Present-day Application Gateway SKU, Standard_v2 or WAF_v2, offering zone redundancy, autoscaling, a static VIP, Key Vault integration and header rewrite. It requires its own subnet, ideally a /24.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Application Gateway v2 in context, with comparison tables and the common traps.
Terms in this definition
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- SKU
The size or tier of a service, for example a VM size or the Premium tier of ACR.
- Standard V2
The Application Gateway tiers: Standard_v2 supports rewrites but lacks WAF, WAF_v2 adds a WAF, and Basic offers neither URL rewrite nor WAF. Only WAF_v2 can have a WAF policy attached.
- WAF V2
Of the Application Gateway tiers, this one brings protection based on the OWASP Core Rule Set; Standard lacks any WAF, and the first-generation WAF tier reached retirement on 28 April 2026.
- Redundancy
So that hardware failures, datacentre outages or a regional disaster cannot destroy data, Azure Storage keeps multiple copies: only in the primary region with LRS and ZRS, or in a secondary region as well with GRS and GZRS.
- Autoscaling
A classic compute option where you give a minimum and maximum worker count and Azure Databricks adjusts the number of workers within that range to match the load.
- VIP
The frontend address of a load balancer, also called its virtual IP. Its availability is tracked by the Data Path Availability metric.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
Related terms
- Application Gateway autoscaling
Capability of Application Gateway v2 that varies the instance count between configured minimum and maximum values, at most 125. Plan subnet size for that maximum, adding one address per private frontend IP.
- Application Gateway Basic SKU
Low-traffic Application Gateway v2 SKU that supports header rewrite but omits WAF, mTLS and URL rewrite.
- Capacity unit
Unit used to size and bill Application Gateway v2, set by whichever is greatest of one compute unit, 2,500 persistent connections or 2.22 Mbps; an instance supplies roughly 10 of them.
- GatewayManager (service tag)
Represents the management traffic Azure's own infrastructure sends. On an Application Gateway v2 subnet, the NSG has to let this tag in on ports 65200-65535 (65503-65534 for v1).
- Key Vault integration (Application Gateway)
Application Gateway v2 feature that pulls listener certificates out of Key Vault, signing in with a user-assigned managed identity. HSM-protected certificates aren't supported, only software-protected ones.
- Network Watcher NSG diagnostics
Covers cases IP flow verify cannot, simulating a flow (ICMP too) against a VM, NIC, scale set NIC or Application Gateway v2 to report allow or deny and the rules involved.
- Private Application Gateway deployment
An Application Gateway v2 whose only frontend is a private IP, with no public IP resource attached. Without a public frontend, the NSG no longer has to allow GatewayManager traffic in or Internet traffic out.
- Rewrite rules
Application Gateway v2 rules for changing URLs and request or response headers. Redirects, and 4xx or 5xx responses produced by the gateway itself, are unaffected.