NGINX acts as a Layer 7 Reverse Proxy and Load Balancer terminating SSL/TLS certificates and routing requests based on URL paths (/api to backend Node.js, /static to S3).
Visual representation of control loops, memory layout, and execution flow for Load Balancing, Firewalls & Network Security.
Client DNS resolves to public Load Balancer Virtual IP (VIP).
Load Balancer routes only to healthy backend server instances.
Selects target backend server via Round Robin, Least Connections, or IP Hash.
| Feature / Dimension | Layer 4 Load Balancer | Layer 7 Load Balancer |
|---|---|---|
| Inspection Level | Operates on IP and TCP/UDP ports only (No payload inspection) | Operates on Application Layer (HTTP headers, cookies, URL paths) |
| Speed & Latency | Extremely fast packet routing with minimal CPU overhead | Slightly higher overhead due to SSL termination and HTTP parsing |
Detailed answers, interviewer pro tips, key takeaway summaries, and code examples formulated for technical rounds.
✅ Correction: A Forward Proxy acts on behalf of clients (hiding client IP from internet); a Reverse Proxy acts on behalf of servers (hiding backend servers from public internet).
Traffic distribution and boundary security enforcement.