • Which proxy, and the third kind: Reverse publishes sites; forward supervises clients; transparent intercepts without being asked, and only reads what clients trust it with.
  7. Recap & playground

    • Cheat sheet
    • Playground