Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Application Gateway in context, with comparison tables and the common traps.
Terms in this definition
- ELT
Extract, load, transform: raw data lands in the target system first and is transformed there. See ETL for the opposite order.
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
- Geographic
A Traffic Manager routing method that picks the endpoint according to where the user is located geographically.
- TLS
Transport Layer Security, the encryption protocol for traffic like HTTPS and Bastion sessions over port 443. On a storage account, minimumTlsVersion fixes the oldest accepted version without opening any network access.
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
Related terms
- AGWFirewallLogs
Log Analytics table, resource-specific, that stores WAF events from Application Gateway. Front Door uses different tables.
- Application Gateway Ingress Controller
Add-on for AKS that reads Kubernetes Ingress resources and sets up an Application Gateway, WAF v2 included, to match them.
- Application Gateway v1
First-generation Application Gateway SKU, with Standard and WAF tiers and authentication certificates, which retired on 28 April 2026. Gateways already on v2 cannot revert to it.
- Application Gateway v2
Present-day Application Gateway SKU, Standard_v2 or WAF_v2, offering zone redundancy, autoscaling, a static VIP, Key Vault integration and header rewrite. It requires its own subnet, ideally a /24.
- Application Gateway WAF tier
Tier of Application Gateway that brings OWASP Core Rule Set protection, now WAF_v2 since the v1 WAF tier retired on 28 April 2026. No WAF is included with the Standard tier.
- Backend settings
Reusable Application Gateway configuration, shareable between rules, covering how backends are contacted: protocol and port, any host name override, a custom health probe and the certificates trusted on the backend.
- CRS
The OWASP Core Rule Set, on which the Application Gateway WAF bases its rules.
- Custom health probe
Application Gateway probe tied to backend settings in which you choose host, path, interval, match criteria and (on v2) port, for example to test port 8080.