A load balancer for web traffic that works at layer 7, sending HTTP and HTTPS requests to back ends based on host name or URL path. It can also handle TLS termination and run a web application firewall, which Azure Load Balancer cannot since it doesn't read web requests.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Application Gateway in context, with comparison tables and the common traps.
Terms in this definition
- ELT
Extract, load, transform: raw data lands in the target system first and is transformed there. See ETL for the opposite order.
- HTTP
Hypertext Transfer Protocol, which sends data in clear text; VCF interfaces and APIs instead use HTTPS.
- HTTPS
Secure HTTP, wrapped in TLS. VCF products serve their web UIs and REST APIs this way on 443.
- URL
The web address of a resource, on which URL-based routing relies.
- PATH
Parent-child hierarchies in DAX rely on this function. For each row it builds one delimited text value listing the IDs of the row's ancestors, top level first and ending with the row's own ID, which PATHITEM, PATHLENGTH and friends can then pick apart.
- TLS termination
Ending TLS at a gateway, for example Application Gateway, so traffic reaches backends as plain HTTP, or is encrypted again when end-to-end TLS is required.
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
- Azure Load Balancer
Layer-4 load balancer operating within a region, with zone redundancy on the Standard SKU; it has no WAF, doesn't terminate TLS and can't route by URL.