Proxies, Firewalls and CDNs

7.The Helpers in the Middle of the Road

A

In this chapter

We'll meet the helpers that sit in the middle of internet traffic — proxies (a receptionist who passes messages), reverse proxies (a company's front desk), firewalls (a security guard with a list) and CDNs (local branch warehouses) — and use them to finish the Northgate investigation.

12–14 min

The Problem in Real Life

The Northgate fix worked, but the college's IT manager writes back with a question: "Our firewall and proxy logs show your site was blocked for some students even before the DNS issue. Can you check?"

Anna has heard all three words — firewall, proxy, CDN — but only as vague network things. John grabs the marker one last time this week. "These are the helpers in the middle of the road. Some pass messages on, some stop them, some answer from a copy. Let's meet them."

A

So between the student and us there are people checking, forwarding and copying everything?

Anna

A Direct Line vs. Helpers in the Middle

Traffic rarely goes straight

Between a client and a server, requests often pass through several helpers.

Some helpers protect

Firewalls decide what's allowed in and out of a network.

Some helpers speed things up

CDNs keep copies of content close to users, so it arrives faster.

Proxies, Reverse Proxies, Firewalls and CDNs

Each helper has a simple everyday version.

  • Proxy — a receptionist who sends messages for you: a proxy (or forward proxy) is a server that makes requests on behalf of clients. On many campuses and in many companies, every student's browser sends its web requests to the proxy, and the proxy fetches the page and passes it back — like a receptionist who places calls for everyone in an office. Organisations use proxies to filter websites, log usage and cache popular pages. To the outside world, all the requests seem to come from the proxy.
  • Reverse proxy — a company's front desk: a reverse proxy sits in front of servers, not clients. Visitors talk to the front desk, and the desk forwards each request to the right person inside. Visitors never see the internal offices. BlueTicket has one: every request to blueticket.example first reaches a reverse proxy, which handles the HTTPS envelope (TLS), and passes the request to the right app server behind it. Reverse proxies also spread load across several servers — which is what a load balancer does (Act 14) — and come back in Act 19.
  • Firewall — a security guard with a list: a firewall checks every packet or connection against rules and allows or blocks it — like a guard at a gate with a list of allowed visitors and doors. Rules can be about addresses ("block this IP"), ports ("only allow 80 and 443 from outside") or programs. Every serious network has one: the campus, BlueTicket's servers, even your laptop. A firewall usually blocks everything coming in except what's explicitly allowed.
  • CDN — local branch warehouses: a CDN (Content Delivery Network) is a network of servers spread around the world that keep copies of a website's files — images, styles, scripts, even whole pages — close to users. Instead of every fan's request travelling to BlueTicket's server in one city, the CDN answers from a nearby branch, like a company that stocks its most popular products in local warehouses so customers get them the same day. Pages load faster, and the main server handles far fewer requests.
Table — The helpers in the middle
HelperEveryday versionSits in front ofMain job
Proxy (forward)An office receptionist placing callsClientsFilter, log and cache outgoing requests
Reverse proxyA company's front deskServersReceive requests, handle TLS, forward to servers
FirewallA security guard with a listA network or a machineAllow or block traffic by rules
CDNLocal branch warehousesA website's contentServe copies close to users, faster
Table — Anna's six questions for any "site not loading" report
StepQuestionWhat to try
1Is their network working at all?Can they open any other website?
2Does the name give the right address?nslookup — compare with a public resolver
3Can they connect to that address and port?Firewall rules, ping, a test connection to port 443
4Is the certificate valid?Browser warnings, expiry date (TLS)
5What status code comes back?Browser Network tab (HTTP)
6Is something in the middle serving an old copy?Proxy or CDN cache

Where the helpers sit

Student's browser

on campus

leaves the laptop

Campus firewall and proxy

checks rules · forwards requests · may cache

across the internet

CDN

nearby copy of images, styles, pages

if the CDN doesn't have it

BlueTicket's firewall + reverse proxy

front desk: TLS, then to an app server

BlueTicket app server

builds the real answer

Finishing the Northgate investigation: Anna reads the college's logs. The campus proxy had cached a copy of BlueTicket's home page from before the move, and the campus firewall had a rule — added years ago — allowing outgoing traffic only to a list of known addresses, which still listed the old server, not the new one. So even after the DNS cache was cleared, a few students whose traffic went through the strictest firewall profile were still blocked. Northgate's IT team updates the firewall rule and clears the proxy cache. The college's error reports drop to zero.

What Anna learned about debugging networks: check the road one stop at a time. Can you reach any website at all (the local network)? Does the name resolve to the right address (DNS)? Can you connect to that address and port (firewall, TCP)? Is the certificate valid (TLS)? What status code comes back (HTTP)? Is something in the middle answering with an old copy (proxy, CDN)? She writes these six questions on a card and pins it above her desk.

Her email to the college: she explains everything in plain language — what was wrong, what they changed, and how to avoid it next time (respect DNS TTLs, review firewall allowlists, don't cache pages longer than the site allows). John reads it before she sends it and nods: "That's how you prove a problem is outside our system — calmly, with evidence, and with a fix they can follow."

Key Takeaway

Helpers in the middle shape most internet traffic: a proxy makes requests on behalf of clients (an office receptionist), a reverse proxy sits in front of servers and forwards requests to them (a company's front desk), a firewall allows or blocks traffic by rules (a security guard with a list), and a CDN serves copies of content from servers near users (local branch warehouses).

Why This Matters

Almost no real traffic goes straight from client to server. BlueTicket itself depends on a firewall, a reverse proxy and a CDN, and in Act 14 it will add a load balancer for Sale Day. Knowing what each helper does — and that any of them can block, change or cache a request — turns mysterious "it doesn't work for some people" reports into a checklist.

The Northgate students got their fest tickets, and Anna solved her first network mystery without touching BlueTicket's code. Before moving on to how the web works on top of all this, John wants to see her six questions in action on a new report.

Next