Ending TLS at a gateway, for example Application Gateway, so traffic reaches backends as plain HTTP, or is encrypted again when end-to-end TLS is required.
Also called SSL offload.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains TLS termination in context, with comparison tables and the common traps.
Terms in this definition
- TLS
Transport Layer Security, the encryption protocol for traffic like HTTPS and Bastion sessions over port 443. On a storage account, minimumTlsVersion fixes the oldest accepted version without opening any network access.
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- HTTP
Hypertext Transfer Protocol, which sends data in clear text; VCF interfaces and APIs instead use HTTPS.
- End-to-end TLS
The client's TLS ends at Application Gateway, which then encrypts a fresh connection to the backend. For this, HTTPS is required in the backend settings, and the backend's certificate has to be trusted.
Related terms
- Azure Application Gateway
A load balancer for web traffic that works at layer 7, sending HTTP and HTTPS requests to back ends based on host name or URL path. It can also handle TLS termination and run a web application firewall, which Azure Load Balancer cannot since it doesn't read web requests.
- SSL
The forerunner of TLS, whose name is still applied to TLS. Terminating TLS at a load balancer is called SSL offload, and VPN Gateway's SSTP (SSL) and OpenVPN (SSL) P2S tunnels run TLS over TCP 443.