Bird
Raised Fist0
Azurecloud~5 mins

Load Balancer vs Application Gateway decision in Azure - CLI Comparison

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
When you want to send internet traffic to your apps, you need a way to share the work across many servers. Azure offers two main tools for this: Load Balancer and Application Gateway. Choosing the right one helps your app run smoothly and safely.
When you want to spread simple network traffic evenly across servers to keep your app fast and available.
When you need to route web traffic based on the URL or need extra security features like a web firewall.
When your app uses non-web protocols like TCP or UDP and needs fast, basic load balancing.
When you want to manage SSL certificates and do web traffic inspection to block bad requests.
When you want to handle user sessions so that a user always talks to the same server.
Commands
This command creates a basic Azure Load Balancer with a public IP, frontend IP configuration, and backend pool to distribute traffic evenly across servers.
Terminal
az network lb create --resource-group example-rg --name example-lb --sku Standard --frontend-ip-name exampleFrontEnd --backend-pool-name exampleBackEndPool --public-ip-address examplePublicIP
Expected OutputExpected
{ "frontendIpConfigurations": [ { "name": "exampleFrontEnd", "privateIpAddress": null, "publicIpAddress": { "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Network/publicIPAddresses/examplePublicIP" } } ], "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Network/loadBalancers/example-lb", "location": "eastus", "name": "example-lb", "resourceGroup": "example-rg", "sku": { "name": "Standard" }, "type": "Microsoft.Network/loadBalancers" }
→
--sku - Defines the Load Balancer type; Standard supports more features and zones.
→
--frontend-ip-name - Names the frontend IP configuration for incoming traffic.
→
--backend-pool-name - Names the group of servers that will receive the traffic.
This command creates a health probe to check if backend servers are healthy by testing TCP port 80. It helps the Load Balancer send traffic only to healthy servers.
Terminal
az network lb probe create --resource-group example-rg --lb-name example-lb --name exampleProbe --protocol tcp --port 80
Expected OutputExpected
{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Network/loadBalancers/example-lb/probes/exampleProbe", "name": "exampleProbe", "protocol": "Tcp", "port": 80 }
→
--protocol - Sets the protocol used for health checks.
→
--port - Sets the port number to check on backend servers.
This command creates an Azure Application Gateway with web traffic features like cookie-based session affinity to keep users connected to the same server.
Terminal
az network application-gateway create --name example-appgw --location eastus --resource-group example-rg --sku Standard_v2 --capacity 2 --frontend-port 80 --http-settings-cookie-based-affinity Enabled --routing-rule-type Basic
Expected OutputExpected
{ "name": "example-appgw", "location": "eastus", "sku": { "name": "Standard_v2" }, "capacity": 2, "frontendPorts": [ { "port": 80 } ], "httpSettings": [ { "cookieBasedAffinity": "Enabled" } ], "routingRules": [ { "ruleType": "Basic" } ] }
→
--sku - Specifies the Application Gateway SKU with advanced features.
→
--capacity - Sets the number of instances for scaling.
→
--http-settings-cookie-based-affinity - Enables session stickiness for user sessions.
This command shows the details of the Application Gateway to verify its configuration and status.
Terminal
az network application-gateway show --name example-appgw --resource-group example-rg
Expected OutputExpected
{ "name": "example-appgw", "location": "eastus", "sku": { "name": "Standard_v2" }, "provisioningState": "Succeeded", "capacity": 2 }
Key Concept

If you remember nothing else from this pattern, remember: Use Load Balancer for simple, fast network traffic distribution and Application Gateway for smart web traffic routing and security.

Common Mistakes
Using Load Balancer when you need URL-based routing or web application firewall features.
Load Balancer cannot inspect or route web traffic based on URLs or provide web security.
Choose Application Gateway when you need advanced web traffic management and security.
Not configuring health probes for Load Balancer backend pools.
Without health probes, Load Balancer may send traffic to unhealthy servers causing downtime.
Always create and attach health probes to monitor backend server health.
Forgetting to enable session affinity on Application Gateway when your app requires sticky sessions.
Users may be routed to different servers causing session loss or errors.
Enable cookie-based affinity in Application Gateway HTTP settings for session stickiness.
Summary
Create an Azure Load Balancer to distribute network traffic evenly across servers.
Add health probes to ensure traffic only goes to healthy backend servers.
Use Azure Application Gateway for web traffic routing, SSL management, and security features.
Enable session affinity on Application Gateway to keep user sessions consistent.

Practice

(1/5)
1. Which Azure service is best suited for distributing simple network traffic quickly without inspecting the content?
easy
A. Azure Front Door
B. Azure Application Gateway
C. Azure Traffic Manager
D. Azure Load Balancer

Solution

  1. Step 1: Understand the role of Azure Load Balancer

    Azure Load Balancer distributes incoming network traffic at the transport layer quickly without inspecting the content.
  2. Step 2: Compare with Application Gateway

    Application Gateway works at the application layer and inspects traffic for web routing and security, which is more complex.
  3. Final Answer:

    Azure Load Balancer -> Option D
  4. Quick Check:

    Simple network traffic distribution = Azure Load Balancer [OK]
Hint: Simple fast traffic? Choose Load Balancer [OK]
Common Mistakes:
  • Confusing Application Gateway with Load Balancer for simple traffic
  • Choosing Traffic Manager which is DNS-based, not load balancing
  • Assuming Front Door is for basic network traffic
2. Which of the following is the correct Azure service to use when you need SSL termination and web application firewall features?
easy
A. Azure Application Gateway
B. Azure Load Balancer
C. Azure Virtual Network
D. Azure Blob Storage

Solution

  1. Step 1: Identify SSL termination and WAF support

    Azure Application Gateway supports SSL termination and has a built-in Web Application Firewall (WAF).
  2. Step 2: Exclude other options

    Load Balancer does not support SSL termination or WAF. Virtual Network and Blob Storage are unrelated services.
  3. Final Answer:

    Azure Application Gateway -> Option A
  4. Quick Check:

    SSL termination + WAF = Application Gateway [OK]
Hint: SSL termination needs Application Gateway [OK]
Common Mistakes:
  • Choosing Load Balancer for SSL termination
  • Confusing Virtual Network as a load balancer
  • Selecting Blob Storage which is for data storage
3. Consider a web app that requires URL-based routing to different backend pools and needs to inspect HTTP headers. Which Azure service will correctly handle this scenario?
medium
A. Azure Application Gateway
B. Azure DNS
C. Azure Load Balancer
D. Azure Content Delivery Network

Solution

  1. Step 1: Analyze URL-based routing and HTTP header inspection needs

    These features require application layer (Layer 7) processing, which Azure Application Gateway provides.
  2. Step 2: Exclude other services

    Load Balancer works at Layer 4 and cannot inspect HTTP headers or route based on URL. DNS and CDN do not perform routing to backend pools.
  3. Final Answer:

    Azure Application Gateway -> Option A
  4. Quick Check:

    URL routing + header inspection = Application Gateway [OK]
Hint: URL routing needs Application Gateway [OK]
Common Mistakes:
  • Choosing Load Balancer for URL routing
  • Confusing DNS with traffic routing
  • Assuming CDN handles backend routing
4. You configured an Azure Load Balancer but your web app requires SSL offloading and WAF protection. What is the main issue and how to fix it?
medium
A. WAF is enabled by default on Load Balancer; disable it
B. Load Balancer needs extra SSL certificates; add them to Load Balancer
C. Load Balancer does not support SSL offloading; switch to Application Gateway
D. Load Balancer supports SSL offloading; check backend app configuration

Solution

  1. Step 1: Identify Load Balancer capabilities

    Azure Load Balancer does not support SSL offloading or WAF features.
  2. Step 2: Recommend correct service

    Application Gateway supports SSL offloading and WAF, so switching is necessary.
  3. Final Answer:

    Load Balancer does not support SSL offloading; switch to Application Gateway -> Option C
  4. Quick Check:

    SSL offloading + WAF need Application Gateway [OK]
Hint: SSL offloading needs Application Gateway, not Load Balancer [OK]
Common Mistakes:
  • Trying to add SSL certs to Load Balancer
  • Assuming WAF is on Load Balancer by default
  • Ignoring backend app SSL settings
5. You are designing a scalable web application that requires fast network traffic distribution, SSL termination, URL-based routing, and protection against common web attacks. Which Azure architecture should you choose?
hard
A. Use Azure Load Balancer for traffic and add Azure Firewall for security
B. Use Azure Application Gateway for all traffic management and security features
C. Use Azure Traffic Manager with Azure Load Balancer for SSL termination
D. Use Azure Front Door only for all routing and security needs

Solution

  1. Step 1: Match requirements to service features

    Fast network distribution, SSL termination, URL routing, and WAF protection are all provided by Azure Application Gateway.
  2. Step 2: Evaluate other options

    Load Balancer lacks SSL termination and WAF; Traffic Manager does DNS routing only; Front Door is global but may not fit all needs here.
  3. Final Answer:

    Use Azure Application Gateway for all traffic management and security features -> Option B
  4. Quick Check:

    All-in-one routing + SSL + WAF = Application Gateway [OK]
Hint: All features together? Pick Application Gateway [OK]
Common Mistakes:
  • Choosing Load Balancer without SSL or WAF
  • Confusing Traffic Manager with SSL termination
  • Assuming Front Door replaces Application Gateway fully