Application Gateway (Layer 7) in Azure - Commands & Configuration
Start learning this pattern below
Jump into concepts and practice - no test required
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"type": "Microsoft.Network/applicationGateways",
"apiVersion": "2023-02-01",
"name": "myAppGateway",
"location": "eastus",
"properties": {
"sku": {
"name": "Standard_v2",
"tier": "Standard_v2",
"capacity": 2
},
"gatewayIPConfigurations": [
{
"name": "appGatewayIpConfig",
"properties": {
"subnet": {
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Network/virtualNetworks/myVnet/subnets/mySubnet"
}
}
}
],
"frontendIPConfigurations": [
{
"name": "appGatewayFrontendIP",
"properties": {
"publicIPAddress": {
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Network/publicIPAddresses/myPublicIP"
}
}
}
],
"frontendPorts": [
{
"name": "appGatewayFrontendPort",
"properties": {
"port": 80
}
}
],
"backendAddressPools": [
{
"name": "appGatewayBackendPool",
"properties": {
"backendAddresses": [
{ "ipAddress": "10.0.1.4" },
{ "ipAddress": "10.0.1.5" }
]
}
}
],
"backendHttpSettingsCollection": [
{
"name": "appGatewayBackendHttpSettings",
"properties": {
"port": 80,
"protocol": "Http",
"cookieBasedAffinity": "Disabled"
}
}
],
"httpListeners": [
{
"name": "appGatewayHttpListener",
"properties": {
"frontendIPConfiguration": {
"id": "[concat(resourceId('Microsoft.Network/applicationGateways', 'myAppGateway'), '/frontendIPConfigurations/appGatewayFrontendIP')]"
},
"frontendPort": {
"id": "[concat(resourceId('Microsoft.Network/applicationGateways', 'myAppGateway'), '/frontendPorts/appGatewayFrontendPort')]"
},
"protocol": "Http"
}
}
],
"requestRoutingRules": [
{
"name": "rule1",
"properties": {
"ruleType": "Basic",
"httpListener": {
"id": "[concat(resourceId('Microsoft.Network/applicationGateways', 'myAppGateway'), '/httpListeners/appGatewayHttpListener')]"
},
"backendAddressPool": {
"id": "[concat(resourceId('Microsoft.Network/applicationGateways', 'myAppGateway'), '/backendAddressPools/appGatewayBackendPool')]"
},
"backendHttpSettings": {
"id": "[concat(resourceId('Microsoft.Network/applicationGateways', 'myAppGateway'), '/backendHttpSettingsCollection/appGatewayBackendHttpSettings')]"
}
}
}
]
}
}
]
}This JSON file is an Azure Resource Manager template that creates an Application Gateway named myAppGateway in the eastus region.
The sku defines the size and features of the gateway.
The gatewayIPConfigurations link the gateway to a subnet in a virtual network.
The frontendIPConfigurations set up a public IP address where users connect.
The frontendPorts define which port listens for web traffic (port 80 for HTTP).
The backendAddressPools list the IP addresses of servers that will receive the traffic.
The backendHttpSettingsCollection defines how to connect to backend servers.
The httpListeners listen for incoming requests on the frontend IP and port.
The requestRoutingRules connect listeners to backend pools, directing traffic properly.
az network application-gateway create --name myAppGateway --resource-group myResourceGroup --location eastus --sku Standard_v2 --capacity 2 --vnet-name myVnet --subnet mySubnet --public-ip-address myPublicIP--sku - Defines the size and features of the Application Gateway--capacity - Sets the number of instances for load balancing--public-ip-address - Assigns the public IP for user accessaz network application-gateway http-settings update --gateway-name myAppGateway --resource-group myResourceGroup --name appGatewayBackendHttpSettings --port 80 --protocol Http --cookie-based-affinity Disabled--port - Specifies the port to connect to backend servers--protocol - Sets the protocol used to communicate with backend serversaz network application-gateway rule create --gateway-name myAppGateway --resource-group myResourceGroup --name rule1 --http-listener appGatewayHttpListener --rule-type Basic --address-pool appGatewayBackendPool --http-settings appGatewayBackendHttpSettings
--rule-type - Defines the type of routing rule (Basic or Path-based)az network application-gateway show --name myAppGateway --resource-group myResourceGroup
If you remember nothing else from this pattern, remember: Application Gateway manages and routes web traffic securely and efficiently at the web (Layer 7) level.
Practice
Solution
Step 1: Understand Layer 7 role
Layer 7 means the application layer, which handles web traffic content like URLs.Step 2: Identify Application Gateway function
Application Gateway routes traffic based on URL paths and content, unlike DNS or VM management.Final Answer:
It routes web traffic based on URL paths and content. -> Option CQuick Check:
Layer 7 routing = URL-based traffic routing [OK]
- Confusing Application Gateway with DNS or VM services
- Thinking it works at network layer instead of application layer
- Assuming it stores data like a database
Solution
Step 1: Review ARM template frontend IP syntax
The frontend IP config requires a name and properties including a reference to a public IP resource by its ID.Step 2: Match correct JSON structure
{\"name\": \"appGatewayFrontendIP\", \"properties\": {\"publicIPAddress\": {\"id\": \"/subscriptions/.../publicIPAddresses/myPublicIP\"}}} correctly uses "name" and "properties" with "publicIPAddress" and its "id" field, matching ARM schema.Final Answer:
{"name": "appGatewayFrontendIP", "properties": {"publicIPAddress": {"id": "/subscriptions/.../publicIPAddresses/myPublicIP"}}} -> Option AQuick Check:
Frontend IP config needs name + publicIPAddress id [OK]
- Missing 'properties' wrapper around publicIPAddress
- Using 'location' inside frontend IP config incorrectly
- Incorrect field names like 'frontendIP' or 'ipConfig'
"pickHostNameFromBackendAddress" to true?{
"name": "appGatewayBackendHttpSettings",
"properties": {
"port": 80,
"protocol": "Http",
"pickHostNameFromBackendAddress": true
}
}Solution
Step 1: Understand 'pickHostNameFromBackendAddress'
This setting tells the gateway to use the hostname from the backend pool's address (IP or FQDN) for HTTP requests.Step 2: Analyze effect on backend requests
When true, the hostname in HTTP headers matches backend pool address, not the HTTP settings hostname.Final Answer:
The backend hostname is taken from the backend pool IP or FQDN instead of the HTTP settings. -> Option AQuick Check:
pickHostNameFromBackendAddress true = use backend pool hostname [OK]
- Thinking it changes port or protocol
- Confusing frontend hostname with backend hostname
- Assuming it disables SSL termination
Solution
Step 1: Understand health probe failure with IP backend pool
If 'pickHostNameFromBackendAddress' is true, the gateway uses backend hostname from IP, which fails if no DNS name exists.Step 2: Identify mismatch causing probe failure
Backend IPs lack DNS names, so probes fail when hostname is required but missing.Final Answer:
The backend HTTP settings have 'pickHostNameFromBackendAddress' set to true but backend IPs lack proper DNS names. -> Option BQuick Check:
IP backend + pickHostNameFromBackendAddress true = probe fails [OK]
- Blaming subnet size for routing issues
- Assuming frontend IP config missing public IP causes backend probe failure
- Confusing backend pool IPs with FQDNs
/images/* to an image server pool and /api/* to an API server pool. Which configuration step is essential to achieve this?Solution
Step 1: Understand URL-based routing requirement
Routing based on URL paths requires path-based routing rules with URL path maps.Step 2: Configure path-based rules
Define URL path maps that link specific URL patterns like '/images/*' and '/api/*' to their respective backend pools.Final Answer:
Create path-based routing rules with URL path maps specifying backend pools for each path. -> Option DQuick Check:
URL path routing = path-based rules with URL maps [OK]
- Thinking multiple public IPs are needed for URL routing
- Using multiple frontend ports without path rules
- Assuming backend HTTP settings control URL routing
