Microsoft Azure

DNS & Traffic Routing — Azure DNS & Traffic Manager

Resolve names to endpoints and steer users between regions with DNS-level routing and health checks.

Azure DNS hosts your zone. Traffic Manager adds routing logic on top of DNS.

A directory enquiries service. It tells you which branch to call based on where you are and which branches are open — then you make the call yourself, and it never hears the conversation.

Key Concepts

1
Traffic Manager works at the DNS layer, which is the single most important thing to know about it:
2
    client -> resolver -> Traffic Manager -> returns an endpoint NAME
           -> client then connects DIRECTLY to that endpoint
3
No traffic flows through Traffic Manager. It only answers the question "which address should I use?".
4
That shapes what it is good at and bad at.
    good   routing to ANY endpoint -- Azure, on-prem, another cloud
    bad    failover speed. Resolvers cache the answer for the TTL,
           so switchover is minutes, not seconds.
5
For fast failover and anything layer-7, Front Door is the right tool. Traffic Manager is the right tool when the endpoints are not all in Azure.
6
The routing methods.
    priority     active-passive failover
    weighted     split by percentage, for canary
    performance  lowest network latency to the user
    geographic   by the user's location -- data residency
    multivalue   several healthy IPs in one answer
    subnet       map client IP ranges to specific endpoints
7
Endpoint monitoring withdraws a failing endpoint from the answers, based on an HTTP probe.
8
Azure DNS itself is the zone host. The record type worth knowing is the alias record, which points at an Azure resource — a Public IP, Front Door or Traffic Manager profile — and updates automatically if that resource's address changes. It also works at the zone apex, where a CNAME is forbidden by the DNS specification.
9
Private DNS zones resolve names inside a VNet, which is how Private Endpoints work: the public name resolves to a private IP for resources inside the network, and normally outside it.
10
TTL is the lever and the limit. Low TTL means faster failover and more queries; high TTL means cheaper and slower. For records you intend to fail over, keep it at 60 seconds or less.
11
What the interviewer is probing.1. "At what layer does Traffic Manager operate?" Probing: the fundamental property. Stalls: "It load balances traffic." Moves up: DNS only — it returns a name and the client connects directly, so no traffic passes through it and it can do nothing at layer 7.
12
2. "When would you use Traffic Manager rather than Front Door?" Probing: the deciding factor. Stalls: "Traffic Manager is cheaper." Moves up: when endpoints are outside Azure — on-premises or another cloud; Front Door is better for public web traffic needing fast failover.
13
3. "Why can a bare domain not be a CNAME?" Probing: the DNS rule. Stalls: "It can." *Moves up:* the specification forbids it alongside the SOA and NS records; an alias record solves it and tracks the Azure resource automatically.
14
4. "What are private DNS zones for?" Probing: internal resolution. Stalls: "Internal websites." Moves up: resolving names inside a VNet — which is how a Private Endpoint makes the public hostname resolve to a private address.