Courses Job Ready Program Fresher Trainings AI For Class 7 to 12 Corporate Training Placements Tutorials
Free Learning Resources

IT Tutorials & Interview Prep

Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

248+
Tutorial Articles
17
Topic Categories
100%
Free to Read
← Back to Learning Hub

AZ-104:Day 11 —Azure Load Balancing

Learning Hub Last Updated: Sep 16, 2026

Key Points, Definitions, Diagrams, Term Differences & Q&A

 

1. 25 Most Important Key Points

  • Azure Load Balancing distributes incoming network traffic across multiple backend resources (VMs, VMSS instances) to improve availability and performance.
  • Azure offers four load-balancing services — Azure Load Balancer, Application Gateway, Traffic Manager, and Azure Front Door — each suited to a different layer or scope.
  • Azure Load Balancer operates at Layer 4 (Transport layer) of the OSI model, distributing TCP and UDP traffic based on IP address and port.
  • Azure Load Balancer can be Public (internet-facing) or Internal/Private (accessible only within a VNet).
  • A Frontend IP Configuration is the IP address and port on which the Load Balancer receives incoming traffic.
  • A Backend Pool is the group of VMs or VMSS instances that receive traffic distributed by the Load Balancer.
  • Load Balancing Rules define how traffic received on a frontend IP/port is distributed to the backend pool.
  • Health Probes continuously check backend instance health (TCP, HTTP, or HTTPS) and automatically remove unhealthy instances from receiving traffic.
  • Inbound NAT Rules forward traffic from a specific frontend port to a specific backend instance port, commonly used for RDP/SSH access to individual VMs.
  • Outbound Rules define how backend pool instances use the Load Balancer's frontend IP for outbound internet connectivity (SNAT).
  • Azure Load Balancer is available in two SKUs: Basic (free, no SLA, limited features) and Standard (paid, 99.99% SLA, zone-redundant, HA Ports).
  • Standard SKU Load Balancer supports Availability Zones, making it zone-redundant or zonal for higher resilience.
  • HA Ports is a Standard SKU feature that load-balances all TCP/UDP ports simultaneously on a single rule, commonly used for network virtual appliances (NVAs).
  • Session persistence (also called session affinity) controls whether requests from the same client are always routed to the same backend instance.
  • Application Gateway operates at Layer 7 (Application layer), routing HTTP/HTTPS traffic based on URL path, host header, or other application-level data.
  • Application Gateway includes a built-in Web Application Firewall (WAF) to protect against common web exploits like SQL injection and cross-site scripting.
  • Application Gateway supports SSL/TLS termination, offloading encryption/decryption work from backend servers.
  • Azure Traffic Manager is a DNS-based global traffic router that directs client requests to the closest or healthiest endpoint across regions — it does not proxy traffic itself.
  • Traffic Manager routing methods include Priority, Weighted, Performance, Geographic, MultiValue, and Subnet.
  • Azure Front Door is a global, Layer 7 load-balancing and CDN service that provides SSL offload, WAF, URL-based routing, and edge acceleration.
  • Front Door improves performance by routing users to the nearest healthy backend using Microsoft's global edge network, rather than DNS resolution alone.
  • Choosing between services depends on scope (regional vs global) and OSI layer (Layer 4 vs Layer 7) needed for the workload.
  • Azure Load Balancer and Application Gateway are regional services; Traffic Manager and Front Door are global services.
  • Multiple load-balancing services can be combined — e.g., Front Door in front of regional Application Gateways, which in turn front VM Scale Sets behind an internal Load Balancer.
  • Best practice: use Standard SKU with Availability Zones for production workloads, configure meaningful health probes, and monitor backend pool health with Azure Monitor.

Figure 2: Basic SKU vs. Standard SKU cheat sheet

2. 20 Definitions with Day-to-Day Examples

Azure Load Balancer

Definition: A Layer 4 (Transport layer) service that distributes incoming TCP/UDP traffic across multiple backend VM instances.

Day-to-Day Example: Like a traffic cop at an intersection directing cars evenly onto multiple lanes so no single lane gets overloaded.

Public Load Balancer

Definition: A Load Balancer with a public IP frontend that accepts traffic from the internet.

Day-to-Day Example: Like the main reception desk of a building that greets outside visitors and directs them to the right department.

Internal (Private) Load Balancer

Definition: A Load Balancer with a private IP frontend, accessible only within a Virtual Network.

Day-to-Day Example: Like an internal office directory that only employees can use to route calls between departments.

Frontend IP Configuration

Definition: The IP address and port combination on which a Load Balancer listens for incoming traffic.

Day-to-Day Example: Like the single phone number printed on a company's storefront that customers call.

Backend Pool

Definition: The set of VMs or VMSS instances that a Load Balancer forwards traffic to.

Day-to-Day Example: Like the group of available cashiers a store manager assigns customers to.

Load Balancing Rule

Definition: A rule mapping a frontend IP/port to a backend pool and port, defining how traffic is distributed.

Day-to-Day Example: Like a receptionist's instructions on which department to forward a call to based on the extension dialed.

Health Probe

Definition: A periodic check (TCP, HTTP, or HTTPS) used to determine whether a backend instance is healthy enough to receive traffic.

Day-to-Day Example: Like a manager periodically checking if each cashier's register is open before sending customers there.

Inbound NAT Rule

Definition: A rule that forwards traffic from a specific frontend port to a specific port on one backend instance.

Day-to-Day Example: Like a hotel switchboard connecting an outside caller directly to one specific room's phone.

Outbound Rule

Definition: A rule defining how backend instances use the Load Balancer's frontend IP for outbound connections to the internet.

Day-to-Day Example: Like all employees using the company's single main phone line as caller ID when making outgoing calls.

Basic SKU (Load Balancer)

Definition: The free tier of Load Balancer with no SLA, no Availability Zone support, and a smaller backend pool limit.

Day-to-Day Example: Like a basic home Wi-Fi router — fine for light use, but without guarantees or advanced features.

Standard SKU (Load Balancer)

Definition: The paid tier offering a 99.99% SLA, Availability Zone support, HA Ports, and a larger backend pool.

Day-to-Day Example: Like an enterprise-grade network switch with redundancy and guaranteed uptime for a business.

HA Ports

Definition: A Standard SKU load-balancing rule that forwards all TCP and UDP ports at once to the backend pool.

Day-to-Day Example: Like a mailroom that forwards every type of package, regardless of size or label, to the correct department automatically.

Session Persistence (Session Affinity)

Definition: A setting controlling whether repeated requests from the same client are sent to the same backend instance.

Day-to-Day Example: Like a regular customer always being seated at the same table by the same waiter at a restaurant.

Azure Application Gateway

Definition: A Layer 7 (Application layer) load balancer for web traffic that can route based on URL path or host name and includes WAF protection.

Day-to-Day Example: Like a smart concierge who reads the visitor's request and sends them to the exact right office, while also checking IDs for security.

Web Application Firewall (WAF)

Definition: A security feature on Application Gateway (or Front Door) that inspects and filters malicious web traffic.

Day-to-Day Example: Like a security guard screening bags at the entrance to a building before anyone is let inside.

URL-Based Routing

Definition: An Application Gateway feature that sends requests to different backend pools based on the URL path (e.g., /images, /api).

Day-to-Day Example: Like a large store's directory sign pointing customers to different aisles based on what they're looking for.

Azure Traffic Manager

Definition: A DNS-based global traffic routing service that directs clients to the most appropriate regional endpoint without proxying the actual data.

Day-to-Day Example: Like a call-center operator who tells you which regional branch to call, then hangs up — the actual conversation happens directly with that branch.

Traffic Manager Routing Method

Definition: The algorithm (Priority, Weighted, Performance, Geographic, etc.) Traffic Manager uses to decide which endpoint to return to a client.

Day-to-Day Example: Like a company deciding whether to route customer calls by branch importance, call volume sharing, nearest location, or customer's home region.

Azure Front Door

Definition: A global Layer 7 service combining load balancing, CDN, WAF, and SSL offload at Microsoft's edge network to accelerate and secure web applications.

Day-to-Day Example: Like a chain of local franchise storefronts (edge locations) that all represent the same brand, so customers are served quickly from the nearest one.

SSL/TLS Offload (Termination)

Definition: The process of decrypting HTTPS traffic at the load balancer or gateway so backend servers don't have to handle encryption themselves.

Day-to-Day Example: Like a hotel's front desk handling ID verification for guests so staff at each floor don't have to check identity again.

Figure 3: Choosing the right Azure load-balancing service — Load Balancer, App Gateway, Traffic Manager, Front Door

Figure 4: Public Load Balancer vs. Internal Load Balancer traffic paths

3. Differences Between Key Technical Terms (10)

1. Azure Load Balancer vs. Application Gateway

FeatureLoad BalancerApplication Gateway
OSI LayerLayer 4 (TCP/UDP)Layer 7 (HTTP/HTTPS)
Routing basisIP address and portURL path, host header, cookies
Common confusionAssumed to read HTTP contentIt only sees packets, not URLs or headers



 

2. Public Load Balancer vs. Internal Load Balancer

FeaturePublic LBInternal LB
Frontend IPPublic IPPrivate IP
Accessible fromInternetWithin VNet / on-premises via VPN or ExpressRoute
Common useInternet-facing web tierBackend or database tier traffic



 

3. Basic SKU vs. Standard SKU

FeatureBasic SKUStandard SKU
CostFreeCharged per rule/hour
SLANone99.99%
Availability ZonesNot supportedSupported



 

4. Layer 4 vs. Layer 7 Load Balancing

FeatureLayer 4Layer 7
Data inspectedIP address, portURL, headers, cookies, HTTP methods
Example serviceAzure Load BalancerApplication Gateway, Front Door
Common confusionAssumed capable of URL routingOnly Layer 7 services can route by URL



 

5. Load Balancing Rule vs. Inbound NAT Rule

FeatureLoad Balancing RuleInbound NAT Rule
Maps toEntire backend poolOne specific backend instance
Typical useDistributing app trafficRDP/SSH access to a single VM
Common confusionAssumed to target one VMIt spreads traffic; NAT rule targets one VM



 

6. Azure Load Balancer vs. Azure Traffic Manager

FeatureLoad BalancerTraffic Manager
ScopeRegionalGlobal
MechanismProxies traffic (Layer 4)DNS-based redirection (no proxying)
Common confusionAssumed to work across regionsRegional only; use Traffic Manager for global



 

7. Traffic Manager vs. Azure Front Door

FeatureTraffic ManagerFront Door
LayerDNS (no traffic proxying)Layer 7 (HTTP/HTTPS)
Extra featuresRouting onlyWAF, caching/CDN, URL routing, SSL offload
Common confusionAssumed to accelerate contentIt only resolves DNS; Front Door actively proxies and caches



 

8. TCP Health Probe vs. HTTP/HTTPS Health Probe

FeatureTCP ProbeHTTP/HTTPS Probe
ChecksPort connectivity onlyActual response code/content from a URL path
Best forSimple availability checksApplication-level health (e.g., app crashed but port open)
Common confusionAssumed to detect app failuresTCP probe can't detect a hung app that still accepts connections



 

9. Session Persistence Modes

TypeBest Suited For
NoneStateless applications where any backend can serve any request
Client IPSimple session stickiness based on client IP address
Client IP and ProtocolStickier persistence considering both IP and protocol used



 

10. Azure Load-Balancing Services Compared

ServiceOSI Layer / ScopeTypical Use Case
Azure Load BalancerLayer 4, RegionalBalancing VM/VMSS network traffic within a region
Application GatewayLayer 7, RegionalWeb traffic routing with WAF within a region
Traffic ManagerDNS, GlobalDirecting clients to the nearest/healthiest region
Azure Front DoorLayer 7, GlobalGlobal web acceleration, WAF, and edge routing


 

4. Theoretical Questions (15)

Q1. What is Azure Load Balancing, and why is it used?

Answer: Azure Load Balancing distributes incoming network traffic across multiple backend resources such as VMs or VMSS instances, improving application availability, scalability, and fault tolerance.

Q2. What OSI layer does Azure Load Balancer operate at, and what does that mean?

Answer: Azure Load Balancer operates at Layer 4 (Transport layer), meaning it makes routing decisions based on IP address and port only, without inspecting application-level data like URLs.

Q3. What is the difference between a Public and an Internal Load Balancer?

Answer: A Public Load Balancer has a public IP frontend and accepts traffic from the internet, while an Internal Load Balancer has a private IP frontend and only accepts traffic from within a Virtual Network.

Q4. What is a Backend Pool, and what does it contain?

Answer: A Backend Pool is the group of VMs or Virtual Machine Scale Set instances that the Load Balancer distributes traffic to based on load balancing rules.

Q5. What is the role of a Health Probe?

Answer: A Health Probe periodically checks backend instance health (via TCP, HTTP, or HTTPS) and automatically removes unhealthy instances from receiving new traffic until they recover.

Q6. What is the difference between a Load Balancing Rule and an Inbound NAT Rule?

Answer: A Load Balancing Rule distributes traffic across the entire backend pool, while an Inbound NAT Rule forwards traffic from a specific frontend port to one specific backend instance, commonly used for direct RDP/SSH access.

Q7. What distinguishes the Basic SKU from the Standard SKU of Azure Load Balancer?

Answer: The Basic SKU is free with no SLA and no Availability Zone support, while the Standard SKU is paid, offers a 99.99% SLA, supports Availability Zones, and includes advanced features like HA Ports.

Q8. What is HA Ports, and when is it used?

Answer: HA Ports is a Standard SKU feature that load-balances all TCP and UDP ports through a single rule, commonly used for network virtual appliances that must inspect traffic on many ports.

Q9. How does Azure Application Gateway differ from Azure Load Balancer?

Answer: Application Gateway operates at Layer 7 and can route HTTP/HTTPS traffic based on URL path or host header, and includes a Web Application Firewall, whereas Load Balancer works at Layer 4 based only on IP and port.

Q10. What does a Web Application Firewall (WAF) protect against?

Answer: A WAF protects web applications from common exploits such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 vulnerabilities, typically deployed on Application Gateway or Front Door.

Q11. How does Azure Traffic Manager route traffic, and what is a key limitation of that approach?

Answer: Traffic Manager uses DNS-based routing to direct clients to the most appropriate regional endpoint; its key limitation is that it only resolves DNS and does not proxy or inspect the actual traffic itself.

Q12. What are two Traffic Manager routing methods, and what do they prioritize?

Answer: Priority routing sends traffic to a primary endpoint with failover to backups, while Performance routing sends traffic to the endpoint with the lowest network latency for the client.

Q13. What additional capabilities does Azure Front Door provide beyond basic global routing?

Answer: Front Door adds Layer 7 HTTP/HTTPS routing, a built-in WAF, SSL offload, caching/CDN acceleration, and URL-based routing at Microsoft's global edge network.

Q14. Why are Azure Load Balancer and Application Gateway considered regional services while Traffic Manager and Front Door are considered global?

Answer: Load Balancer and Application Gateway operate within a single Azure region's resources, while Traffic Manager and Front Door route clients across multiple regions worldwide to the closest or healthiest endpoint.

Q15. Why might an architecture combine multiple load-balancing services together?

Answer: Combining services — e.g., Front Door for global entry, Application Gateway per region for WAF and URL routing, and an internal Load Balancer for backend VM traffic — layers global reach, security, and regional efficiency for a complete, resilient design.

5. Scenario-Based Questions (8)

Q1. A company runs a web app on VMs in a single region and needs traffic split evenly across them using only IP and port information, with no need for URL-based routing. What should they use?

Answer: They should use Azure Load Balancer (Standard SKU), since Layer 4 IP/port-based distribution across VMs within one region is exactly what it's built for.

Q2. An application needs to route /images requests to one set of servers and /api requests to another set of servers, all within the same domain. What service fits, and why?

Answer: Azure Application Gateway fits, because its Layer 7 URL-based routing can inspect the path and direct /images and /api requests to different backend pools.

Q3. A company has identical web applications deployed in three Azure regions and wants global users automatically directed to the nearest healthy region using DNS, without paying for content acceleration or WAF. What should they use?

Answer: They should use Azure Traffic Manager with Performance routing, since it provides DNS-based global routing to the closest healthy region without the added CDN/WAF cost of Front Door.

Q4. A global e-commerce site wants edge caching, a Web Application Firewall, SSL offload, and Layer 7 routing across multiple regions. What should they implement?

Answer: They should implement Azure Front Door, since it combines global Layer 7 routing, WAF, SSL offload, and CDN-style caching at Microsoft's edge network.

Q5. A network virtual appliance (NVA) needs to inspect traffic across a wide, unpredictable range of TCP and UDP ports through a single load-balancing rule. What feature should be configured?

Answer: They should configure HA Ports on a Standard SKU Load Balancer, which load-balances all ports through one rule instead of requiring a rule per port.

Q6. An administrator needs to RDP directly into one specific VM behind a Load Balancer using a unique external port, without exposing RDP on every VM. What should they configure?

Answer: They should configure an Inbound NAT Rule mapping a unique frontend port to port 3389 on that specific VM.

Q7. A production workload requires 99.99% availability and must survive the loss of an entire datacenter within a region. What Load Balancer configuration should be used?

Answer: They should use a Standard SKU Load Balancer configured as zone-redundant across Availability Zones, giving both the 99.99% SLA and resilience to a zone/datacenter failure.

Q8. A shopping cart application needs each user's requests to consistently reach the same backend server for the duration of their session. What should be configured?

Answer: They should configure Session Persistence (session affinity) — such as Client IP-based persistence — on the load-balancing service so repeated requests from the same client land on the same backend instance.