This publish was co-authored by Dave Burkhardt and Sami Modak.
As a part of your cloud journey, crucial purposes should be deployed in a number of Azure areas to make sure excessive availability on your world buyer base. When reviewing Azure’s numerous world site visitors distribution options, ask your self, “Which choice is the perfect one for my software?”
On this weblog, you’ll study every world site visitors distribution answer Azure affords, and which answer is the perfect one on your internet-facing cloud structure. At present, Azure affords totally different choices for distributing world site visitors. Microsoft Azure Entrance Door is a content material supply community (CDN) service with software layer load balancing capabilities. Azure cross-region Load Balancer is a world community layer load balancer. Lastly, Azure Site visitors Supervisor is a site title service (DNS)-based site visitors distribution answer.
Selecting the best world site visitors distribution answer
You’ll study three instance corporations—Contoso1, Contoso2, and Contoso3. For every firm, we’ll dive into their software’s situation and resolve which world site visitors distribution answer is the perfect one for them.
Buyer situation 1—wholesale distributor
Contoso1 is a big wholesale distributor that has areas all around the globe. Contoso1 has been going by way of a big technological transformation and has been migrating providers to Azure. One of many purposes being moved to Azure is their backend stock administration software program. This software is answerable for offering customers with details about stock standing and updating stock information after a transaction has occurred. As a part of their migration the staff at Contoso1 has strict necessities that should be met by a world distribution answer.
- First, all site visitors sort can be layer 4 and have to be served with ultra-low latency. As well as, the appliance requires a regional redundancy with automated site visitors fail-over within the occasion a area is down, to make sure excessive availability.
- Second, the appliance requires a static IP handle that the appliance’s frontend will persistently ping.
- Lastly, any updates made to regional deployments shouldn’t have an effect on the general backend stock software.
Given all the necessities laid out by Contoso1’s, Azure cross-region Load Balancer is an ideal answer for his or her software. Azure cross-region Load Balancer is extremely optimized at serving layer-4 site visitors with ultra-low latency. Moreover, cross-region load balancer supplies geo-proximity routing, which implies all Contoso1’s shops site visitors can be forwarded to the closest regional deployment to them. Azure cross-region Load Balancer additionally supplies automated failover. Within the occasion one among Contoso1’s regional deployment is unhealthy, all site visitors can be serviced by the subsequent wholesome regional deployment. As well as, cross-region load balancers present customers with a static globally anycast IP handle, by which Contoso1 doesn’t have to fret about their IP handle altering. Lastly, Azure cross-region Load Balancer will permit Contoso1 to replace its regional deployments behind a single world endpoint with none influence on its finish customers.

Buyer situation 2—social media firm
Contoso2 is a world social media platform. As a social media web site, they should serve each interactive and static content material to their customers across the globe as rapidly and reliably as potential. Most lately, as a consequence of Contoso2’s distinguished standing as a social media platform, they’ve skilled an outage with their on-premises hosted web site due to a DDoS assault. That stated, Contoso2 has the next strict necessities as they migrate to Azure:
- A platform that may ship each static and dynamic content material to their customers across the globe with the utmost efficiency and reliability.
- Capability to route content material to each their cell and desktop customers as rapidly as potential.
- Simply combine with Azure’s DNS, Net Utility, Storage, and Utility Gateway merchandise.
- DDoS safety.
- Cut back safe sockets layer (SSL) load on Contoso2’s software servers, and as a substitute course of SSL requests on the sting for quicker consumer expertise for Contoso2’s world shoppers.
Azure Entrance Door is a perfect answer to allow accelerated and extremely resilient internet software efficiency for optimum supply of static and dynamic content material across the globe:
- Static Content material—Contoso2’s cached static content material will be served from Azure Entrance Door’s 185 world edge factors of presence (PoP) areas. To make sure the utmost efficiency and resiliency, Azure Entrance Door makes use of the Anycast protocol to verify the Contoso2’s shopper’s requests are served from the closest world edge areas.
- Dynamic Content material—Azure Entrance Door has an arsenal of site visitors acceleration options. Shopper to Azure Entrance Door PoP site visitors is once more optimized through the Anycast protocol. Though because it particularly pertains to dynamic workloads, edge PoP to buyer’s origin connections are optimized through break up TCP. This method allows the site visitors to terminate the TCP connection to the closest edge PoP and makes use of lengthy residing connections over Microsoft’s world non-public broad space community (WAN) to scale back the round-trip-time (RTT). Moreover, within the occasion Cotoso2 deployed multiregional origin deployments, Azure Entrance Door makes use of well being probes to fetch content material from the least latent origin.
Furthermore, Azure Entrance Door additionally has SSL offload capabilities which may enhance efficiency additional. As well as, Azure Entrance Door is extremely optimized for HTTP and web-based purposes. With Azure Entrance Door, clients are geared up with numerous layer 7 routing options. These options permit clients to use enterprise routing and superior routing inside Azure Entrance Door. For instance, Azure Entrance Door can route requests to cell or desktop variations of Contoso2’s internet software primarily based on the shopper system sort. Further examples embody SSL offload, path-based routing, quick failover, caching, and extra.
At this time Azure supplies end-to-end options for each facet of software administration. Azure Entrance Door supplies seamless integration with different Azure providers resembling DNS, Net App, and Storage. These integrations permit clients to simply create highly effective internet purposes constructed utilizing the mixing of a number of Azure providers.
Lastly, Azure Entrance Door supplies built-in assist for numerous safety merchandise to assist defend clients’ internet purposes. For instance, clients can safe their origins with layer 3, 4, and seven DDOS mitigation, and seamlessly allow Azure Net Utility Firewall safety.

Buyer situation 3—sustainable style retailor
Contoso3 is a big retail retailer targeted on sustainable style objects. Contoso3 has a big on-line presence and has traditionally been internet hosting all their purposes on-premises. Nonetheless, given the benefit of the cloud and Azure, Contoso3 has begun migrating their purposes to Azure. Certainly one of these purposes is their on-line retailer platform. Because the staff at Contoso3 is evaluating totally different Azure world site visitors distribution options, they’ve outlined a number of necessities that have to be addressed.
- First, the staff at Contoso3 can be doing a rolling migration the place a part of their software will stay on-premises and the opposite half can be hosted on Azure. Any viable answer ought to have the ability to direct site visitors to on-premises servers to assist this rolling migration plan.
- Second, latency is crucial for Contoso3 and shopper site visitors must be routed to wholesome endpoints in a well timed method.
- Lastly, the answer wants to have the ability to direct customers to the right backend sort primarily based on their geographical location. Contoso3 caters to a variety of consumers and sometimes has clothes objects particular to sure geographical areas.
With all the necessities acknowledged prior, Azure Site visitors Supervisor can be the optimum answer for Contoso3. With Azure Site visitors Supervisor, customers can add on-premises servers within the backend to assist burst-to-cloud, failover-to-cloud, and migrate-to-cloud eventualities. As well as, Azure Site visitors Supervisor supplies automated failover and multi-region assist, which all end in site visitors being served with low latency. DNS title decision is quick, and outcomes are cached. The pace of the preliminary DNS lookup depends upon the DNS servers the shopper makes use of for title decision. Sometimes, a shopper can full a DNS lookup inside roughly 50 ms. The outcomes of the lookup are cached at some point of the DNS time-to-live (TTL). The default TTL for Site visitors Supervisor is 300 seconds (about 5 minutes). The Site visitors Supervisor may also assist Contoso3 with their geofencing wants, particularly with the geographic routing function. This function will permit Contoso3 to direct customers to the right backend occasion primarily based on their geographical location.

Abstract
The next part discusses frequent use instances for every load balancing answer, and what every answer is optimized for.
Azure Entrance Door | Azure cross-region Load Balancer | Azure Site visitors Supervisor | |
Site visitors sort | HTTP/HTTPS | TCP/UDP | DNS |
Routing insurance policies | Latency, precedence, spherical robin, weighted spherical robin, path-based, superior http guidelines engine | Geo-proximity and Hash Based mostly | Geographical, latency, weighted, precedence, subnet, multi-value |
Supported environments. | Azure, non-Azure cloud, on-premises | Azure | Azure, non-Azure cloud, on-premises |
Backend Sorts | Azure Utility Gateway, Azure Load balancer, Azure Site visitors Manger | Azure Load Balancer | Azure Utility Gateway, Azure Load balancer, Azure Site visitors Supervisor, Azure Entrance Door, Azure Cross Area Load Balancer |
Session affinity | X | X | NA |
Web site acceleration | X | NA | NA |
Caching | X | NA | NA |
Static IP | NA | X | NA |
Safety | DDOS, Net Utility Firewall, Non-public Hyperlink | Community Safety Group | Azure Useful resource Logs, Azure Insurance policies |
SLA | 99.99% | 99.99% | 99.99% |
Pricing | Pricing | Pricing | Pricing |
Be taught extra
To be taught extra concerning the merchandise mentioned within the weblog please go to the next websites: