Microsoft Azure
Load Balancing — Application Gateway & Load Balancer
Spread traffic inside a region and know which balancer belongs at which layer.
Azure separates the layers into different products, and picking wrongly is the usual interview slip.
The Load Balancer is a turnstile counting people through the nearest open gate. Application Gateway is a receptionist who reads why you came and sends you to the right floor.
Key Concepts
1
Load Balancer layer 4, TCP/UDP, regional, very fast
Application Gateway layer 7, HTTP/HTTPS, with WAF
Front Door layer 7, GLOBAL, with CDN and WAF
Traffic Manager DNS only2
Application Gateway understands the request, so it can route on it:
3
/api/* -> backend pool "api"
/images/* -> backend pool "static"
Host: admin.example.com -> backend pool "admin"4
A layer-4 Load Balancer cannot do any of that — there is no URL at that layer.
5
What else Application Gateway gives you.
TLS termination and end-to-end TLS re-encryption
WAF with the OWASP managed rule set
cookie-based session affinity
autoscaling and zone redundancy (v2)
URL rewriting and redirects6
The Load Balancer is for everything that is not HTTP — databases, custom TCP protocols, game servers — and for internal traffic between tiers. It is also the cheaper option at high throughput, because it does not parse anything.
7
Standard versus Basic matters. Standard Load Balancer is zone-redundant, secure by default — traffic is denied unless an NSG allows it — and has an SLA. Basic has none of that and is being retired.
8
Health probes decide who receives traffic, and the usual mistakes apply:
9
a probe that always returns 200 keeps broken instances in rotation
a probe that checks the database one blip takes out every instance10
Probe what that instance needs to serve its own requests, and nothing further.
11
The client IP arrives in X-Forwarded-For behind Application Gateway. Reading the socket address gives you the gateway, which is why rate limiting and access logs show the wrong address when nobody configured it.
X-Forwarded-For
12
Outbound is its own topic. Default outbound access is being retired, so production VMs need an explicit NAT Gateway or outbound rules — otherwise they silently lose internet access.
13
What the interviewer is probing.1. "Application Gateway or Load Balancer?" Probing: the layer. Stalls: "Whichever is
cheaper." Moves up: Application Gateway for HTTP needing path or host routing and WAF; Load
Balancer for other TCP protocols and internal tier-to-tier traffic.
14
2. "What is wrong with Basic Load Balancer?" Probing: currency. Stalls: "Nothing, it works."
Moves up: no SLA, no zone redundancy, and it is being retired — Standard is secure by default and
zone-redundant.
15
3. "Your VMs lost internet access after a platform change. What happened?" Probing: default
outbound retirement. Stalls: "A firewall rule." Moves up: default outbound access is being
retired, so production VMs need an explicit NAT Gateway or outbound rules.
16
4. "Where is the client IP behind Application Gateway?" Probing: the header. Stalls: "The
socket address." Moves up: X-Forwarded-For — the socket shows the gateway, which is why rate
limiting and logs show one address.