Elective Network and System Administration

Network and System AdministrationUnit 611 min read

Web & Proxy Servers: Config, Security & Performance

Unit 6 of Network and System Administration explores web server (Apache/Nginx) and proxy server (Squid) configurations, HTTP/HTTPS protocols, virtual hosting, caching, security hardening, and real-world deployment scenarios like eSewa’s payment gateway and Daraz’s CDN integration.

TAKEAWAYS:

  • Understand web server architecture (Apache vs. Nginx) and how they process HTTP requests using virtual hosts and reverse proxy setups.
  • Configure HTTPS with SSL/TLS certificates (Let’s Encrypt) and secure headers to protect against OWASP Top 10 threats like XSS and CSRF.
  • Optimize performance using caching layers (browser, proxy, CDN) and load balancing (round-robin, least connections).
  • Deploy proxy servers (Squid) for content filtering, anonymity, and traffic acceleration in corporate networks or ISPs like NTC.
  • Troubleshoot common errors (404, 500, mixed-content warnings) using server logs and curl/dig tools.
  • Compare on-premise vs. cloud-based web servers (e.g., Daraz’s AWS vs. a local Apache setup for a small business).

Core Concepts: Web Servers

A web server is software that delivers web content (HTML, CSS, JS, images) to clients (browsers) via HTTP/HTTPS. The two most widely used open-source servers are:

  • Apache HTTP Server: Modular, feature-rich (.htaccess files, .conf configs), widely used in shared hosting (e.g., Nepali blogs on Hostinger).
  • Nginx: Event-driven, high-performance (handles ~10,000+ concurrent connections), preferred for high-traffic sites (e.g., YouTube, Netflix).
classDiagram
    class WebServer {
        +Process HTTP/HTTPS requests
        +Host virtual websites
        +Serve static/dynamic content
        +Log access/error events
    }
    class Apache {
        +Modular (MPM: prefork/worker)
        +`.conf`/`.htaccess` configs
        +Supports PHP via mod_php
    }
    class Nginx {
        +Event-driven (non-blocking I/O)
        +Reverse proxy capabilities
        +Lightweight (low memory usage)
    }
    WebServer <|-- Apache
    WebServer <|-- Nginx

How a Web Server Works: Request-Response Cycle

  1. Client sends an HTTP request (e.g., GET /index.html).
  2. Server processes the request:
    • Checks for static files (serves directly).
    • For dynamic content (PHP/Python), forwards to backend (e.g., Apache → PHP-FPM).
  3. Response sent back with headers (e.g., Content-Type: text/html) and body.
sequenceDiagram
    Client->>WebServer: HTTP GET /home (Host: example.com)
    WebServer->>DNS: Resolve example.com → 192.0.2.1
    WebServer->>Apache/Nginx: Route to virtual host
    Apache/Nginx->>StaticFiles: Check /var/www/html/index.html
    StaticFiles-->>Apache/Nginx: File found
    Apache/Nginx-->>Client: HTTP 200 OK + HTML

Virtual Hosting: Hosting Multiple Websites on One Server

Virtual hosting allows a single server to host multiple websites using:

  • Name-based: Different ServerName directives in configs (e.g., example.com vs. blog.example.com).
  • IP-based: Each site binds to a unique IP (rare today due to IPv4 exhaustion).
classDiagram
    class VirtualHost {
        +Name-based or IP-based
        +Isolates configs (DocumentRoot, SSL certs)
        +Supports multiple domains on one IP (HTTP/2)
    }
    VirtualHost "1" --> "1" Website
    Website: example.com
    Website: blog.example.com
    Website: shop.example.com

Example: Configuring Apache for Two Sites

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /var/www/example
    ErrorLog /var/log/apache2/example-error.log
</VirtualHost>

<VirtualHost *:80>
    ServerName blog.example.com
    DocumentRoot /var/www/blog
    ErrorLog /var/log/apache2/blog-error.log
</VirtualHost>

Proxy Servers: Squid and Reverse Proxies

A proxy server acts as an intermediary between clients and servers. Types:

  1. Forward Proxy: Clients configure proxy to access internet anonymously (e.g., corporate networks).
  2. Reverse Proxy: Hides origin servers (e.g., Nginx → Apache for load balancing).

Squid Proxy Server

  • Use Cases:
    • Caching frequently accessed content (reduces bandwidth, e.g., NTC caching popular websites).
    • Content filtering (block adult sites in schools).
    • Anonymity (hide client IPs from servers).
  • Config Example:
    acl allowed_sites dstdomain .google.com .youtube.com
    http_access allow allowed_sites
    http_access deny all
    
graph TD
    A["Client"] -->|"HTTP Request"| B["Squid Proxy"]
    B -->|"Cache Hit?"| C{"Yes/No"}
    C -->|"No"| D["Forward to Origin Server"]
    D -->|"Response"| B
    B -->|"Cache"| E["Store Response"]
    B -->|"HTTP Response"| A

HTTPS and SSL/TLS: Securing Web Traffic

HTTPS encrypts data using SSL/TLS certificates. Key steps:

  1. Generate CSR (Certificate Signing Request) on the server.
  2. Obtain certificate from CA (e.g., Let’s Encrypt for free).
  3. Configure server to use the certificate.

Example: Nginx SSL Config

server {
    listen 443 ssl;
    server_name example.com;
    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    # Security headers
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";
}

Security Headers to Harden Web Servers

Header Purpose Example Value
Content-Security-Policy Mitigate XSS attacks default-src 'self'; script-src 'self'
X-Frame-Options Prevent clickjacking DENY
X-Content-Type-Options Stop MIME sniffing nosniff
Referrer-Policy Control referrer leaks no-referrer

Performance Optimization: Caching and Load Balancing

1. Caching Layers

Layer Example Technologies Purpose
Browser Cache-Control: max-age=3600 Reduce repeat requests for static files
Proxy Squid, Varnish Cache responses for multiple clients
CDN Cloudflare, Akamai Distribute content globally (e.g., Daraz)
Server mod_cache (Apache), proxy_cache (Nginx) Cache dynamic content

2. Load Balancing

  • Round Robin: Distributes requests sequentially across servers.
  • Least Connections: Sends traffic to the least busy server.
  • IP Hash: Ensures a client always connects to the same backend (session persistence).
graph LR
    A["Client"] --> B["Load Balancer"]
    B --> C1["Web Server 1"]
    B --> C2["Web Server 2"]
    B --> C3["Web Server 3"]

Example: Nginx Load Balancing Config

upstream backend {
    least_conn;
    server 192.168.1.10:80;
    server 192.168.1.11:80;
}

server {
    location / {
        proxy_pass http://backend;
    }
}

In the Real World

  1. eSewa (Nepal):

    • Uses reverse proxy (Nginx) to route traffic between frontend (React) and backend (Java/Spring Boot).
    • HTTPS secures payment transactions (PCI-DSS compliance).
    • Caching (Redis) speeds up frequent API calls (e.g., balance checks).
  2. Daraz (Alibaba Group):

    • CDN (Cloudflare/Akamai) caches product images globally to reduce latency for Nepali users.
    • Load balancing distributes orders across servers during sales (e.g., 11.11 Singles’ Day).
    • Proxy servers filter malicious traffic (e.g., DDoS attacks).
  3. NTC (Nepal Telecom):

    • Squid proxy caches popular websites (e.g., YouTube, Facebook) to reduce bandwidth costs.
    • Transparent proxy monitors traffic for compliance (e.g., blocking pirated content).
  4. Nepal Stock Exchange (NEPSE):

    • HTTPS + HSTS secures real-time stock data feeds.
    • Rate limiting (Nginx limit_req) prevents abuse of the API.

Worked Example: Configuring a Secure Web Server for a Nepali Blog

Scenario: You manage a blog (nepalitips.com) hosted on a VPS. Configure Apache to:

  1. Serve the blog from /var/www/nepalitips.
  2. Enable HTTPS with Let’s Encrypt.
  3. Block hotlinking (prevent other sites from embedding your images).
  4. Cache static files for 1 day.

Solution:

<VirtualHost *:80>
    ServerName nepalitips.com
    DocumentRoot /var/www/nepalitips
    Redirect permanent / https://nepalitips.com/
</VirtualHost>

<VirtualHost *:443>
    ServerName nepalitips.com
    DocumentRoot /var/www/nepalitips
    SSLEngine on
    SSLCertificateFile /etc/letsencrypt/live/nepalitips.com/cert.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/nepalitips.com/privkey.pem

    # Block hotlinking
    RewriteEngine On
    RewriteCond %{HTTP_REFERER} !^https://nepalitips\.com/ [NC]
    RewriteCond %{HTTP_REFERER} !^https://www\.nepalitips\.com/ [NC]
    RewriteRule \.(jpg|png|gif)$ - [NC,F,L]

    # Cache static files
    <FilesMatch "\.(ico|pdf|flv|jpg|jpeg|png|gif|js|css|swf)$">
        Header set Cache-Control "max-age=86400, public"
    </FilesMatch>
</VirtualHost>

Proxy Server in Action: NTC’s Traffic Optimization

Scenario: NTC wants to reduce bandwidth usage by caching popular websites (e.g., YouTube, Facebook) for its 10M+ users.

Squid Config Snippet:

# Cache frequently accessed domains
acl popular_sites dstdomain .youtube.com .facebook.com .google.com
cache allow popular_sites
cache deny all

# Cache for 24 hours
cache_store_log none
cache_mem 256 MB
maximum_object_size 256 MB
cache_dir ufs /var/spool/squid 100 16 256

Impact:

  • Bandwidth savings: 30–50% reduction in outbound traffic.
  • Faster access: Users experience lower latency for cached content.
  • Cost reduction: Fewer peering costs with international ISPs.

Common Pitfalls and Troubleshooting

Issue Cause Solution
500 Internal Server Error PHP syntax error or missing file Check /var/log/apache2/error.log
Mixed Content Warnings HTTP resources on HTTPS page Use Content Security Policy or fix URLs
Proxy Authentication Failed Incorrect acl or auth config Verify squid.conf and client settings
High CPU Usage Too many concurrent connections Tune worker_connections (Nginx) or MaxClients (Apache)

Tools for Debugging:

  • curl -I https://example.com → Check headers.
  • dig example.com → Test DNS resolution.
  • tail -f /var/log/apache2/access.log → Monitor requests.

Exam Tip

  1. Diagrams are worth marks: Always draw:

    • Layered models (e.g., web server → reverse proxy → load balancer).
    • Packet flows (e.g., HTTP request → proxy → origin server).
    • Network topologies (e.g., CDN nodes for Daraz).
  2. Compare Apache vs. Nginx:

    • Use a table with columns: Use Case, Config File, Performance, Security Features.
  3. Real-world scenarios:

    • Explain how eSewa uses HTTPS to secure payments (mention HSTS, OCSP stapling).
    • Describe NTC’s Squid proxy setup (cache hit/miss, ACLs).
  4. Config snippets:

    • Memorize key directives:
      • Apache: <VirtualHost>, SSLEngine, mod_security.
      • Nginx: proxy_pass, ssl_certificate, add_header.
      • Squid: acl, cache, http_access.
  5. Security:

    • Always mention OWASP Top 10 (e.g., "Prevent XSS with Content-Security-Policy").
    • For proxy servers, discuss anonymity vs. filtering trade-offs.

Based on the TU BSc CSIT syllabus for Network and System Administration, unit 6.

Discussion

Loading…