Application Gateway TCP/TLS proxy overview (Preview) (2024)

  • Article

In addition to the existing Layer 7 capabilities (HTTP, HTTPS, WebSockets and HTTP/2), Azure Application Gateway now also supports Layer 4 (TCP protocol) and TLS (Transport Layer Security) proxying. This feature is currently in public preview. To preview this feature, see Register to the preview.

TLS/TCP proxy capabilities on Application Gateway

As a reverse proxy service, the Layer 4 operations of Application Gateway work similar to its Layer 7 proxy operations. A client establishes a TCP connection with Application Gateway, and Application Gateway itself initiates a new TCP connection to a backend server from the backend pool. The following figure shows typical operation.

Application Gateway TCP/TLS proxy overview (Preview) (1)

Process flow:

  1. A client initiates a TCP or TLS connection with the application gateway using its frontend listener's IP address and port number. This establishes the frontend connection. Once the connection is established, the client sends a request using the required application layer protocol.
  2. The application gateway establishes a new connection with one of the backend targets from the associated backend pool (forming the backend connection) and sends the client request to that backend server.
  3. The response from the backend server is sent back to the client by the application gateway.
  4. The same frontend TCP connection is used for subsequent requests from the client unless the TCP idle timeout closes that connection.

Comparing Azure Load Balancer with Azure Application Gateway:

ProductType
Azure Load BalancerA pass-through load balancer where a client directly establishes a connection with a backend server selected by the Load Balancer's distribution algorithm.
Azure Application GatewayTerminating load balancer where a client directly establishes a connection with Application Gateway and a separate connection is initiated with a backend server selected by Application Gateway's distribution algorithm.

Features

  • Use a single endpoint (frontend IP) to serve HTTP and non-HTTP workloads. The same application gateway deployment can support Layer 7 and Layer 4 protocols: HTTP(S), TCP, or TLS. All your clients can connect to the same endpoint and access different backend applications.
  • Use a custom domain to front any backend service. With the frontend for the Application Gateway V2 SKU as public and private IP addresses, you can configure any custom domain name to point its IP address using an address (A) record. Additionally, with TLS termination and support for certificates from a private certification authority (CA), you can ensure a secure connection on the domain of your choice.
  • Use a backend server from any location (Azure or On-premises). The backends for the application gateway can be:
    • Azure resources such as IaaS virtual machines, virtual machine scale sets, or PaaS (App Services, Event Hubs, SQL)
    • Remote resources such as on-premises servers accessible via FQDN or IP addresses
  • Supported for a private-only gateway. With TLS and TCP proxy support for private Application Gateway deployments, you can support HTTP and non-HTTP clients in an isolated environment for enhanced security.

Limitations

  • A WAF v2 SKU gateway allows the creation of TLS or TCP listeners and backends to support HTTP and non-HTTP traffic through the same resource. However, it does not inspect traffic on TLS and TCP listeners for exploits and vulnerabilities.
  • The default draining timeout value for backend servers is 30 seconds. At present, a user-defined draining value is not supported.
  • Client IP preservation is currently not supported.
  • Application Gateway Ingress Controller (AGIC) is not supported and works only with L7 proxy through HTTP(S) listeners.

Next steps

Feedback

Was this page helpful?

Application Gateway TCP/TLS proxy overview (Preview) (2024)
Top Articles
9 Ways to Lower Your Cable Bill - NerdWallet
100+ catchy sales slogans and taglines that customers will love
Automated refuse, recycling for most residences; schedule announced | Lehigh Valley Press
Cranes For Sale in United States| IronPlanet
Durr Burger Inflatable
Noaa Charleston Wv
Metallica - Blackened Lyrics Meaning
Tj Nails Victoria Tx
Triumph Speed Twin 2025 e Speed Twin RS, nelle concessionarie da gennaio 2025 - News - Moto.it
Bloxburg Image Ids
Shaniki Hernandez Cam
Visustella Battle Core
True Statement About A Crown Dependency Crossword
A Fashion Lover's Guide To Copenhagen
4156303136
DIN 41612 - FCI - PDF Catalogs | Technical Documentation
Med First James City
Hilo Hi Craigslist
Skyward Login Jennings County
Wicked Local Plymouth Police Log 2022
Craigslist In Visalia California
Georgia Cash 3 Midday-Lottery Results & Winning Numbers
Weve Got You Surrounded Meme
Craigslist Alo
Raw Manga 1000
Accuradio Unblocked
Egusd Lunch Menu
27 Fantastic Things to do in Lynchburg, Virginia - Happy To Be Virginia
Login.castlebranch.com
Log in to your MyChart account
Pay Stub Portal
Earthy Fuel Crossword
Was heißt AMK? » Bedeutung und Herkunft des Ausdrucks
Solve 100000div3= | Microsoft Math Solver
De beste uitvaartdiensten die goede rituele diensten aanbieden voor de laatste rituelen
T&J Agnes Theaters
Agematch Com Member Login
Craigslist Lakeside Az
Craigs List Jonesboro Ar
7543460065
Priscilla 2023 Showtimes Near Consolidated Theatres Ward With Titan Luxe
Oriellys Tooele
A Comprehensive 360 Training Review (2021) — How Good Is It?
Henry Ford’s Greatest Achievements and Inventions - World History Edu
Panorama Charter Portal
Craigslist Antique
Doe mee met ons loyaliteitsprogramma | Victoria Club
Cvs Coit And Alpha
Fredatmcd.read.inkling.com
ESPN's New Standalone Streaming Service Will Be Available Through Disney+ In 2025
Bomgas Cams
Emmi-Sellers
Latest Posts
Article information

Author: Foster Heidenreich CPA

Last Updated:

Views: 5457

Rating: 4.6 / 5 (76 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Foster Heidenreich CPA

Birthday: 1995-01-14

Address: 55021 Usha Garden, North Larisa, DE 19209

Phone: +6812240846623

Job: Corporate Healthcare Strategist

Hobby: Singing, Listening to music, Rafting, LARPing, Gardening, Quilting, Rappelling

Introduction: My name is Foster Heidenreich CPA, I am a delightful, quaint, glorious, quaint, faithful, enchanting, fine person who loves writing and wants to share my knowledge and understanding with you.