> What we do internally where I work is the following: our application servers all listen only on a secure internal network and accept incoming connections only from our 'gateway' server. All simple HTTP over port 80. The 'gateway' servers run just Nginx and nothing else. They staple SSL and HTTP/2 on top of the forwarded requests to application servers.
Very typical setup. Although in some companies they encrypt traffic all the way through (bad if you want to make sense of your tcpdump).
Did you encounter any issues after switching to HTTP/2 or during the process of switching over?