Application Gateway
Azure Application Gateway is a Layer 7 load balancer that routes HTTP/HTTPS traffic based on URL path or host header, terminates TLS, and includes an integrated Web Application Firewall (WAF) to block common exploits like SQL injection and cross-site scripting. It's the Azure equivalent of an AWS ALB, purpose-built for web application traffic rather than raw TCP/UDP.
Application Gateway
Application Gateway understands HTTP — it can route /api/* to one backend pool and /static/* to another, terminate TLS, and block common web attacks via its built-in WAF.
Why It Matters in Production
PhonePe routes traffic through Application Gateway with WAF enabled in Prevention mode, blocking common SQLi and XSS payloads before they ever reach the application backend pool.
az network application-gateway create --resource-group phonepe-prod-rg
--name phonepe-appgw --sku WAF_v2 --capacity 2
--vnet-name phonepe-prod-vnet --subnet appgw-subnet
SecurityAlways enable WAF in "Prevention" mode for production — "Detection" mode only logs attacks without blocking them.
Frequently Asked Questions
How is Application Gateway different from Azure Load Balancer?
Azure Load Balancer operates at Layer 4 (TCP/UDP) — it doesn't understand HTTP, just forwards packets based on IP and port. Application Gateway operates at Layer 7, meaning it can read the actual HTTP request and route based on URL path (/api vs /images) or hostname, terminate SSL centrally, and inspect traffic with its built-in WAF. Use Load Balancer for raw TCP services, Application Gateway for web applications.
What's a common mistake when deploying Application Gateway?
Leaving the WAF in Detection mode instead of Prevention mode in production — Detection only logs suspicious requests without blocking them, so teams think they're protected against SQL injection and XSS when nothing is actually being stopped. Also, WAF rule sets need periodic review; overly strict default rules can generate false positives that block legitimate traffic, so test rule changes in a staging environment first.