Asterrr's Handbook

Load balancers

Choosing between Application, Network and Gateway Load Balancers, and how cross-zone balancing, stickiness, TLS, authentication and static IPs work on each.

Exam tasks: 2.4 (design for reliability and scalability with load balancing), 2.3 (TLS and authentication at the load balancer)

The decision: does the load balancer need to understand HTTP (paths, headers, users), just move TCP or UDP packets fast with fixed IPs, or transparently steer traffic through security appliances?

Choosing a load balancer

Side by side

ALBNLBGWLB
OSI layer743 (network gateway)
ProtocolsHTTP, HTTPS, HTTP/2, gRPC, WebSocketsTCP, UDP, TLS, TCP_UDPIP packets, carried to appliances in GENEVE on port 6081
RoutingHost, path, header, method, query string, source IP rulesPort onlyFlow hash to healthy appliances
Static IPNo. DNS name onlyYes, one per AZ, optionally your Elastic IPsNo
TLSTerminates. SNI for many certificates. Optional mutual TLSTerminates (TLS listener) or passes through (TCP listener)Doesn't touch it
Client source IPIn X-Forwarded-ForPreservedPreserved (transparent)
TargetsInstances, IPs, Lambda functionsInstances, IPs, an ALBAppliance instances or IPs
WAFYesNoNo
AuthenticationCognito or any OIDC providerNoNo
PrivateLink endpoint serviceNoYesYes, as GWLB endpoints
Cross-zone defaultOnOffOff

Exam signal

"Static IPs that customers can allowlist" means NLB (or Global Accelerator). "End-to-end encryption, the load balancer must not decrypt" means an NLB with a TCP listener. "Route /api and /images to different services" means ALB.

Application Load Balancer

  • Listener rules route by host header, path, HTTP header, method, query string or source IP, and can also return fixed responses or redirects (for example HTTP to HTTPS).
  • Weighted target groups in one rule support blue/green and canary releases. See deployment strategies.
  • Authentication: an HTTPS listener rule can authenticate-cognito or authenticate-oidc before forwarding. The ALB handles the login redirect and sends user claims to targets in the x-amzn-oidc-* headers, so the app doesn't need its own login code.
  • Mutual TLS can verify client certificates against a trust store, or pass the certificate to targets.
  • Lambda targets make an ALB a simple HTTP front end for serverless code.

Network Load Balancer

  • Handles millions of requests per second with very low latency, and keeps long-lived TCP connections.
  • One static IP per AZ, or your own Elastic IPs for internet-facing NLBs.
  • Required behind a PrivateLink endpoint service. See VPC connectivity.
  • Supports security groups, which you can reference from the targets' security groups.
  • Preserves the client IP. For IP targets across a proxy, use Proxy Protocol v2 to pass it.

Static IPs in front of HTTP features

An ALB can be the target of an NLB. Clients get fixed NLB IPs, and the ALB still does path routing, WAF and authentication.

Global Accelerator in front of an ALB solves the same problem with two anycast IPs worldwide, and adds multi-Region failover.

Gateway Load Balancer

  • Sends traffic through a fleet of virtual appliances (firewalls, IDS/IPS, deep packet inspection) while staying invisible to source and destination.
  • Traffic is wrapped in GENEVE, so appliances see the original packet. Flows stay on the same appliance (5-tuple or 3-tuple stickiness), which stateful inspection needs.
  • Consumers insert a GWLB endpoint in their route tables (for example on the IGW ingress route table), and the appliances can live in a separate security account.

GWLB versus Network Firewall

If the question requires a specific third-party firewall vendor, use GWLB with the vendor's appliances. If it just needs managed stateful filtering, AWS Network Firewall has less to operate. See DDoS and edge security.

Cross-zone load balancing

With cross-zone on, each load balancer node spreads traffic across healthy targets in all enabled AZs. With it off, each node sends only to targets in its own AZ.

ALBNLBGWLB
DefaultOnOffOff
Where you change itLoad balancer, or override per target groupLoad balancer, or per target groupLoad balancer
Inter-AZ data charge when onNoYesYes

Uneven AZs with cross-zone off

With cross-zone off, an AZ with 2 targets gets the same share of traffic as an AZ with 8, so the 2 targets are overloaded. Enable cross-zone, or keep target counts equal across AZs.

Stickiness

  • ALB duration-based: the ALB sets an AWSALB cookie for a fixed time.
  • ALB application-based: follows a cookie your app sets.
  • NLB: source-IP stickiness at the target group level.
  • Stickiness fights even load distribution and makes scale-in harder. Storing sessions in ElastiCache or DynamoDB is usually the better answer. See caching.
6081
UDP port GWLB uses for GENEVE encapsulation
1 per AZ
Static IPs on an NLB, optionally your own Elastic IPs
Off
Cross-zone default for NLB and GWLB. It is on by default for ALB

Legacy: use Application Load Balancer or Network Load Balancer instead

The Classic Load Balancer is a previous-generation service. If a question includes one, the answer is usually to migrate to an ALB or NLB, for features such as path routing, Lambda targets or static IPs.

Scenarios

Scenario
A payment processor exposes an HTTPS API. Its banking partners can only allowlist fixed IP addresses in their firewalls. The API needs path-based routing to three microservices and protection with AWS WAF. Which solution meets these requirements with the LEAST operational overhead?
Scenario · choose 2
A security team must inspect all inbound internet traffic to 20 application VPCs with a specific third-party next-generation firewall, and the appliances must scale out and fail over automatically. The source IP must reach the applications unchanged. Which TWO components should the architect use?

Further reading

On this page