Ch. 20 · Networking

Reverse Proxies and Trusted Forwarded Headers

Reverse Proxies and Trusted Forwarded Headers. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

A reverse proxy forwards requests and may add client or protocol metadata. Trust only metadata supplied through controlled proxy paths.

Before you start

You should understand clients, servers, IP addresses and ports. Follow a request through name resolution, connection establishment and application exchange. Distinguish protocol guarantees from deployment policy, and use observations from the relevant layer rather than guessing from one browser error message.

The practical goal is to reason through this situation: A server needs the original scheme when generating secure redirects behind a proxy. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Identify trusted hops

Know which proxies can supply authentic forwarding metadata.

Step 2: Control incoming headers

Untrusted client values must not masquerade as proxy observations.

Step 3: Test direct and proxied access

Trust configuration should match real deployment paths.

Worked scenario

A server needs the original scheme when generating secure redirects behind a proxy.

A client sets a forwarded-protocol header to claim HTTPS. If the backend blindly trusts it, generated redirects or security decisions may use fabricated context. The trusted proxy should manage header replacement or appending according to a defined chain, and the backend should trust only that controlled path.

Common mistake

Trusting arbitrary client-supplied forwarding headers can spoof addresses or scheme.

Verify the behavior

Try spoofed headers on direct access and verify legitimate proxy metadata separately.

Interview exercise

Configure proxy trust.

Answer and reasoning

Identify trusted hops and how headers are replaced or appended, then test direct and proxied access.

Continue learning

Compare the scenario with the Networking interview questions and test your understanding with the Networking MCQs. For terminology and implementation details, consult the reference material.

More in Networking

read ✓Networking · mid

Networking: DNS Caching and TTL

Understand positive and negative caching, why changes are not instant, and how TTL trades propagation speed against query load.

~2 min readread →
read ✓Networking · easy

Networking: DNS Record Types

Read and choose DNS records: A and AAAA for addresses, CNAME for aliases, and MX and TXT for mail and verification.

~2 min readread →
read ✓Networking · mid

Networking: HTTP Redirects

Choose between 301, 302, 307 and 308, know which preserve the request method, and avoid caching and loop mistakes.

~2 min readread →
esc