A decision guide by traffic type (HTTP or not) and scope (regional or global).
From Ultra Transcenders AZ-700 by Tony Rough (publishing soon)
Before configuring anything, decide which layer the traffic needs handling at and whether it is regional or global. The table below is the quickest way to rule services in or out. Figure 9.1 places each service by traffic type and scope.
| Service | Layer / scope | Handles | Doesn’t fit |
|---|---|---|---|
| Azure Load Balancer (Standard) | L4, regional (cross-region tier for global) | Any TCP/UDP port, internal or public, IPv4/IPv6 dual-stack; cheapest option | HTTP-aware routing |
| Application Gateway (v1/v2) | L7, regional | HTTP(S) proxy (limited TLS/TCP proxy); multi-site by host name | UDP, arbitrary ports, IPv6 backend addresses; costs more |
| Traffic Manager | DNS, global | Chooses an endpoint per DNS query with health checks | Inline traffic handling, NVA HA |
| Front Door | L7 HTTP, global (azurefd.net) |
Global HTTP(S) entry | Internal traffic, non-HTTP |
| NAT gateway | Outbound only | SNAT for a subnet | Any inbound connection |
Some typical design choices follow directly from the table:
This note is one section of Ultra Transcenders AZ-700: Designing and Implementing Microsoft Azure Networking Solutions, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free AZ-700 glossary · All AZ-700 study notes
How many usable addresses each prefix gives in Azure, why five are always reserved, and how to size subnets for gateways, Bastion and VMs.
Resolving Azure private zones from on-premises and on-premises names from Azure, with subnet sizing and ruleset rules.
Where each peering setting goes, what spokes can reach, and why peering isn't transitive.
Longest prefix match, system routes versus user-defined routes, and how a 0.0.0.0/0 route forces internet traffic on-premises.
What each ExpressRoute feature does, which SKUs and gateways it needs, and where it fits on a circuit.
The CNAME chain from a public service name to a private endpoint, zone groups and zone links.
Rule order, the default rules, and what happens to a flow between subnets and to return traffic.