Azure应用网关与Ubuntu虚拟机负载均衡配置技术问询
Hey there! Let's break down exactly how to get your Azure Application Gateway set up to load balance those two Ubuntu VMs—since you already have the core infrastructure in place, we just need to connect the dots properly.
Step-by-Step Configuration Guide
1. Set Up the Backend Pool
First, we need to tell the gateway which VMs to send traffic to:
- Log into the Azure Portal, navigate to your Application Gateway, and go to the Backend Pools tab.
- Click "Add" to create a new pool:
- Name it something descriptive, like
Ubuntu-VM-Backend-Pool. - For "Backend target type", select IP address or FQDN.
- Add the private IPs of your two VMs:
10.1.0.4and10.1.0.5. - You don't need to associate VM NICs here since you're using private IPs directly.
- Save the pool.
- Name it something descriptive, like
2. Configure Health Probes (Critical!)
The gateway needs to know if your VMs are up and running—this is where health probes come in:
- Go to the Health Probes tab in your Application Gateway.
- Click "Add":
- Name it
Ubuntu-Health-Check. - Choose the protocol (HTTP or HTTPS) that matches the service you're running on your VMs (default to HTTP on port 80 if you're testing with something like Nginx).
- Set the path to
/(or a custom health endpoint like/healthzif your service has one). - Set the interval to 30 seconds and unhealthy threshold to 3 (adjust if needed, but this is a safe default).
- Enter the target port your service listens on (e.g., 80).
- Save the probe.
- Name it
3. Set Up Backend HTTP Settings
This defines how the gateway communicates with your backend VMs:
- Navigate to the Backend HTTP Settings tab and click "Add".
- Name it
Ubuntu-HTTP-Config. - Enter the target port matching your service (same as the health probe).
- Select the correct protocol.
- Check the box for Use custom health probe and select the probe you created earlier.
- Keep other default settings and save.
4. Create a Routing Rule (Forward Traffic to Backend)
This ties the frontend public IP to your backend pool:
- Go to the Rules tab and click "Add".
- Choose Basic rule type.
- Name it
Load-Balancing-Rule. - For "Frontend IP configuration", select the one tied to your gateway's public IP (usually
appGatewayFrontendIPby default). - Pick the frontend port (80 for HTTP, 443 for HTTPS).
- Select your backend pool (
Ubuntu-VM-Backend-Pool) and backend HTTP settings (Ubuntu-HTTP-Config). - Save the rule.
5. Prepare Your Ubuntu VMs
Make sure your VMs are ready to receive traffic from the gateway:
- Install and start your target service (e.g., Nginx for testing):
sudo apt update && sudo apt install nginx -y sudo systemctl start nginx && sudo systemctl enable nginx - Update UFW to allow traffic from the gateway's subnet (adjust the CIDR to match your gateway's private IP range):
sudo ufw allow from 10.1.1.0/24 to any port 80 sudo ufw reload - Double-check your Azure Network Security Group (NSG) attached to the VMs: ensure it allows inbound traffic from the Application Gateway's subnet on your service port (80).
6. Verify the Setup
- Visit your Application Gateway's public IP in a browser. Refresh a few times—you should see content from both VMs (customize each VM's Nginx index page to tell them apart, e.g., edit
/var/www/html/index.nginx-debian.htmlto add "VM 1" or "VM 2"). - Back in the Azure Portal, check the Backend Health tab of your gateway—both VMs should show as Healthy.
Common Troubleshooting Tips
- If backend health shows "Unhealthy": Check if your VM service is running, UFW/NSG rules are correct, and the health probe path/port matches your service.
- If traffic isn't forwarding: Verify your routing rule is linked to the correct frontend IP/port and backend settings.
内容的提问来源于stack exchange,提问作者Arty
相关产品推荐
相关产品推荐

