Proxy server
An intermediary that ends a client's connection and opens its own onward connection, so it can filter, cache, log or hide traffic on behalf of clients or of the servers behind it.
A proxy server sits between two parties and speaks to each on the other’s behalf. The client connects to the proxy, the proxy can decide whether the request is allowed, and then it opens a separate connection to the destination. Because it handles the request itself, a proxy can read the application content, filter it, cache responses, log requests and hide the addresses on each side from the other. NIST SP 800-41 Rev 1 describes the firewall form of this idea as an application-proxy gateway, also called an application-level gateway.
A forward proxy serves internal users going out, which is the core of a secure web gateway. A reverse proxy stands in front of servers and receives inbound requests for them, often alongside a load balancer. A proxy is not network address translation: NAT rewrites addresses in packets that pass through, while a proxy ends one connection and starts another. To inspect encrypted web traffic, a proxy has to terminate the TLS session, so it sees the content in clear and must itself be protected.
Exam relevance: a scenario about filtering or caching web requests for users is likely to point to a forward proxy, and one that shields servers to a reverse proxy. Candidates are expected to tell a proxy apart from NAT and from a packet filter, which does not read application content.