Transparent proxy
In everyday use, a transparent proxy is one that intercepts traffic without any configuration on the client, so the client does not know it is there.
In everyday use, a transparent proxy is one that intercepts traffic without any configuration on the client, so the client does not know it is there. The term is unfortunate, because the specifications use it for something else entirely.
#The naming collision
In HTTP’s own vocabulary a transparent proxy is one that does not modify the request or response beyond what proxy authentication and identification require. A non-transparent proxy is one that does modify them, to add some service. That reading says nothing about client configuration.
RFC 3040 records the clash and introduces interception proxy for the zero-configuration deployment the caching community meant, recommending that the older term always be qualified. Both meanings remain in circulation, so establish which one is intended before answering a question about one.
#How interception actually works
A network element redirects the traffic flow to the proxy, usually by policy routing or by rules on a gateway. The client still believes it is talking to the origin. Because plain HTTP carries the target host in the request, the proxy can serve it without the client’s cooperation.
Encrypted traffic is a different matter. Interception of HTTPS requires TLS interception, which requires a certificate the client already trusts. Without that, the proxy can pass the connection through or block it, but not read it. Many deployments therefore intercept plain HTTP fully and treat encrypted traffic as an opaque flow to be allowed, logged by destination, or refused.
#Detecting one
curl -sI http://example.com/ | grep -Ei 'via|x-cache|x-forwarded|server'
Look for a Via entry, an X-Forwarded-For you did not send, cache headers from software the origin does not run, or an error page in a house style. None of these is conclusive: an interception proxy can be configured to add nothing.
#Commonly confused with
A forward proxy is one you configure deliberately. The mechanics are similar; the difference is consent and configuration. A reverse proxy sits in front of a server and is deployed by that server’s operator, not by the client’s network.