You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否使用Azure负载均衡器或应用网关替换本地Cisco负载均衡器?

Absolutely, this is totally feasible! You can replace your on-premises Cisco load balancer with Azure's native load balancing solutions to handle traffic for your DMZ-hosted SFTP and HTTPS sites. Let’s break down your options and key things to keep in mind:

Key Azure Solutions to Choose From

Azure Application Gateway (AG)

This is your go-to for HTTPS sites since it’s a layer 7 (application-level) load balancer. It comes with handy features tailored for web traffic:

  • SSL termination (offloads encryption/decryption work from your DMZ servers to reduce their load)
  • Web Application Firewall (WAF) to shield your sites from common web threats like SQL injection or XSS
  • Path-based routing (if you need to direct traffic to different backend services based on URL paths)
  • Session affinity to maintain user sessions with specific servers

Note: Application Gateway doesn’t natively support SFTP (since it’s built on SSH, a layer 4 protocol), so you’ll need a separate solution for your SFTP traffic.

Azure Load Balancer (ALB)

This is a layer 4 (transport-level) load balancer, perfect for SFTP traffic (which uses TCP port 22). It can also handle HTTPS traffic (TCP port 443), but without the advanced layer 7 features mentioned above. Use ALB if:

  • You just need straightforward traffic distribution for SFTP
  • Your HTTPS sites don’t require layer 7 capabilities like SSL termination or path routing
  • You want a cost-effective, high-performance option for TCP-based services
Critical Connectivity & Configuration Steps

Since your servers are in an on-premises DMZ, you’ll need to ensure Azure can reach them securely:

  • Set up a secure network link: Use either a site-to-site VPN or Azure ExpressRoute to connect your on-premises network to Azure. This is essential—traffic routed through Azure’s load balancers needs a direct, encrypted path to your DMZ servers.
  • Adjust firewall/NAT rules: Make sure your on-premises firewalls and network devices allow incoming traffic from Azure’s load balancer subnets to your DMZ servers. You may need to configure NAT rules to map Azure’s public IPs to your internal DMZ server addresses.
  • Configure health probes: Both AG and ALB use health probes to check if your backend servers are operational. For SFTP, use a TCP probe on port 22; for HTTPS, use an HTTPS probe (or TCP probe on 443) to verify the service is up and running.
Example Deployment Setup

If you’re running both SFTP and HTTPS services, here’s a practical approach:

  • Use Azure Application Gateway for your HTTPS sites: Terminate SSL at the gateway, set up backend pools pointing to your DMZ web servers (via the VPN/ExpressRoute link), and configure routing rules to direct traffic as needed.
  • Use Azure Load Balancer for your SFTP service: Create a public load balancer with a TCP rule for port 22, link it to your SFTP servers in the DMZ, and set up TCP health probes to monitor SSH availability.

In short, Azure’s load balancing tools are more than capable of replacing your Cisco load balancer for your use case—you just need to match the solution to your specific traffic needs and get the network connectivity configured correctly.

内容的提问来源于stack exchange,提问作者Mettlus Shaw

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:21:09