The Mendix Runtime only has an HTTP interface, no AJP. For linux environments, Mendix recommends using Nginx as reverse proxy.
Also see the on premise security checklist for some extra hints about security.
Yes, that's possible. We did something like that in the past with Apache before the Mendix Jetty server.