Securely set up reverse proxies for internal services
A reverse proxy limits reachable destinations, sets trusted forwarding headers, and protects internal services through TLS, authentication, and limits.
"Securing Reverse Proxies for Internal Services" is discussed here from the perspective of "DNS, TLS, and Reverse Proxy." For system administrators and web developers, "Fixed Upstream" and "Open Proxy" are particularly important.
Published: 3 min read · Author: Sebastian Geier
What boundaries and headers does a secure reverse proxy need for internal services?
Only authorized hosts, paths, and internal destinations are forwarded. Host and Forwarded headers are set instead of being blindly inherited; internal ports remain blocked externally, and time and size limits are enforced at the proxy.
Open Proxy
Open Proxy – Manipulated destinations allow access to internal or external services.
Header Spoofing – The application trusts client-side Forwarded values and therefore considers incorrect client IPs or protocols to be verified.
Bypassable Proxy – The internal service remains directly accessible from the internet, bypassing access control, limits, and logging of the proxy.
Fixed Upstream
Test criterion
Fixed Upstream
Destinations are derived from configuration and never from unverified user input.
Test criterion
Header Trust
Client IP and protocol are only accepted by known proxy chains.
Closed Backside – The origin is only accessible via the designated entry path.
Header Trust
Document public paths, fixed upstreams, and trust boundaries.
Explicitly configure headers, TLS, timeouts, size limits, and access control.
Test direct access, manipulated headers, and slow upstream connections as negative cases.
Closed Backside
Control signal
Signal 1
Deny access to unauthorized hosts, paths, or internal ports.
Control signal
Signal 2
Test upstream timeouts and header deviations with a correlating request ID.
Case Study: "Open Proxy"
An internal reporting service is only accessible via /reports. The proxy sets the host and client IP addresses from a trusted chain, limits response time and body size; a direct call to the internal port fails at the network boundary.
How to Differentiate Between a Proxy Error, Congestion, and Application Outage
A relevant follow-up question answered Differentiating 503 Errors Between Congestion, Proxy, and ApplicationHow to Differentiate Between a Proxy Error, Congestion, and Application Outage in a 503 Error?
A second link for "Securing Reverse Proxies for Internal Services" leads to Mastering Relative and Absolute Paths in Nested ProjectsThis article remains focused on the question, "How do you prevent PHP includes in nested directories from suddenly using incorrect paths?"
If you want to practically implement "Securing Reverse Proxies for Internal Services," you can refer to Robust Website Systems This article focuses on "DNS, TLS, and Reverse Proxy" and "Fixed Upstream."
Conclusion: Securing Reverse Proxies for Internal Services
The proxy is a security and protocol boundary, not just a forwarder. Every permitted connection requires a defined destination and controlled context.
Sources and Further Information
The following sources document the technical and methodological guidelines used for "Securing Reverse Proxies for Internal Services."
RFC 6797: HTTP Strict Transport SecurityThe IETF standard defines HSTS behavior, scope, persistence, and security requirements.
NGINX Reverse Proxy – NGINX DocumentationThe official NGINX documentation describes upstream forwarding, headers, buffering, and proxy configuration. `` : ...
RFC 1034: Domain Names – Concepts and FacilitiesThe fundamental DNS standard defines zones, resolvers, caching, and the semantics of distributed name resolution.
Key Thesis
Only predefined upstreams and paths are forwarded; Host and Forwarded headers are set in a controlled manner. Internal ports remain blocked externally, while TLS, timeouts, size limits, and access protocols are enforced at the proxy.
What This Is Not About
A reverse proxy must not forward arbitrary destinations or allow internal services to be accessed simultaneously via open ports.
What it's about
Fixed upstreams, controlled headers, TLS, limits, and logging establish a clear public boundary.
More insights
Hosting, servers, CDN & caching
Configuring Apache and Nginx together in an understandable way
As a separate test step for "Securing reverse proxies for internal services," consider the question: How do you divide responsibilities between Nginx and Apache without duplicate rules?
Hosting, servers, CDN & caching
Run Cloudflare modes without an insecure SSL configuration
Supplements "Securing reverse proxies for internal services" with a separate decision: Which Cloudflare setting prevents a partially encrypted connection?
Insights Overview
All VELUNO Insights at a Glance
Further analyses on Website Systems, digital visibility, and robust working models.
Header trust: the first task
A diagram of the client, proxy, and upstream reveals trust and open ports. Then, headers and network rules can be secured with negative tests.