Microsoft Azure

Load Balancing — Application Gateway & Load Balancer

Spread traffic inside a region and know which balancer belongs at which layer.

Azure separates the layers into different products, and picking wrongly is the usual interview slip.

The Load Balancer is a turnstile counting people through the nearest open gate. Application Gateway is a receptionist who reads why you came and sends you to the right floor.

Key Concepts

1
    Load Balancer        layer 4, TCP/UDP, regional, very fast
    Application Gateway  layer 7, HTTP/HTTPS, with WAF
    Front Door           layer 7, GLOBAL, with CDN and WAF
    Traffic Manager      DNS only
2
Application Gateway understands the request, so it can route on it:
3
    /api/*                   -> backend pool "api"
    /images/*                -> backend pool "static"
    Host: admin.example.com  -> backend pool "admin"
4
A layer-4 Load Balancer cannot do any of that — there is no URL at that layer.
5
What else Application Gateway gives you.
    TLS termination and end-to-end TLS re-encryption
    WAF with the OWASP managed rule set
    cookie-based session affinity
    autoscaling and zone redundancy (v2)
    URL rewriting and redirects
6
The Load Balancer is for everything that is not HTTP — databases, custom TCP protocols, game servers — and for internal traffic between tiers. It is also the cheaper option at high throughput, because it does not parse anything.
7
Standard versus Basic matters. Standard Load Balancer is zone-redundant, secure by default — traffic is denied unless an NSG allows it — and has an SLA. Basic has none of that and is being retired.
8
Health probes decide who receives traffic, and the usual mistakes apply:
9
    a probe that always returns 200     keeps broken instances in rotation
    a probe that checks the database    one blip takes out every instance
10
Probe what that instance needs to serve its own requests, and nothing further.
11
The client IP arrives in X-Forwarded-For behind Application Gateway. Reading the socket address gives you the gateway, which is why rate limiting and access logs show the wrong address when nobody configured it.
X-Forwarded-For
12
Outbound is its own topic. Default outbound access is being retired, so production VMs need an explicit NAT Gateway or outbound rules — otherwise they silently lose internet access.
13
What the interviewer is probing.1. "Application Gateway or Load Balancer?" Probing: the layer. Stalls: "Whichever is cheaper." Moves up: Application Gateway for HTTP needing path or host routing and WAF; Load Balancer for other TCP protocols and internal tier-to-tier traffic.
14
2. "What is wrong with Basic Load Balancer?" Probing: currency. Stalls: "Nothing, it works." Moves up: no SLA, no zone redundancy, and it is being retired — Standard is secure by default and zone-redundant.
15
3. "Your VMs lost internet access after a platform change. What happened?" Probing: default outbound retirement. Stalls: "A firewall rule." Moves up: default outbound access is being retired, so production VMs need an explicit NAT Gateway or outbound rules.
16
4. "Where is the client IP behind Application Gateway?" Probing: the header. Stalls: "The socket address." Moves up: X-Forwarded-For — the socket shows the gateway, which is why rate limiting and logs show one address.