@Patrick: Thanks for the reply!
I found the reason, why the access from the VPN was so bad. During the migration I needed to use outbount NAT on the LAN interface for the VPN Clients, because at this time, the default gw on the servers still pointed to the old firewall. After removing the outbound NAT rule, the direct access to the tomcat is working.
I tried Caddy, too ... but the behavior is like with nginx. Awfull slow ... and there are only a few options to play with ...
It is a bit frustrating! I hat a look into the old Sophos fiewall, that uses apache as reverse proxy ... but that was not very helpful ...
I found the reason, why the access from the VPN was so bad. During the migration I needed to use outbount NAT on the LAN interface for the VPN Clients, because at this time, the default gw on the servers still pointed to the old firewall. After removing the outbound NAT rule, the direct access to the tomcat is working.
I tried Caddy, too ... but the behavior is like with nginx. Awfull slow ... and there are only a few options to play with ...
It is a bit frustrating! I hat a look into the old Sophos fiewall, that uses apache as reverse proxy ... but that was not very helpful ...