Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 18: Load Balancing

18.8 Network Load Balancer

Why TCP is a different door

Some clients are not a browser choosing a path. They open a TCP connection, often on port 443, and they expect the certificate and the bytes from your instance, not from a balancer that decrypted the session. A partner firewall sometimes allows one public IP and will not allow a name whose addresses change. A Network Load Balancer is the type for that. It is fast because it does not read HTTP.

What passthrough means

You create a Network Load Balancer with a listener on TCP 443. The target group is TCP 443. The balancer does not present its own certificate. Nginx on the instance does, the same certificate from section 9.11 if you already ran certbot. Each Availability Zone gets a static address. You can attach an Elastic IP. Write that address down. It does not move when you replace an instance behind it.

This is not round robin in the HTTP sense. A TCP flow stays on the target the hash selected.

How to pass port 443 through

Do section 9.11 first if this instance does not already answer HTTPS. The point of this lab is passthrough, not a new way to obtain a certificate.

  1. SSH to the instance that already has the certificate. Use instance B if that is the one with Nginx on 443.
  2. Run sudo service nginx status.
  3. You should see Nginx running.
  4. From that instance, run curl -sk -o /dev/null -w '%{http_code}\n' https://127.0.0.1/.
  5. You should see 200. If you see a connection error, fix the instance listener before you add a balancer.
  6. Open Create load balancer.
  7. Choose Network Load Balancer.
  8. Set the name to lab-nlb.
  9. Choose Internet-facing.
  10. Select one public subnet in each Availability Zone you will use.
  11. Write down the static IPv4 address shown for each subnet.
  12. Add a listener on TCP port 443.
  13. Create a target group named tcp-443-tg, target type Instances, protocol TCP, port 443.
  14. Register the instance on port 443.
  15. Set the health check to TCP on port 443.
  16. Create the balancer and wait until it is Active.
  17. On the instance security group, allow inbound TCP 443 from 0.0.0.0/0 so the visitor's own address is allowed. Client IP preservation is on by default, so the instance sees the visitor, not the balancer.
  18. Also allow inbound TCP 443 from the VPC CIDR, for example 172.31.0.0/16 in the default VPC, so the health check from the balancer can arrive.
  19. Wait until the target is healthy.
  20. Run curl -vk https://NLB-DNS/ and read the certificate lines.
  21. You should see the certificate name from the instance, the same one Nginx has. The balancer did not replace it.
  22. Compare the static IP you wrote down with the console. You should see the same address.

If the target stays unhealthy while your own curl to the instance works, the health-check rule from the VPC CIDR is missing. Add that rule and wait for the next check.