Bird
Raised Fist0
Azurecloud~30 mins

Azure Load Balancer (Layer 4) - Mini Project: Build & Apply

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Azure Load Balancer (Layer 4) Setup
📖 Scenario: You are setting up a simple Azure Load Balancer to distribute incoming traffic evenly across two virtual machines. This helps keep your app available and responsive, like having two cashiers open at a store to serve customers faster.
🎯 Goal: Create an Azure Load Balancer with a frontend IP configuration, backend pool with two virtual machines, and a load balancing rule to distribute TCP traffic on port 80.
📋 What You'll Learn
Create a resource group named rg-loadbalancer
Create a public IP address named lbPublicIP
Create a load balancer named myLoadBalancer with a frontend IP configuration using lbPublicIP
Create a backend address pool named myBackendPool with two VM NICs: nicVM1 and nicVM2
Create a load balancing rule named httpRule to forward TCP traffic on port 80
💡 Why This Matters
🌍 Real World
Azure Load Balancers help distribute network traffic to multiple servers, improving availability and performance for web apps, APIs, and services.
💼 Career
Cloud engineers and infrastructure specialists use load balancers to build scalable and reliable cloud applications.
Progress0 / 4 steps
1
Create Resource Group and Public IP
Write Azure CLI commands to create a resource group named rg-loadbalancer in eastus and a public IP address named lbPublicIP in that resource group with SKU Standard and static allocation.
Azure
Hint

Use az group create to make the resource group, then az network public-ip create to make the public IP.

2
Create Load Balancer with Frontend IP Configuration
Write an Azure CLI command to create a load balancer named myLoadBalancer in resource group rg-loadbalancer using the public IP lbPublicIP as the frontend IP configuration named LoadBalancerFrontEnd.
Azure
Hint

Use az network lb create with --frontend-ip-name and --public-ip-address options.

3
Create Backend Address Pool with VM NICs
Write Azure CLI commands to create a backend address pool named myBackendPool in load balancer myLoadBalancer and add two network interfaces named nicVM1 and nicVM2 to this backend pool.
Azure
Hint

First create the backend pool with az network lb address-pool create, then add NICs with az network nic ip-config address-pool add.

4
Create Load Balancing Rule for TCP Port 80
Write an Azure CLI command to create a load balancing rule named httpRule on load balancer myLoadBalancer in resource group rg-loadbalancer that forwards TCP traffic on port 80 from frontend IP LoadBalancerFrontEnd to backend pool myBackendPool.
Azure
Hint

Use az network lb rule create with the correct ports, protocol, frontend IP, and backend pool names.

Practice

(1/5)
1. What is the primary function of the Azure Load Balancer (Layer 4)?
easy
A. Encrypt data at rest in Azure storage
B. Inspect and modify HTTP headers for incoming requests
C. Store and manage user session data
D. Distribute incoming TCP/UDP traffic evenly across multiple servers

Solution

  1. Step 1: Understand Layer 4 Load Balancing

    Azure Load Balancer works at the transport layer (Layer 4) to distribute TCP/UDP traffic.
  2. Step 2: Identify its main role

    It balances traffic across multiple servers to improve availability and scalability without inspecting message content.
  3. Final Answer:

    Distribute incoming TCP/UDP traffic evenly across multiple servers -> Option D
  4. Quick Check:

    Layer 4 Load Balancer = TCP/UDP traffic distribution [OK]
Hint: Layer 4 means TCP/UDP traffic balancing only [OK]
Common Mistakes:
  • Confusing Layer 4 with Layer 7 load balancer features
  • Thinking it inspects HTTP headers
  • Assuming it manages session data
2. Which of the following is the correct way to configure a backend pool in Azure Load Balancer (Layer 4)?
easy
A. Configure SSL certificates in the backend pool
B. Assign virtual machines or VM scale sets to the backend pool
C. Add HTTP routes to the backend pool
D. Set up DNS names in the backend pool

Solution

  1. Step 1: Understand backend pool composition

    Backend pools in Azure Load Balancer contain virtual machines or VM scale sets to receive traffic.
  2. Step 2: Eliminate incorrect options

    HTTP routes, SSL certificates, and DNS names are not configured in backend pools for Layer 4 load balancer.
  3. Final Answer:

    Assign virtual machines or VM scale sets to the backend pool -> Option B
  4. Quick Check:

    Backend pool = VMs or VM scale sets [OK]
Hint: Backend pool holds VMs or VM scale sets only [OK]
Common Mistakes:
  • Trying to add HTTP routes to backend pool
  • Confusing SSL setup with load balancer config
  • Adding DNS names instead of VMs
3. Given an Azure Load Balancer configured with 3 healthy backend VMs, what happens when one VM becomes unhealthy?
medium
A. Traffic is routed only to the 2 healthy VMs
B. Traffic is evenly distributed to all 3 VMs regardless
C. Load balancer stops routing traffic until all VMs are healthy
D. Traffic is routed only to the unhealthy VM

Solution

  1. Step 1: Understand health probe role

    Azure Load Balancer uses health probes to detect unhealthy VMs and stops sending traffic to them.
  2. Step 2: Apply health probe behavior

    When one VM is unhealthy, traffic is routed only to the remaining healthy VMs to maintain availability.
  3. Final Answer:

    Traffic is routed only to the 2 healthy VMs -> Option A
  4. Quick Check:

    Unhealthy VM excluded from traffic [OK]
Hint: Unhealthy VMs do not get traffic [OK]
Common Mistakes:
  • Assuming traffic still goes to unhealthy VMs
  • Thinking load balancer stops all traffic
  • Believing unhealthy VMs get all traffic
4. You configured an Azure Load Balancer but clients report intermittent connection failures. What is a likely cause?
medium
A. Backend VMs have too much CPU capacity
B. Load balancer is inspecting HTTP headers incorrectly
C. Health probes are misconfigured, marking healthy VMs as unhealthy
D. DNS names are missing in the backend pool

Solution

  1. Step 1: Analyze symptoms

    Intermittent connection failures often relate to backend availability issues.
  2. Step 2: Identify misconfiguration impact

    If health probes are misconfigured, healthy VMs may be marked unhealthy, reducing available servers and causing failures.
  3. Final Answer:

    Health probes are misconfigured, marking healthy VMs as unhealthy -> Option C
  4. Quick Check:

    Misconfigured health probes cause connection failures [OK]
Hint: Check health probe settings first for connection issues [OK]
Common Mistakes:
  • Blaming backend VM CPU capacity without evidence
  • Thinking Layer 4 load balancer inspects HTTP headers
  • Assuming DNS names belong in backend pool
5. You want to design a highly available web service using Azure Load Balancer (Layer 4). Which combination ensures scalability and fault tolerance?
hard
A. Use a backend pool with multiple VM scale sets and configure health probes
B. Use a single VM with static IP and no health probes
C. Configure DNS round-robin without load balancer
D. Use Azure Load Balancer with only one backend VM and no health probes

Solution

  1. Step 1: Identify scalability needs

    Multiple VM scale sets allow automatic scaling of backend servers to handle load.
  2. Step 2: Ensure fault tolerance

    Health probes detect unhealthy instances and route traffic only to healthy ones, improving availability.
  3. Step 3: Evaluate other options

    Single VM or no health probes reduce fault tolerance; DNS round-robin lacks health checks and load balancing features.
  4. Final Answer:

    Use a backend pool with multiple VM scale sets and configure health probes -> Option A
  5. Quick Check:

    Scale sets + health probes = scalable, fault tolerant [OK]
Hint: Combine scale sets with health probes for best availability [OK]
Common Mistakes:
  • Using single VM reduces fault tolerance
  • Ignoring health probes causes traffic to unhealthy VMs
  • Relying on DNS round-robin lacks health checks