Your comment, to me, only points out that the OSI layer model is nonsense. Envoy in DSR mode routes traffic based on application features, at "layer 7".
https://blog.envoyproxy.io/introduction-to-modern-network-lo...
Layer 4 to 7 is useful in this case, as layer 4 involves forging tcp/udp packets, which is vastly different than say a http level reverse proxy.
There's a separate term for the bits of the OSI model that are actually relevant; it's called the IETF model.