Entry point of an Application Gateway, which accepts requests on a given frontend IP, port and protocol, optionally per host name for multi-site setups. You attach the HTTPS certificate and SSL profile to it, but traffic flows only once a routing rule references it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Listener in context, with comparison tables and the common traps.
Terms in this definition
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- HTTPS
Secure HTTP, wrapped in TLS. VCF products serve their web UIs and REST APIs this way on 443.
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- SSL profile
Settings on an Application Gateway v2 listener that hold a listener-specific SSL policy and client authentication, meaning the trusted client CA chain used for mutual TLS.
- Geographic
A Traffic Manager routing method that picks the endpoint according to where the user is located geographically.
Related terms
- Auto-failover group
Azure SQL feature that geo-replicates a group of databases or an entire Managed Instance, failing over automatically behind listener endpoints that stay the same. For Managed Instance it is the sole regional DR option.
- Distributed network name
A SQL Server listener option on Azure VMs. Unlike a virtual network name (VNN) it works without any Azure Load Balancer and completes failover faster.
- Key Vault integration (Application Gateway)
Application Gateway v2 feature that pulls listener certificates out of Key Vault, signing in with a user-assigned managed identity. HSM-protected certificates aren't supported, only software-protected ones.
- Multi-site listener
Application Gateway listener type that chooses a route based on host name, so numerous sites can sit behind a single frontend IP and port. On v2 it accepts up to five host names or wildcards.
- Regional WAF policy
Kind of WAF policy used with Application Gateway, created in the same region as the gateway and applied to the whole gateway, a listener or a path. You can create it before the gateway.
- Request routing rule
Decides where traffic arriving on an Application Gateway listener goes. A basic rule forwards it to one backend pool with set backend settings; a path-based rule picks the pool from a URL path map.
- VNN
The legacy listener type for SQL Server on Azure VMs, requiring an Azure Load Balancer; DNN has replaced it.
- Wildcard certificate
Issued for *.domain, this TLS certificate secures any first-level subdomain, so new host names on a listener are covered; the bare apex and multi-level subdomains are not.