Home/Labs/L4 vs L7 Balancing
All 280 Labs
INTERACTIVE LAB⚖️

Layer 4 vs Layer 7 Lab (Interactive)

Route video, API, and database traffic through L4 and L7 balancers to compare throughput, latency, and routing IQ. Send three realistic workloads through an NLB-style and an ALB-style balancer. Compute packet throughput, TLS CPU cost, NIC saturation, and Direct Server Return savings.

Layer 4 vs Layer 7 Routing Lab

Same traffic, two OSI layers: compare throughput, latency overhead, TLS handling, and routing intelligence.

Workload:
Client requestHTTPS
GET /video/seg432.mp4

450 B up / 5.0 MB down · 20,000 req/s

L4 Balancer (NLB / HAProxy TCP / IPVS)5-TUPLE ONLY

Forwarded raw TCP via Direct Server Return: rewrote dst MAC only; response bypasses the LB back to the client.

Destination:random node #2 (round-robin; LB blind to /video path)

L4 never decrypts TLS, so URL paths, cookies, and headers are invisible.

Throughput class12M+ pps (L4 ceiling)

Ingress 0.07 Gbps · egress via LB 0.0 Gbps

TLS + CPUTLS passthrough

≈ 0.01 LB cores busy at 20,000 QPS

Traffic dial

Added latency+0.08ms
LB NIC stateline rate OK
DSR check: with Direct Server Return ON, 800.0 Gbps of video/response egress leaves the LB entirely — a 10 Gbps appliance can front a 100+ Gbps stream.

Decision matrix

• >1M QPS, non-HTTP (Postgres/Kafka/Redis), <0.1ms → L4 (NLB, IPVS)

• Path/header canary routing, gRPC, WAF, TLS offload → L7 (ALB, Envoy)

• Hyperscale pattern: L4 anycast ingress → L7 gateway fleet (Netflix NLB → Zuul).

How It Works Under the Hood

Layer 4 balancers forward on the 5-tuple (protocol, source IP/port, destination IP/port) without ever decrypting TLS, reaching tens of millions of packets per second with sub-0.1ms overhead. Layer 7 balancers terminate TLS, parse HTTP paths, headers, and cookies, and route /api/orders to the right microservice fleet at the cost of ~0.5-2.0ms and real CPU for cryptography. Direct Server Return rewrites only the destination MAC so huge responses bypass the balancer entirely — the trick that lets one 10 Gbps appliance front terabits of video egress.

Core Architectural Principles

  • L4 routes raw 5-tuple packets at line rate; L7 decrypts TLS and routes on URL paths, headers, and cookies.
  • DSR sends multi-megabyte responses directly from backend to client, removing the LB egress bottleneck.
  • Non-HTTP protocols (Postgres, Redis, Kafka) can only be balanced at L4.
Interview Round Script

State the distinction crisply: L4 routes on IP/port without decrypting; L7 terminates TLS and inspects HTTP for content routing. Then show tiering: anycast L4 ingress feeding an L7 Envoy/ALB gateway, Netflix-style. Cite DSR when designing video or game egress at petabyte scale.

Key Trade-Offs

L4 buys 5-10x throughput and microsecond latency but is blind to content; L7 buys intelligent routing and TLS offload at ~1ms and real CPU cost.

Related Curriculum Chapter

Layer 4 vs Layer 7 Load Balancing

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs