Bird
Raised Fist0
Azurecloud~5 mins

Load balancing rules in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Load balancing rules in Azure help distribute incoming network traffic evenly across multiple servers. This prevents any single server from getting overwhelmed and keeps your app running smoothly.
When you want to share user requests between several web servers to avoid overload.
When you have multiple virtual machines running the same service and want to balance traffic.
When you need to ensure high availability by redirecting traffic if one server fails.
When you want to manage traffic on specific ports like HTTP or HTTPS across servers.
When you want to improve app performance by spreading workload evenly.
Config File - loadbalancer-rule.json
loadbalancer-rule.json
{
  "type": "Microsoft.Network/loadBalancers/loadBalancingRules",
  "apiVersion": "2023-05-01",
  "name": "myLoadBalancingRule",
  "properties": {
    "frontendIPConfiguration": {
      "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Network/loadBalancers/myLoadBalancer/frontendIPConfigurations/myFrontEnd"
    },
    "backendAddressPool": {
      "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Network/loadBalancers/myLoadBalancer/backendAddressPools/myBackEndPool"
    },
    "probe": {
      "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example-rg/providers/Microsoft.Network/loadBalancers/myLoadBalancer/probes/myHealthProbe"
    },
    "protocol": "Tcp",
    "loadDistribution": "Default",
    "frontendPort": 80,
    "backendPort": 80,
    "enableFloatingIP": false,
    "idleTimeoutInMinutes": 4,
    "enableTcpReset": true
  }
}

This JSON defines a load balancing rule for an Azure Load Balancer.

  • frontendIPConfiguration: The public IP or frontend IP where traffic arrives.
  • backendAddressPool: The group of virtual machines receiving the traffic.
  • probe: Health check to ensure backend VMs are healthy.
  • protocol: Network protocol used (TCP here).
  • frontendPort and backendPort: Ports on frontend and backend.
  • loadDistribution: How traffic is distributed (Default means even).
  • enableFloatingIP: Whether to allow direct server return traffic.
  • idleTimeoutInMinutes: Timeout for idle connections.
  • enableTcpReset: Whether to reset TCP connections on timeout.
Commands
This command creates a load balancing rule on the Azure Load Balancer named 'myLoadBalancer' in the resource group 'example-rg'. It sets TCP traffic on port 80 to be balanced between backend VMs, using a health probe to check VM status.
Terminal
az network lb rule create --resource-group example-rg --lb-name myLoadBalancer --name myLoadBalancingRule --protocol Tcp --frontend-port 80 --backend-port 80 --frontend-ip-name myFrontEnd --backend-pool-name myBackEndPool --probe-name myHealthProbe --idle-timeout 4 --enable-tcp-reset true
Expected OutputExpected
{ "frontendPort": 80, "backendPort": 80, "enableFloatingIP": false, "enableTcpReset": true, "idleTimeoutInMinutes": 4, "loadDistribution": "Default", "name": "myLoadBalancingRule", "protocol": "Tcp", "provisioningState": "Succeeded" }
→
--frontend-port - Port on the load balancer to listen on
→
--backend-port - Port on backend VMs to forward traffic to
→
--probe-name - Health probe to check backend VM health
This command lists all load balancing rules configured on the load balancer to verify the rule was created successfully.
Terminal
az network lb rule list --resource-group example-rg --lb-name myLoadBalancer
Expected OutputExpected
[{ "name": "myLoadBalancingRule", "protocol": "Tcp", "frontendPort": 80, "backendPort": 80, "provisioningState": "Succeeded" }]
Key Concept

If you remember nothing else from this pattern, remember: load balancing rules connect incoming traffic on a frontend IP and port to backend servers, using health probes to keep traffic flowing only to healthy servers.

Common Mistakes
Not specifying the correct frontend IP configuration name when creating the rule.
The load balancer won't know where to listen for incoming traffic, so the rule won't work.
Always use the exact frontend IP configuration name that exists on your load balancer.
Using different ports for frontend and backend without a clear reason.
This can cause confusion and traffic may not reach the backend service correctly.
Keep frontend and backend ports the same unless you have a specific need to translate ports.
Skipping the health probe configuration.
Without health probes, traffic may be sent to unhealthy or offline backend servers.
Always configure a health probe and link it to your load balancing rule.
Summary
Create a load balancing rule to direct traffic from a frontend IP and port to backend VMs.
Use health probes to ensure traffic only goes to healthy backend servers.
Verify the rule creation by listing load balancing rules on the load balancer.

Practice

(1/5)
1. What is the main purpose of a load balancing rule in Azure Load Balancer?
easy
A. To create virtual machines automatically
B. To store data securely in the cloud
C. To distribute incoming network traffic evenly across backend servers
D. To monitor user activity on a website

Solution

  1. Step 1: Understand load balancing rules

    Load balancing rules define how traffic is distributed from the frontend IP to backend servers.
  2. Step 2: Identify the main function

    The main function is to spread incoming traffic evenly to avoid overloading one server.
  3. Final Answer:

    To distribute incoming network traffic evenly across backend servers -> Option C
  4. Quick Check:

    Load balancing rules = distribute traffic evenly [OK]
Hint: Load balancing rules spread traffic evenly to backend servers [OK]
Common Mistakes:
  • Confusing load balancing with VM creation
  • Thinking it stores data
  • Assuming it tracks user activity
2. Which of the following is the correct way to specify a load balancing rule's frontend port in Azure CLI?
easy
A. --frontend-port 80
B. --frontendPort 80
C. --front-port 80
D. --port-frontend 80

Solution

  1. Step 1: Review Azure CLI syntax for load balancing rules

    The correct parameter for frontend port is '--frontend-port' with a hyphen.
  2. Step 2: Compare options

    Only --frontend-port 80 uses the exact correct syntax '--frontend-port 80'. Others have incorrect parameter names.
  3. Final Answer:

    --frontend-port 80 -> Option A
  4. Quick Check:

    Azure CLI frontend port = --frontend-port [OK]
Hint: Azure CLI uses hyphenated parameters like --frontend-port [OK]
Common Mistakes:
  • Using camelCase instead of hyphens
  • Mixing words order in parameter
  • Using incorrect parameter names
3. Given this Azure Load Balancer rule configuration snippet:
"frontendPort": 443,
"backendPort": 8443,
"protocol": "Tcp"

What happens when a user sends a TCP request to port 443 on the frontend IP?
medium
A. The request is forwarded to backend servers on port 8443
B. The request is blocked because ports do not match
C. The request is forwarded to backend servers on port 443
D. The request is forwarded using UDP protocol

Solution

  1. Step 1: Understand frontend and backend ports in load balancing

    The frontend port is where the client connects; the backend port is where the traffic is sent on backend servers.
  2. Step 2: Match the ports and protocol

    Client connects to port 443 (frontend), traffic is forwarded to backend servers on port 8443 using TCP.
  3. Final Answer:

    The request is forwarded to backend servers on port 8443 -> Option A
  4. Quick Check:

    Frontend port 443 forwards to backend port 8443 [OK]
Hint: Frontend port ≠ backend port; traffic forwards to backend port [OK]
Common Mistakes:
  • Assuming frontend and backend ports must be the same
  • Confusing TCP with UDP protocol
  • Thinking request is blocked due to port difference
4. You created a load balancing rule but traffic is not reaching backend servers. Which of these is a likely misconfiguration?
medium
A. Load balancing rule uses correct protocol and ports
B. Frontend IP address is set correctly
C. Backend pool contains healthy servers
D. Health probe is missing or misconfigured

Solution

  1. Step 1: Check role of health probes

    Health probes monitor backend server health; without them, load balancer may not send traffic.
  2. Step 2: Identify misconfiguration

    If health probe is missing or wrong, backend servers appear unhealthy, so traffic is blocked.
  3. Final Answer:

    Health probe is missing or misconfigured -> Option D
  4. Quick Check:

    Missing health probe blocks traffic [OK]
Hint: Always configure health probes to allow traffic flow [OK]
Common Mistakes:
  • Ignoring health probe setup
  • Assuming backend servers are always healthy
  • Overlooking frontend IP correctness
5. You want to create a load balancing rule that forwards HTTPS traffic from port 443 on the frontend IP to port 8443 on backend VMs, but only if the backend VMs pass a TCP health probe on port 8443. Which configuration is correct?
hard
A. Load balancing rule with frontendPort=8443, backendPort=443, protocol=Tcp; health probe on port 443 using Http
B. Load balancing rule with frontendPort=443, backendPort=8443, protocol=Tcp; health probe on port 8443 using Tcp
C. Load balancing rule with frontendPort=443, backendPort=443, protocol=Udp; health probe on port 8443 using Tcp
D. Load balancing rule with frontendPort=443, backendPort=8443, protocol=Tcp; no health probe configured

Solution

  1. Step 1: Match frontend and backend ports with protocol

    Frontend port 443 (HTTPS) forwards to backend port 8443 using TCP protocol, matching the requirement.
  2. Step 2: Configure health probe correctly

    Health probe must check TCP on port 8443 to verify backend VM health before forwarding traffic.
  3. Step 3: Verify other options

    Load balancing rule with frontendPort=8443, backendPort=443, protocol=Tcp; health probe on port 443 using Http swaps ports and uses HTTP probe incorrectly; Load balancing rule with frontendPort=443, backendPort=443, protocol=Udp; health probe on port 8443 using Tcp uses UDP protocol wrongly; Load balancing rule with frontendPort=443, backendPort=8443, protocol=Tcp; no health probe configured lacks health probe, risking traffic to unhealthy VMs.
  4. Final Answer:

    Load balancing rule with frontendPort=443, backendPort=8443, protocol=Tcp; health probe on port 8443 using Tcp -> Option B
  5. Quick Check:

    Correct ports, protocol, and health probe = Load balancing rule with frontendPort=443, backendPort=8443, protocol=Tcp; health probe on port 8443 using Tcp [OK]
Hint: Match frontend/backend ports and use health probe on backend port [OK]
Common Mistakes:
  • Swapping frontend and backend ports
  • Using wrong protocol (UDP instead of TCP)
  • Skipping health probe configuration