In this chapter
We'll meet the helpers that sit in the middle of internet traffic — proxies (a receptionist who passes messages), reverse proxies (a company's front desk), firewalls (a security guard with a list) and CDNs (local branch warehouses) — and use them to finish the Northgate investigation.
The Problem in Real Life
The Northgate fix worked, but the college's IT manager writes back with a question: "Our firewall and proxy logs show your site was blocked for some students even before the DNS issue. Can you check?"
Anna has heard all three words — firewall, proxy, CDN — but only as vague network things. John grabs the marker one last time this week. "These are the helpers in the middle of the road. Some pass messages on, some stop them, some answer from a copy. Let's meet them."
So between the student and us there are people checking, forwarding and copying everything?
Anna
A Direct Line vs. Helpers in the Middle
Traffic rarely goes straight
Between a client and a server, requests often pass through several helpers.
Some helpers protect
Firewalls decide what's allowed in and out of a network.
Some helpers speed things up
CDNs keep copies of content close to users, so it arrives faster.
Proxies, Reverse Proxies, Firewalls and CDNs
Each helper has a simple everyday version.
- Proxy — a receptionist who sends messages for you: a proxy (or forward proxy) is a server that makes requests on behalf of clients. On many campuses and in many companies, every student's browser sends its web requests to the proxy, and the proxy fetches the page and passes it back — like a receptionist who places calls for everyone in an office. Organisations use proxies to filter websites, log usage and cache popular pages. To the outside world, all the requests seem to come from the proxy.
- Reverse proxy — a company's front desk: a reverse proxy sits in front of servers, not clients. Visitors talk to the front desk, and the desk forwards each request to the right person inside. Visitors never see the internal offices. BlueTicket has one: every request to
blueticket.examplefirst reaches a reverse proxy, which handles the HTTPS envelope (TLS), and passes the request to the right app server behind it. Reverse proxies also spread load across several servers — which is what a load balancer does (Act 14) — and come back in Act 19. - Firewall — a security guard with a list: a firewall checks every packet or connection against rules and allows or blocks it — like a guard at a gate with a list of allowed visitors and doors. Rules can be about addresses ("block this IP"), ports ("only allow 80 and 443 from outside") or programs. Every serious network has one: the campus, BlueTicket's servers, even your laptop. A firewall usually blocks everything coming in except what's explicitly allowed.
- CDN — local branch warehouses: a CDN (Content Delivery Network) is a network of servers spread around the world that keep copies of a website's files — images, styles, scripts, even whole pages — close to users. Instead of every fan's request travelling to BlueTicket's server in one city, the CDN answers from a nearby branch, like a company that stocks its most popular products in local warehouses so customers get them the same day. Pages load faster, and the main server handles far fewer requests.
| Helper | Everyday version | Sits in front of | Main job |
|---|---|---|---|
| Proxy (forward) | An office receptionist placing calls | Clients | Filter, log and cache outgoing requests |
| Reverse proxy | A company's front desk | Servers | Receive requests, handle TLS, forward to servers |
| Firewall | A security guard with a list | A network or a machine | Allow or block traffic by rules |
| CDN | Local branch warehouses | A website's content | Serve copies close to users, faster |
| Step | Question | What to try |
|---|---|---|
| 1 | Is their network working at all? | Can they open any other website? |
| 2 | Does the name give the right address? | nslookup — compare with a public resolver |
| 3 | Can they connect to that address and port? | Firewall rules, ping, a test connection to port 443 |
| 4 | Is the certificate valid? | Browser warnings, expiry date (TLS) |
| 5 | What status code comes back? | Browser Network tab (HTTP) |
| 6 | Is something in the middle serving an old copy? | Proxy or CDN cache |
Where the helpers sit
Student's browser
on campus
Campus firewall and proxy
checks rules · forwards requests · may cache
CDN
nearby copy of images, styles, pages
BlueTicket's firewall + reverse proxy
front desk: TLS, then to an app server
BlueTicket app server
builds the real answer
Finishing the Northgate investigation: Anna reads the college's logs. The campus proxy had cached a copy of BlueTicket's home page from before the move, and the campus firewall had a rule — added years ago — allowing outgoing traffic only to a list of known addresses, which still listed the old server, not the new one. So even after the DNS cache was cleared, a few students whose traffic went through the strictest firewall profile were still blocked. Northgate's IT team updates the firewall rule and clears the proxy cache. The college's error reports drop to zero.
What Anna learned about debugging networks: check the road one stop at a time. Can you reach any website at all (the local network)? Does the name resolve to the right address (DNS)? Can you connect to that address and port (firewall, TCP)? Is the certificate valid (TLS)? What status code comes back (HTTP)? Is something in the middle answering with an old copy (proxy, CDN)? She writes these six questions on a card and pins it above her desk.
Her email to the college: she explains everything in plain language — what was wrong, what they changed, and how to avoid it next time (respect DNS TTLs, review firewall allowlists, don't cache pages longer than the site allows). John reads it before she sends it and nods: "That's how you prove a problem is outside our system — calmly, with evidence, and with a fix they can follow."
Key Takeaway
Helpers in the middle shape most internet traffic: a proxy makes requests on behalf of clients (an office receptionist), a reverse proxy sits in front of servers and forwards requests to them (a company's front desk), a firewall allows or blocks traffic by rules (a security guard with a list), and a CDN serves copies of content from servers near users (local branch warehouses).
Why This Matters
Almost no real traffic goes straight from client to server. BlueTicket itself depends on a firewall, a reverse proxy and a CDN, and in Act 14 it will add a load balancer for Sale Day. Knowing what each helper does — and that any of them can block, change or cache a request — turns mysterious "it doesn't work for some people" reports into a checklist.
The Northgate students got their fest tickets, and Anna solved her first network mystery without touching BlueTicket's code. Before moving on to how the web works on top of all this, John wants to see her six questions in action on a new report.
