Loading Node.js application servers with software firewall middleware wastes valuable V8 event loop ticks on malicious bot traffic. Effective security architecture blocks aggressive vulnerability scanners, scrapers, and spam bots at the **Nginx Ingress / Kernel Firewall layer** before traffic ever reaches Node.js.
1. Ingress Security Layer Responsibilities
| Security Tier | Enforcement Mechanism | Blocked Attack Vectors |
|---|---|---|
| Layer 3 / 4 (Kernel) | iptables / UFW & TCP SYN Cookies | SYN floods, unauthorized port probing, known malicious IP subnets. |
| Layer 7 (Nginx Edge) | `limit_req_zone` & User-Agent Maps | Aggressive brute-force scrapers, WordPress vulnerability probes (.php). |
| Layer 7 (Application) | HMAC Captcha & Honeypot Fields | Automated spam submissions on contact forms. |
