Azure Load Balancer & Application Gateway

Microsoft Azure Networking (AZ-700 track) Azure portal — free tier (GUI + CLI)

مقصدObjectiveObjective

Load Balancer SKUs اور Application Gateway features سمجھنا — اور backend pool کے ساتھ Standard Load Balancer بنانا۔Load Balancer SKUs aur Application Gateway features samajhna — aur backend pool ke saath Standard Load Balancer banana.Understand Load Balancer SKUs and Application Gateway features — and create a Standard Load Balancer with a backend pool.

آسان مثالSimple AnalogySimple Analogy

Load Balancer ایک receptionist ہے جو visitors کو کسی free clerk کے پاس بھیجتا ہے — یہ Layer 4 پر کام کرتا ہے۔ Application Gateway smart receptionist ہے جو visitor کا request letter (HTTP/HTTPS) پڑھ کر URL path کے حساب سے route کرتا ہے — Layer 7۔Load Balancer ek receptionist hai jo visitors ko kisi free clerk ke paas bhejta hai — yeh Layer 4 par kaam karta hai. Application Gateway smart receptionist hai jo visitor ka request letter (HTTP/HTTPS) parh kar URL path ke hisab se route karta hai — Layer 7.Load Balancer is a receptionist who sends visitors to any free clerk — it works at Layer 4. Application Gateway is a smart receptionist who reads the visitor's request letter (HTTP/HTTPS) and routes by URL path — Layer 7.

سیٹ اپLab SetupLab Setup

rg-netsec-lab اور vnet-core استعمال کریں۔ آپ load balancer کو snet-web backends کے سامنے رکھیں گے۔rg-netsec-lab aur vnet-core use karein. Aap load balancer ko snet-web backends ke saamne rakhein ge.Use rg-netsec-lab and vnet-core. You will place the load balancer in front of snet-web backends.

اقداماتStepsSteps

Step 1

lb-web نام کا Standard SKU public Load Balancer بنائیں، frontend IP اور backend pool bepool کے ساتھ۔ Backend pool میں وہ servers ہوں گے جنہیں ٹریفک ملے گا۔lb-web naam ka Standard SKU public Load Balancer banayein, frontend IP aur backend pool bepool ke saath. Backend pool mein woh servers honge jinhe traffic milega.Create a Standard SKU public Load Balancer named lb-web with a frontend IP and a backend pool bepool. The backend pool will hold the servers that receive traffic.

az network lb create --resource-group rg-netsec-lab --name lb-web --sku Standard --public-ip-address-allocation Static --public-ip-sku Standard --backend-pool-name bepool --frontend-ip-name fepublic --location southeastasia

🖱️ Load balancers > Create — SKU Standard، public frontend، backend pool bepoolLoad balancers > Create — SKU Standard, public frontend, backend pool bepoolLoad balancers > Create — SKU Standard, public frontend, backend pool bepool

Step 2

Port 80، path / پر HTTP health probe شامل کریں۔ Probe چیک کرتا ہے کہ کون سے backends healthy ہیں پھر انہیں ٹریفک بھیجتا ہے۔Port 80, path / par HTTP health probe add karein. Probe check karta hai ke kaunse backends healthy hain phir unhe traffic bhejta hai.Add an HTTP health probe on port 80, path /. The probe checks which backends are healthy before sending them traffic.

az network lb probe create --resource-group rg-netsec-lab --lb-name lb-web --name probe-http --protocol Http --port 80 --path / --interval 15 --threshold 4

🖱️ Load balancers > lb-web > Health probes > Add — port 80، path / پر HTTP probeLoad balancers > lb-web > Health probes > Add — port 80, path / par HTTP probeLoad balancers > lb-web > Health probes > Add — HTTP probe on port 80, path /

Step 3

Load balancing rule شامل کریں: frontend port 80 سے backend port 80۔ یہ rule frontend IP، backend pool اور probe کو جوڑتا ہے۔Load balancing rule add karein: frontend port 80 se backend port 80. Yeh rule frontend IP, backend pool aur probe ko jorta hai.Add a load balancing rule: frontend port 80 to backend port 80. This rule ties the frontend IP, backend pool, and probe together.

az network lb rule create --resource-group rg-netsec-lab --lb-name lb-web --name rule-http --protocol Tcp --frontend-port 80 --backend-port 80 --frontend-ip-name fepublic --backend-pool-name bepool --probe-name probe-http

🖱️ Load balancers > lb-web > Load balancing rules > Add — frontend 80 سے backend 80Load balancers > lb-web > Load balancing rules > Add — frontend 80 se backend 80Load balancers > lb-web > Load balancing rules > Add — frontend 80 to backend 80

Step 4

Load balancer، اس کا frontend public IP، backend pool، probe اور rule ویریفائی کریں۔ Frontend IP نوٹ کریں — یہ single entry point بنتا ہے۔Load balancer, us ka frontend public IP, backend pool, probe aur rule verify karein. Frontend IP note karein — yeh single entry point banta hai.Verify the load balancer, its frontend public IP, backend pool, probe, and rule. Note the frontend IP — it becomes the single entry point.

az network lb list --resource-group rg-netsec-lab --output table

🖱️ Load balancers — تصدیق کریں کہ lb-web اپنے public IP کے ساتھ نظر آ رہا ہےLoad balancers — tasdeeq karein ke lb-web apne public IP ke saath nazar aa raha haiLoad balancers — verify lb-web appears with its public IP

Step 5

Application gateways > Create کھولیں اور pieces کا جائزہ لیں: SKU (Standard_v2)، listeners (frontend port/protocol)، routing rules، اور backend pools۔ صرف concepts — deploy نہ کریں (لاگت ہوتی ہے)۔Application gateways > Create kholein aur pieces review karein: SKU (Standard_v2), listeners (frontend port/protocol), routing rules, aur backend pools. Sirf concepts — deploy na karein (cost hoti hai).Open Application gateways > Create and review the pieces: SKU (Standard_v2), listeners (frontend port/protocol), routing rules, and backend pools. Concepts only — do not deploy (costs money).

🖱️ Application gateways > Create — SKU (Standard_v2)، listeners، rules، backend pools کا جائزہ لیںApplication gateways > Create — SKU (Standard_v2), listeners, rules, backend pools review kareinApplication gateways > Create — review SKU (Standard_v2), listeners, rules, backend pools

Step 6

Listener rule types کا موازنہ کریں: Basic (ایک backend)، Path-based (مثلاً /images/* pool A کو، /api/* pool B کو)، اور Multi-site (hostname سے route)۔ یہ Application Gateway کی Layer 7 power ہے۔Listener rule types compare karein: Basic (ek backend), Path-based (masalan /images/* pool A ko, /api/* pool B ko), aur Multi-site (hostname se route). Yeh Application Gateway ki Layer 7 power hai.Compare listener rule types: Basic (one backend), Path-based (e.g. /images/* to pool A, /api/* to pool B), and Multi-site (route by hostname). This is Application Gateway's Layer 7 power.

🖱️ Application gateways > Create > Rules tab — Basic بمقابلہ Path-based بمقابلہ Multi-site listeners کا موازنہ کریںApplication gateways > Create > Rules tab — Basic vs Path-based vs Multi-site listeners compare kareinApplication gateways > Create > Rules tab — compare Basic vs Path-based vs Multi-site listeners

تصدیقVerifyVerify

lb-web موجود ہے public frontend IP، backend pool bepool، HTTP health probe اور port-80 load balancing rule کے ساتھ۔lb-web maujood hai public frontend IP, backend pool bepool, HTTP health probe aur port-80 load balancing rule ke saath.lb-web exists with a public frontend IP, backend pool bepool, HTTP health probe, and a port-80 load balancing rule.

az network lb rule list --resource-group rg-netsec-lab --lb-name lb-web --output table

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Probe نے backend کو unhealthy mark کر دیاProbe ne backend ko unhealthy mark kar diyaBackend marked unhealthy by the probe

✅ چیک کریں کہ backend subnet کا NSG probe path (port 80) allow کرتا ہے۔ تصدیق کریں کہ backend app probe path / پر timeout کے اندر respond کرتی ہے۔Check karein ke backend subnet ka NSG probe path (port 80) allow karta hai. Tasdeeq karein ke backend app probe path / par timeout ke andar respond karti hai.Check the NSG on the backend subnet allows the probe path (port 80). Also confirm the backend app responds on the probe path / within the timeout.

⚠️ Load balancer rule creation ناکامLoad balancer rule creation failLoad balancer rule creation fails

✅ پہلے probe اور backend pool بنائیں — rule انہیں نام سے refer کرتی ہے۔ نام verify کریں: az network lb show --resource-group rg-netsec-lab --name lb-web۔Pehle probe aur backend pool banayein — rule unhe naam se refer karti hai. Naam verify karein: az network lb show --resource-group rg-netsec-lab --name lb-web.Create the probe and backend pool first — a rule references them by name. Verify names with: az network lb show --resource-group rg-netsec-lab --name lb-web.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ Azure Load Balancer اور Application Gateway میں کیا فرق ہے؟Azure Load Balancer aur Application Gateway mein kya farq hai?What is the difference between Azure Load Balancer and Application Gateway?

Azure Load Balancer Layer 4 (TCP/UDP) پر کام کرتا ہے اور default 5-tuple hash سے ٹریفک بانٹتا ہے۔ Application Gateway Layer 7 (HTTP/HTTPS) پر کام کرتا ہے اور path-based routing، SSL termination اور web application firewall (WAF) شامل کرتا ہے۔Azure Load Balancer Layer 4 (TCP/UDP) par kaam karta hai aur default 5-tuple hash se traffic baant-ta hai. Application Gateway Layer 7 (HTTP/HTTPS) par kaam karta hai aur path-based routing, SSL termination aur web application firewall (WAF) add karta hai.Azure Load Balancer works at Layer 4 (TCP/UDP) and spreads traffic with a 5-tuple hash by default. Application Gateway works at Layer 7 (HTTP/HTTPS) and adds path-based routing, SSL termination, and a web application firewall (WAF).

❓ Basic بمقابلہ Standard Load Balancer SKU؟Basic vs Standard Load Balancer SKU?Basic vs Standard Load Balancer SKU?

Basic چھوٹی labs کے لیے free-tier friendly ہے لیکن اس میں SLA یا zone redundancy نہیں۔ Standard میں zone redundancy، diagnostics اور SLA ہے، اور یہ production کا انتخاب ہے۔Basic choti labs ke liye free-tier friendly hai lekin us mein SLA ya zone redundancy nahi. Standard mein zone redundancy, diagnostics aur SLA hai, aur yeh production ka choice hai.Basic is free-tier friendly for small labs but has no SLA and no zone redundancy. Standard adds zone redundancy, diagnostics, an SLA, and is the production choice.