Зворотний проксі (reverse proxy)
Сервер, що стоїть перед одним або кількома вебсерверами й передає їм вхідні клієнтські запити, приховуючи бекенд від клієнта.
Зворотний проксі - це сервер, який приймає запити від клієнтів від імені одного або кількох бекенд-серверів, потім передає кожен запит потрібному бекенду й повертає відповідь. З точки зору клієнта зворотний проксі і є сайт - реальні сервери за ним приховані.
Це дзеркальне відображення прямого проксі. Прямий проксі працює від імені клієнтів, щоб дістатися до зовнішнього інтернету (приховуючи клієнта). Зворотний проксі працює від імені серверів, щоб приймати трафік з інтернету (приховуючи сервери). Той самий принцип посередника, але у зворотному напрямку.
Зворотні проксі - базова вебінфраструктура. Вони займаються балансуванням навантаження (розподіл трафіку по кількох бекендах), термінацією SSL/TLS (розшифрування HTTPS, щоб бекендам не довелося), кешуванням (віддача повторюваних відповідей без звернення до бекенду) і фільтрацією безпеки (блокування шкідливих запитів до потрапляння в застосунок). Nginx, HAProxy і Cloudflare - типові зворотні проксі.
Для тих, хто займається скрапінгом, зворотні проксі важливі тому, що саме там часто живуть антибот-системи. Cloudflare, Akamai і подібні сервіси працюють як зворотні проксі перед цільовими сайтами, інспектуючи вхідні запити й челенджа або блокуючи ті, що мають автоматизований вигляд. Розуміння цього пояснює, чому запити блокуються ще до того, як досягнуть реального сервера.
The proxy that belongs to the website
A forward proxy acts for the client. A reverse proxy acts for the server: it sits in front of an origin, accepts connections from the public, and decides what to do with them before anything reaches the application behind it.
Reverse proxies handle TLS termination, caching, load balancing and, most relevantly here, filtering. Cloudflare, Fastly and similar services are reverse proxies operated as a product, which is why so many of the blocks you meet come from infrastructure rather than from the site itself.
This is why two different sites can block you in exactly the same way, with the same challenge page and the same signals. You are not meeting their rules, you are meeting their vendor's.
What this means for your setup
When the block comes from a reverse proxy, the fix is about signals rather than the site:
Recognising the layer
Challenge page from a known vendor -> you are being scored, not banned
Same block pattern across sites -> shared vendor, shared ruleset
Server header naming a CDN -> a reverse proxy is in front
curl -I https://example.com | grep -i 'server\|cf-ray'- A vendor scoring system weighs address class, TLS fingerprint and behaviour. Improving one moves the score, and the address is the one we sell.
- Because rules are shared across customers, a setup that clears one site often clears others using the same vendor.
- Rate limits are frequently enforced at this layer too, which is why they feel identical across unrelated sites.
- None of this is defeated by rotating addresses alone if your client announces itself in the handshake.
Forward and reverse mixed up
A reverse proxy is not something you buy from us
We sell forward proxies. A reverse proxy protects a site you do not own.
It is not the site's own decision
The vendor's default rules block a great deal that the site owner never considered.
Bypassing it is not a product feature
Anyone selling a guaranteed bypass is selling something that stops working the week the vendor updates.
It does explain identical blocks
Meeting the same challenge on unrelated sites means one vendor, not a coordinated ban.
Пов'язані терміни
Дивись на практиці
Готовий використовувати зворотний проксі (reverse proxy)?
SotaProxy надає доступ до ротуючих резидентських, мобільних, дата-центр та ISP проксі. Без мінімальних платежів.
Почати