Network and System AdministrationUnit 611 min read
Web & Proxy Servers: Config, Security & Performance
Unit 6 of Network and System Administration explores web server (Apache/Nginx) and proxy server (Squid) configurations, HTTP/HTTPS protocols, virtual hosting, caching, security hardening, and real-world deployment scenarios like eSewa’s payment gateway and Daraz’s CDN integration.
TAKEAWAYS:
- Understand web server architecture (Apache vs. Nginx) and how they process HTTP requests using virtual hosts and reverse proxy setups.
- Configure HTTPS with SSL/TLS certificates (Let’s Encrypt) and secure headers to protect against OWASP Top 10 threats like XSS and CSRF.
- Optimize performance using caching layers (browser, proxy, CDN) and load balancing (round-robin, least connections).
- Deploy proxy servers (Squid) for content filtering, anonymity, and traffic acceleration in corporate networks or ISPs like NTC.
- Troubleshoot common errors (404, 500, mixed-content warnings) using server logs and
curl/digtools. - Compare on-premise vs. cloud-based web servers (e.g., Daraz’s AWS vs. a local Apache setup for a small business).
Core Concepts: Web Servers
A web server is software that delivers web content (HTML, CSS, JS, images) to clients (browsers) via HTTP/HTTPS. The two most widely used open-source servers are:
- Apache HTTP Server: Modular, feature-rich (
.htaccessfiles,.confconfigs), widely used in shared hosting (e.g., Nepali blogs on Hostinger). - Nginx: Event-driven, high-performance (handles ~10,000+ concurrent connections), preferred for high-traffic sites (e.g., YouTube, Netflix).
classDiagram
class WebServer {
+Process HTTP/HTTPS requests
+Host virtual websites
+Serve static/dynamic content
+Log access/error events
}
class Apache {
+Modular (MPM: prefork/worker)
+`.conf`/`.htaccess` configs
+Supports PHP via mod_php
}
class Nginx {
+Event-driven (non-blocking I/O)
+Reverse proxy capabilities
+Lightweight (low memory usage)
}
WebServer <|-- Apache
WebServer <|-- NginxHow a Web Server Works: Request-Response Cycle
- Client sends an HTTP request (e.g.,
GET /index.html). - Server processes the request:
- Checks for static files (serves directly).
- For dynamic content (PHP/Python), forwards to backend (e.g., Apache → PHP-FPM).
- Response sent back with headers (e.g.,
Content-Type: text/html) and body.
sequenceDiagram
Client->>WebServer: HTTP GET /home (Host: example.com)
WebServer->>DNS: Resolve example.com → 192.0.2.1
WebServer->>Apache/Nginx: Route to virtual host
Apache/Nginx->>StaticFiles: Check /var/www/html/index.html
StaticFiles-->>Apache/Nginx: File found
Apache/Nginx-->>Client: HTTP 200 OK + HTMLVirtual Hosting: Hosting Multiple Websites on One Server
Virtual hosting allows a single server to host multiple websites using:
- Name-based: Different
ServerNamedirectives in configs (e.g.,example.comvs.blog.example.com). - IP-based: Each site binds to a unique IP (rare today due to IPv4 exhaustion).
classDiagram
class VirtualHost {
+Name-based or IP-based
+Isolates configs (DocumentRoot, SSL certs)
+Supports multiple domains on one IP (HTTP/2)
}
VirtualHost "1" --> "1" Website
Website: example.com
Website: blog.example.com
Website: shop.example.comExample: Configuring Apache for Two Sites
<VirtualHost *:80>
ServerName example.com
DocumentRoot /var/www/example
ErrorLog /var/log/apache2/example-error.log
</VirtualHost>
<VirtualHost *:80>
ServerName blog.example.com
DocumentRoot /var/www/blog
ErrorLog /var/log/apache2/blog-error.log
</VirtualHost>
Proxy Servers: Squid and Reverse Proxies
A proxy server acts as an intermediary between clients and servers. Types:
- Forward Proxy: Clients configure proxy to access internet anonymously (e.g., corporate networks).
- Reverse Proxy: Hides origin servers (e.g., Nginx → Apache for load balancing).
Squid Proxy Server
- Use Cases:
- Caching frequently accessed content (reduces bandwidth, e.g., NTC caching popular websites).
- Content filtering (block adult sites in schools).
- Anonymity (hide client IPs from servers).
- Config Example:
acl allowed_sites dstdomain .google.com .youtube.com http_access allow allowed_sites http_access deny all
graph TD
A["Client"] -->|"HTTP Request"| B["Squid Proxy"]
B -->|"Cache Hit?"| C{"Yes/No"}
C -->|"No"| D["Forward to Origin Server"]
D -->|"Response"| B
B -->|"Cache"| E["Store Response"]
B -->|"HTTP Response"| AHTTPS and SSL/TLS: Securing Web Traffic
HTTPS encrypts data using SSL/TLS certificates. Key steps:
- Generate CSR (Certificate Signing Request) on the server.
- Obtain certificate from CA (e.g., Let’s Encrypt for free).
- Configure server to use the certificate.
Example: Nginx SSL Config
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
# Security headers
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";
}
Security Headers to Harden Web Servers
| Header | Purpose | Example Value |
|---|---|---|
Content-Security-Policy |
Mitigate XSS attacks | default-src 'self'; script-src 'self' |
X-Frame-Options |
Prevent clickjacking | DENY |
X-Content-Type-Options |
Stop MIME sniffing | nosniff |
Referrer-Policy |
Control referrer leaks | no-referrer |
Performance Optimization: Caching and Load Balancing
1. Caching Layers
| Layer | Example Technologies | Purpose |
|---|---|---|
| Browser | Cache-Control: max-age=3600 |
Reduce repeat requests for static files |
| Proxy | Squid, Varnish | Cache responses for multiple clients |
| CDN | Cloudflare, Akamai | Distribute content globally (e.g., Daraz) |
| Server | mod_cache (Apache), proxy_cache (Nginx) |
Cache dynamic content |
2. Load Balancing
- Round Robin: Distributes requests sequentially across servers.
- Least Connections: Sends traffic to the least busy server.
- IP Hash: Ensures a client always connects to the same backend (session persistence).
graph LR
A["Client"] --> B["Load Balancer"]
B --> C1["Web Server 1"]
B --> C2["Web Server 2"]
B --> C3["Web Server 3"]Example: Nginx Load Balancing Config
upstream backend {
least_conn;
server 192.168.1.10:80;
server 192.168.1.11:80;
}
server {
location / {
proxy_pass http://backend;
}
}
In the Real World
eSewa (Nepal):
- Uses reverse proxy (Nginx) to route traffic between frontend (React) and backend (Java/Spring Boot).
- HTTPS secures payment transactions (PCI-DSS compliance).
- Caching (Redis) speeds up frequent API calls (e.g., balance checks).
Daraz (Alibaba Group):
- CDN (Cloudflare/Akamai) caches product images globally to reduce latency for Nepali users.
- Load balancing distributes orders across servers during sales (e.g., 11.11 Singles’ Day).
- Proxy servers filter malicious traffic (e.g., DDoS attacks).
NTC (Nepal Telecom):
- Squid proxy caches popular websites (e.g., YouTube, Facebook) to reduce bandwidth costs.
- Transparent proxy monitors traffic for compliance (e.g., blocking pirated content).
Nepal Stock Exchange (NEPSE):
- HTTPS + HSTS secures real-time stock data feeds.
- Rate limiting (Nginx
limit_req) prevents abuse of the API.
Worked Example: Configuring a Secure Web Server for a Nepali Blog
Scenario: You manage a blog (nepalitips.com) hosted on a VPS. Configure Apache to:
- Serve the blog from
/var/www/nepalitips. - Enable HTTPS with Let’s Encrypt.
- Block hotlinking (prevent other sites from embedding your images).
- Cache static files for 1 day.
Solution:
<VirtualHost *:80>
ServerName nepalitips.com
DocumentRoot /var/www/nepalitips
Redirect permanent / https://nepalitips.com/
</VirtualHost>
<VirtualHost *:443>
ServerName nepalitips.com
DocumentRoot /var/www/nepalitips
SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/nepalitips.com/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/nepalitips.com/privkey.pem
# Block hotlinking
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^https://nepalitips\.com/ [NC]
RewriteCond %{HTTP_REFERER} !^https://www\.nepalitips\.com/ [NC]
RewriteRule \.(jpg|png|gif)$ - [NC,F,L]
# Cache static files
<FilesMatch "\.(ico|pdf|flv|jpg|jpeg|png|gif|js|css|swf)$">
Header set Cache-Control "max-age=86400, public"
</FilesMatch>
</VirtualHost>
Proxy Server in Action: NTC’s Traffic Optimization
Scenario: NTC wants to reduce bandwidth usage by caching popular websites (e.g., YouTube, Facebook) for its 10M+ users.
Squid Config Snippet:
# Cache frequently accessed domains
acl popular_sites dstdomain .youtube.com .facebook.com .google.com
cache allow popular_sites
cache deny all
# Cache for 24 hours
cache_store_log none
cache_mem 256 MB
maximum_object_size 256 MB
cache_dir ufs /var/spool/squid 100 16 256
Impact:
- Bandwidth savings: 30–50% reduction in outbound traffic.
- Faster access: Users experience lower latency for cached content.
- Cost reduction: Fewer peering costs with international ISPs.
Common Pitfalls and Troubleshooting
| Issue | Cause | Solution |
|---|---|---|
| 500 Internal Server Error | PHP syntax error or missing file | Check /var/log/apache2/error.log |
| Mixed Content Warnings | HTTP resources on HTTPS page | Use Content Security Policy or fix URLs |
| Proxy Authentication Failed | Incorrect acl or auth config |
Verify squid.conf and client settings |
| High CPU Usage | Too many concurrent connections | Tune worker_connections (Nginx) or MaxClients (Apache) |
Tools for Debugging:
curl -I https://example.com→ Check headers.dig example.com→ Test DNS resolution.tail -f /var/log/apache2/access.log→ Monitor requests.
Exam Tip
Diagrams are worth marks: Always draw:
- Layered models (e.g., web server → reverse proxy → load balancer).
- Packet flows (e.g., HTTP request → proxy → origin server).
- Network topologies (e.g., CDN nodes for Daraz).
Compare Apache vs. Nginx:
- Use a table with columns: Use Case, Config File, Performance, Security Features.
Real-world scenarios:
- Explain how eSewa uses HTTPS to secure payments (mention HSTS, OCSP stapling).
- Describe NTC’s Squid proxy setup (cache hit/miss, ACLs).
Config snippets:
- Memorize key directives:
- Apache:
<VirtualHost>,SSLEngine,mod_security. - Nginx:
proxy_pass,ssl_certificate,add_header. - Squid:
acl,cache,http_access.
- Apache:
- Memorize key directives:
Security:
- Always mention OWASP Top 10 (e.g., "Prevent XSS with
Content-Security-Policy"). - For proxy servers, discuss anonymity vs. filtering trade-offs.
- Always mention OWASP Top 10 (e.g., "Prevent XSS with
Based on the TU BSc CSIT syllabus for Network and System Administration, unit 6.
Discussion
Loading…