Azure Load Balancer (Layer 4) - Commands & Configuration
Start learning this pattern below
Jump into concepts and practice - no test required
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"type": "Microsoft.Network/loadBalancers",
"apiVersion": "2022-05-01",
"name": "myLoadBalancer",
"location": "eastus",
"properties": {
"frontendIPConfigurations": [
{
"name": "LoadBalancerFrontEnd",
"properties": {
"publicIPAddress": {
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Network/publicIPAddresses/myPublicIP"
}
}
}
],
"backendAddressPools": [
{
"name": "myBackendPool"
}
],
"loadBalancingRules": [
{
"name": "myLoadBalancingRule",
"properties": {
"frontendIPConfiguration": {
"id": "[concat(resourceId('Microsoft.Network/loadBalancers', 'myLoadBalancer'), '/frontendIPConfigurations/LoadBalancerFrontEnd')]"
},
"backendAddressPool": {
"id": "[concat(resourceId('Microsoft.Network/loadBalancers', 'myLoadBalancer'), '/backendAddressPools/myBackendPool')]"
},
"protocol": "Tcp",
"frontendPort": 80,
"backendPort": 80,
"enableFloatingIP": false,
"idleTimeoutInMinutes": 4,
"loadDistribution": "Default",
"probe": {
"id": "[concat(resourceId('Microsoft.Network/loadBalancers', 'myLoadBalancer'), '/probes/myHealthProbe')]"
}
}
}
],
"probes": [
{
"name": "myHealthProbe",
"properties": {
"protocol": "Tcp",
"port": 80,
"intervalInSeconds": 5,
"numberOfProbes": 2
}
}
]
}
}
]
}This JSON file is an Azure Resource Manager template that creates a Load Balancer named myLoadBalancer in the eastus region.
frontendIPConfigurations defines the public IP address where the Load Balancer listens for incoming traffic.
backendAddressPools lists the group of virtual machines that will receive the traffic.
loadBalancingRules specify how traffic is distributed from the frontend to the backend, here for TCP port 80.
probes check the health of backend servers to send traffic only to healthy ones.
az network lb create --resource-group myResourceGroup --name myLoadBalancer --sku Basic --frontend-ip-name LoadBalancerFrontEnd --backend-pool-name myBackendPool --public-ip-address myPublicIP --location eastus
--sku - Specifies the Load Balancer SKU type (Basic or Standard)--frontend-ip-name - Names the frontend IP configuration--backend-pool-name - Names the backend address poolaz network lb probe create --resource-group myResourceGroup --lb-name myLoadBalancer --name myHealthProbe --protocol tcp --port 80 --interval 5 --threshold 2
--protocol - Specifies the protocol used for the health probe--interval - Sets how often the probe runs in seconds--threshold - Number of failed probes before marking backend unhealthyaz network lb rule create --resource-group myResourceGroup --lb-name myLoadBalancer --name myLoadBalancingRule --protocol Tcp --frontend-port 80 --backend-port 80 --frontend-ip-name LoadBalancerFrontEnd --backend-pool-name myBackendPool --probe-name myHealthProbe
--frontend-port - Port on the frontend IP to listen on--backend-port - Port on backend servers to forward traffic to--probe-name - Associates the health probe with this ruleaz network lb show --resource-group myResourceGroup --name myLoadBalancer
If you remember nothing else from this pattern, remember: Azure Load Balancer spreads network traffic evenly across healthy servers at the basic TCP/UDP level to keep your app fast and available.
Practice
Azure Load Balancer (Layer 4)?Solution
Step 1: Understand Layer 4 Load Balancing
Azure Load Balancer works at the transport layer (Layer 4) to distribute TCP/UDP traffic.Step 2: Identify its main role
It balances traffic across multiple servers to improve availability and scalability without inspecting message content.Final Answer:
Distribute incoming TCP/UDP traffic evenly across multiple servers -> Option DQuick Check:
Layer 4 Load Balancer = TCP/UDP traffic distribution [OK]
- Confusing Layer 4 with Layer 7 load balancer features
- Thinking it inspects HTTP headers
- Assuming it manages session data
Solution
Step 1: Understand backend pool composition
Backend pools in Azure Load Balancer contain virtual machines or VM scale sets to receive traffic.Step 2: Eliminate incorrect options
HTTP routes, SSL certificates, and DNS names are not configured in backend pools for Layer 4 load balancer.Final Answer:
Assign virtual machines or VM scale sets to the backend pool -> Option BQuick Check:
Backend pool = VMs or VM scale sets [OK]
- Trying to add HTTP routes to backend pool
- Confusing SSL setup with load balancer config
- Adding DNS names instead of VMs
Solution
Step 1: Understand health probe role
Azure Load Balancer uses health probes to detect unhealthy VMs and stops sending traffic to them.Step 2: Apply health probe behavior
When one VM is unhealthy, traffic is routed only to the remaining healthy VMs to maintain availability.Final Answer:
Traffic is routed only to the 2 healthy VMs -> Option AQuick Check:
Unhealthy VM excluded from traffic [OK]
- Assuming traffic still goes to unhealthy VMs
- Thinking load balancer stops all traffic
- Believing unhealthy VMs get all traffic
Solution
Step 1: Analyze symptoms
Intermittent connection failures often relate to backend availability issues.Step 2: Identify misconfiguration impact
If health probes are misconfigured, healthy VMs may be marked unhealthy, reducing available servers and causing failures.Final Answer:
Health probes are misconfigured, marking healthy VMs as unhealthy -> Option CQuick Check:
Misconfigured health probes cause connection failures [OK]
- Blaming backend VM CPU capacity without evidence
- Thinking Layer 4 load balancer inspects HTTP headers
- Assuming DNS names belong in backend pool
Solution
Step 1: Identify scalability needs
Multiple VM scale sets allow automatic scaling of backend servers to handle load.Step 2: Ensure fault tolerance
Health probes detect unhealthy instances and route traffic only to healthy ones, improving availability.Step 3: Evaluate other options
Single VM or no health probes reduce fault tolerance; DNS round-robin lacks health checks and load balancing features.Final Answer:
Use a backend pool with multiple VM scale sets and configure health probes -> Option AQuick Check:
Scale sets + health probes = scalable, fault tolerant [OK]
- Using single VM reduces fault tolerance
- Ignoring health probes causes traffic to unhealthy VMs
- Relying on DNS round-robin lacks health checks
