Reusable Application Gateway configuration, shareable between rules, covering how backends are contacted: protocol and port, any host name override, a custom health probe and the certificates trusted on the backend.
Also called backend HTTP settings.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Backend settings in context, with comparison tables and the common traps.
Terms in this definition
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- Custom health probe
Application Gateway probe tied to backend settings in which you choose host, path, interval, match criteria and (on v2) port, for example to test port 8080.
Related terms
- Authentication certificate
How Application Gateway v1 trusted backends: the public key (.cer) of the backend's certificate was uploaded into backend settings. On v2, trusted root certificates take its place.
- Default health probe
Automatic Application Gateway probe built from the protocol and port in the backend settings, aimed at 127.0.0.1 when no host is given. Problems on any other port go unnoticed.
- End-to-end TLS
The client's TLS ends at Application Gateway, which then encrypts a fresh connection to the backend. For this, HTTPS is required in the backend settings, and the backend's certificate has to be trusted.
- Request routing rule
Decides where traffic arriving on an Application Gateway listener goes. A basic rule forwards it to one backend pool with set backend settings; a path-based rule picks the pool from a URL path map.
- Trusted root certificate
How Application Gateway v2 trusts a backend: the .cer root CA certificate for the backend's certificate is added in backend settings. Certificates issued by well-known CAs don't require it.