Load balancers
Choosing between Application, Network and Gateway Load Balancers, and how cross-zone balancing, stickiness, TLS, authentication and static IPs work on each.
Exam tasks: 2.4 (design for reliability and scalability with load balancing), 2.3 (TLS and authentication at the load balancer)
The decision: does the load balancer need to understand HTTP (paths, headers, users), just move TCP or UDP packets fast with fixed IPs, or transparently steer traffic through security appliances?
Choosing a load balancer
Side by side
| ALB | NLB | GWLB | |
|---|---|---|---|
| OSI layer | 7 | 4 | 3 (network gateway) |
| Protocols | HTTP, HTTPS, HTTP/2, gRPC, WebSockets | TCP, UDP, TLS, TCP_UDP | IP packets, carried to appliances in GENEVE on port 6081 |
| Routing | Host, path, header, method, query string, source IP rules | Port only | Flow hash to healthy appliances |
| Static IP | No. DNS name only | Yes, one per AZ, optionally your Elastic IPs | No |
| TLS | Terminates. SNI for many certificates. Optional mutual TLS | Terminates (TLS listener) or passes through (TCP listener) | Doesn't touch it |
| Client source IP | In X-Forwarded-For | Preserved | Preserved (transparent) |
| Targets | Instances, IPs, Lambda functions | Instances, IPs, an ALB | Appliance instances or IPs |
| WAF | Yes | No | No |
| Authentication | Cognito or any OIDC provider | No | No |
| PrivateLink endpoint service | No | Yes | Yes, as GWLB endpoints |
| Cross-zone default | On | Off | Off |
Exam signal
"Static IPs that customers can allowlist" means NLB (or Global Accelerator). "End-to-end encryption, the load
balancer must not decrypt" means an NLB with a TCP listener. "Route /api and /images to different services"
means ALB.
Application Load Balancer
- Listener rules route by host header, path, HTTP header, method, query string or source IP, and can also return fixed responses or redirects (for example HTTP to HTTPS).
- Weighted target groups in one rule support blue/green and canary releases. See deployment strategies.
- Authentication: an HTTPS listener rule can
authenticate-cognitoorauthenticate-oidcbefore forwarding. The ALB handles the login redirect and sends user claims to targets in thex-amzn-oidc-*headers, so the app doesn't need its own login code. - Mutual TLS can verify client certificates against a trust store, or pass the certificate to targets.
- Lambda targets make an ALB a simple HTTP front end for serverless code.
Network Load Balancer
- Handles millions of requests per second with very low latency, and keeps long-lived TCP connections.
- One static IP per AZ, or your own Elastic IPs for internet-facing NLBs.
- Required behind a PrivateLink endpoint service. See VPC connectivity.
- Supports security groups, which you can reference from the targets' security groups.
- Preserves the client IP. For IP targets across a proxy, use Proxy Protocol v2 to pass it.
Static IPs in front of HTTP features
An ALB can be the target of an NLB. Clients get fixed NLB IPs, and the ALB still does path routing, WAF and authentication.
Global Accelerator in front of an ALB solves the same problem with two anycast IPs worldwide, and adds multi-Region failover.
Gateway Load Balancer
- Sends traffic through a fleet of virtual appliances (firewalls, IDS/IPS, deep packet inspection) while staying invisible to source and destination.
- Traffic is wrapped in GENEVE, so appliances see the original packet. Flows stay on the same appliance (5-tuple or 3-tuple stickiness), which stateful inspection needs.
- Consumers insert a GWLB endpoint in their route tables (for example on the IGW ingress route table), and the appliances can live in a separate security account.
GWLB versus Network Firewall
If the question requires a specific third-party firewall vendor, use GWLB with the vendor's appliances. If it just needs managed stateful filtering, AWS Network Firewall has less to operate. See DDoS and edge security.
Cross-zone load balancing
With cross-zone on, each load balancer node spreads traffic across healthy targets in all enabled AZs. With it off, each node sends only to targets in its own AZ.
| ALB | NLB | GWLB | |
|---|---|---|---|
| Default | On | Off | Off |
| Where you change it | Load balancer, or override per target group | Load balancer, or per target group | Load balancer |
| Inter-AZ data charge when on | No | Yes | Yes |
Uneven AZs with cross-zone off
With cross-zone off, an AZ with 2 targets gets the same share of traffic as an AZ with 8, so the 2 targets are overloaded. Enable cross-zone, or keep target counts equal across AZs.
Stickiness
- ALB duration-based: the ALB sets an
AWSALBcookie for a fixed time. - ALB application-based: follows a cookie your app sets.
- NLB: source-IP stickiness at the target group level.
- Stickiness fights even load distribution and makes scale-in harder. Storing sessions in ElastiCache or DynamoDB is usually the better answer. See caching.
Legacy: use Application Load Balancer or Network Load Balancer instead
The Classic Load Balancer is a previous-generation service. If a question includes one, the answer is usually to migrate to an ALB or NLB, for features such as path routing, Lambda targets or static IPs.
Scenarios
An NLB gives fixed IPs, and an ALB as its target keeps path routing and WAF. You can't assign Elastic IPs to an ALB, and WAF doesn't attach to an NLB, which also can't route by path. Self-managed NGINX works but adds the most operational overhead.
GWLB distributes flows across the vendor appliances with GENEVE, keeps packets unchanged, and handles appliance health. GWLB endpoints in each VPC steer traffic to it through route tables. An ALB or NLB would terminate or rewrite connections and isn't transparent, and Network Firewall doesn't meet the specific vendor requirement.
Further reading
Route 53 routing
Route 53 routing policies, health checks, alias records, nested record trees for high availability, and DNSSEC signing.
Decoupling with queues, topics and events
When to use SQS, SNS, EventBridge, Step Functions, Kinesis Data Streams, Amazon MQ or MSK to break a system into independent parts.