Question

What is the difference between a reverse proxy and a load balancer?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Considerable overlap, and a real distinction: a reverse proxy sits in front of servers and handles requests on their behalf; a load balancer distributes requests across several servers. Most modern software does both, which is why the terms blur.

Forward proxy vs reverse proxy, first, because this trips people up:

A forward proxy acts on behalf of clients, sitting between users and the internet — corporate web filtering, for example.

A reverse proxy acts on behalf of servers, sitting between the internet and your infrastructure. Clients believe they are talking to the real server.

What a reverse proxy does beyond forwarding:

TLS termination, so certificates are managed in one place rather than on every backend.

Caching of responses.

Compression.

Request routing by path or hostname, so one address serves several applications.

Hiding internal structure, so backend addresses and software are not exposed.

Authentication and rate limiting applied centrally.

What a load balancer adds:

Distribution algorithms — round robin, least connections, weighted, or hashing on a client attribute.

Health checks, removing failed backends from rotation automatically. This is the feature that actually matters, and it is what makes a load balancer a resilience tool rather than merely a distribution one.

Session persistence (sticky sessions), keeping a user on the same backend where the application requires it.

Layer 4 vs layer 7. A layer 4 load balancer works at TCP level — fast, protocol-agnostic, and blind to content. A layer 7 balancer understands HTTP and can route on paths, headers and cookies, at some cost in overhead. A reverse proxy is inherently layer 7.

Where each fits: a reverse proxy alone in front of a single application server is common and useful; a load balancer is needed once there is more than one backend or uptime requires removing a failed one automatically.

Common implementations — nginx, HAProxy, Traefik, Envoy and cloud-managed services — mostly perform both roles, which is why the labels are used interchangeably in practice.

Note that a load balancer is itself a single point of failure unless deployed redundantly, which is the mistake worth avoiding.

Related Questions