18.8 Network Load Balancer
Why TCP is a different door
Some clients are not a browser choosing a path. They open a TCP connection, often on port 443, and they expect the certificate and the bytes from your instance, not from a balancer that decrypted the session. A partner firewall sometimes allows one public IP and will not allow a name whose addresses change. A Network Load Balancer is the type for that. It is fast because it does not read HTTP.
What passthrough means
You create a Network Load Balancer with a listener on TCP 443. The target group is TCP 443. The balancer does not present its own certificate. Nginx on the instance does, the same certificate from section 9.11 if you already ran certbot. Each Availability Zone gets a static address. You can attach an Elastic IP. Write that address down. It does not move when you replace an instance behind it.
This is not round robin in the HTTP sense. A TCP flow stays on the target the hash selected.
How to pass port 443 through
Do section 9.11 first if this instance does not already answer HTTPS. The point of this lab is passthrough, not a new way to obtain a certificate.
- SSH to the instance that already has the certificate. Use instance B if that is the one with Nginx on 443.
- Run
sudo service nginx status. - You should see Nginx running.
- From that instance, run
curl -sk -o /dev/null -w '%{http_code}\n' https://127.0.0.1/. - You should see
200. If you see a connection error, fix the instance listener before you add a balancer. - Open Create load balancer.
- Choose Network Load Balancer.
- Set the name to
lab-nlb. - Choose Internet-facing.
- Select one public subnet in each Availability Zone you will use.
- Write down the static IPv4 address shown for each subnet.
- Add a listener on TCP port 443.
- Create a target group named
tcp-443-tg, target type Instances, protocol TCP, port 443. - Register the instance on port 443.
- Set the health check to TCP on port 443.
- Create the balancer and wait until it is Active.
- On the instance security group, allow inbound TCP 443 from
0.0.0.0/0so the visitor's own address is allowed. Client IP preservation is on by default, so the instance sees the visitor, not the balancer. - Also allow inbound TCP 443 from the VPC CIDR, for example
172.31.0.0/16in the default VPC, so the health check from the balancer can arrive. - Wait until the target is healthy.
- Run
curl -vk https://NLB-DNS/and read the certificate lines. - You should see the certificate name from the instance, the same one Nginx has. The balancer did not replace it.
- Compare the static IP you wrote down with the console. You should see the same address.
If the target stays unhealthy while your own curl to the instance works, the health-check rule from the VPC CIDR is missing. Add that rule and wait for the next check.