A Simple Story to Remember ALB, NLB, and GWLB
Imagine a huge tech campus receiving thousands of visitors every day.
ALB is the receptionist. It asks where each visitor wants to go and sends them to the correct department.
NLB is the express highway. It moves a huge amount of traffic quickly without worrying about what each visitor wants.
GWLB is the security checkpoint. It sends visitors through security and inspection before allowing them to continue.
The easiest way to remember them is:
ALB = Smart Routing
NLB = Fast Traffic
GWLB = Security Traffic
Learn more about aws load balancer deep dive: alb vs nlb vs gwlb.
What is a Load Balancer in AWS?
AWS Elastic Load Balancing distributes incoming traffic across multiple healthy servers or services.
Instead of sending every request to a single server:
Users ↓ Single Server
AWS can distribute the traffic:
Users ↓ Load Balancer ↓ Server 1 Server 2 Server 3
This helps applications improve availability, reliability, and scalability.
Overview of AWS Load Balancers: ALB, NLB, and GWLB
Application Load Balancer — ALB
Think of ALB as a receptionist.
A visitor arrives and says:
“I want to visit the billing department.”
The receptionist understands the request and sends the visitor to the correct place.
ALB works in a similar way.
It operates at Layer 7 and understands HTTP and HTTPS requests. It can route traffic based on details such as the URL path or hostname.
Think of ALB as a receptionist.
A visitor arrives and says:
“I want to visit the billing department.”
The receptionist understands the request and sends the visitor to the correct place.
ALB works in a similar way.
It operates at Layer 7 and understands HTTP and HTTPS requests. It can route traffic based on details such as the URL path or hostname.
Example
User
↓
ALB
├── /products → Product Service
├── /orders → Order Service
└── /users → User Service
User ↓ ALB ├── /products → Product Service ├── /orders → Order Service └── /users → User Service
ALB is commonly used for
- Websites
- REST APIs
- Microservices
- Container applications
- HTTP/HTTPS traffic
- Path-based routing
- Host-based routing
- Websites
- REST APIs
- Microservices
- Container applications
- HTTP/HTTPS traffic
- Path-based routing
- Host-based routing
Host-Based Routing Example
shop.example.com → Shopping Servers
admin.example.com → Admin Servers
Simple rule: Choose ALB when the content of the HTTP request matters.
shop.example.com → Shopping Servers admin.example.com → Admin Servers
Simple rule: Choose ALB when the content of the HTTP request matters.
Network Load Balancer — NLB
Think of NLB as an express highway.
A highway does not ask why each car is travelling. Its main job is to move large amounts of traffic quickly and efficiently.
NLB works in a similar way.
It operates mainly at Layer 4 and handles network connections instead of inspecting application URLs.
Think of NLB as an express highway.
A highway does not ask why each car is travelling. Its main job is to move large amounts of traffic quickly and efficiently.
NLB works in a similar way.
It operates mainly at Layer 4 and handles network connections instead of inspecting application URLs.
Example
Clients
↓
NLB
├── Server 1
├── Server 2
└── Server 3
Clients ↓ NLB ├── Server 1 ├── Server 2 └── Server 3
NLB supports protocols such as
- TCP
- UDP
- TLS
- TCP
- UDP
- TLS
NLB is useful when you need
- High connection volumes
- Low latency
- High network performance
- Static IP addresses
- TCP or UDP traffic
Common examples include gaming platforms, IoT systems, streaming services, and high-performance network applications.
Simple rule: Choose NLB when network performance and connection handling matter more than HTTP-level routing.
- High connection volumes
- Low latency
- High network performance
- Static IP addresses
- TCP or UDP traffic
Common examples include gaming platforms, IoT systems, streaming services, and high-performance network applications.
Simple rule: Choose NLB when network performance and connection handling matter more than HTTP-level routing.
Gateway Load Balancer — GWLB
Think of GWLB as a security checkpoint.
Before visitors enter a secure building, they may need to pass through a security inspection.
GWLB performs a similar role for network traffic.
Think of GWLB as a security checkpoint.
Before visitors enter a secure building, they may need to pass through a security inspection.
GWLB performs a similar role for network traffic.
Example
Internet
↓
GWLB
↓
Security Appliance
↓
Application
Gateway Load Balancer is mainly designed to work with virtual network appliances.
Internet ↓ GWLB ↓ Security Appliance ↓ Application
Gateway Load Balancer is mainly designed to work with virtual network appliances.
Common use cases
- Firewalls
- Intrusion Detection Systems (IDS)
- Intrusion Prevention Systems (IPS)
- Traffic inspection appliances
Imagine a company running several firewall instances.
Instead of sending all network traffic through one firewall, GWLB can distribute the traffic across multiple healthy firewall appliances.
┌── Firewall 1
Traffic → GWLB ─┼── Firewall 2
└── Firewall 3
This helps prevent one security appliance from becoming a bottleneck.
Simple rule: Choose GWLB when traffic needs to pass through firewalls, security systems, or network inspection appliances.
- Firewalls
- Intrusion Detection Systems (IDS)
- Intrusion Prevention Systems (IPS)
- Traffic inspection appliances
Imagine a company running several firewall instances.
Instead of sending all network traffic through one firewall, GWLB can distribute the traffic across multiple healthy firewall appliances.
┌── Firewall 1 Traffic → GWLB ─┼── Firewall 2 └── Firewall 3
This helps prevent one security appliance from becoming a bottleneck.
Simple rule: Choose GWLB when traffic needs to pass through firewalls, security systems, or network inspection appliances.
Execution Boundaries and Integration Points
Each load balancer type enforces different execution boundaries:
- ALB terminates client connections and establishes new connections to targets, enabling advanced routing and SSL offloading.
- NLB preserves the client source IP by forwarding packets without terminating connections, supporting static IPs and high throughput.
- GWLB acts as a transparent gateway, forwarding traffic to virtual appliances without modifying packet headers, enabling seamless integration of third-party security and network functions.
Integration with AWS services varies: ALB tightly integrates with ECS and Lambda for serverless routing, NLB supports IP targets and static IPs for hybrid architectures, and GWLB integrates with virtual appliances deployed in VPCs.
Target Groups and Health Checks
AWS load balancers need to know which backend resources can receive traffic.
These resources are organized into target groups.
ALB ↓ Target Group ├── Server 1 ✓ ├── Server 2 ✕ └── Server 3 ✓
AWS performs health checks on the registered targets.
If Server 2 becomes unhealthy, the load balancer stops sending normal traffic to it and continues routing requests to healthy servers.
This helps keep the application available even when one server has a problem.
Which AWS Load Balancer Should You Choose?
The decision becomes easier when you start with the type of traffic.
Building a website or REST API?
Choose ALB.
Handling TCP, UDP, TLS, or high-performance network traffic?
Choose NLB.
Routing traffic through firewalls or security appliances?
Choose GWLB.
A simple decision flow is:
HTTP / HTTPS? ↓ ALBTCP / UDP / TLS? ↓ NLB
Firewall / Traffic Inspection? ↓ GWLB
A Real-World Example
Imagine an online shopping company.
Its customer-facing website may use ALB:
Customer ↓ ALB ├── /products ├── /cart └── /orders
The company could use NLB for a high-performance internal network service.
It could also use GWLB to route traffic through security firewalls.
This means a large AWS architecture may use ALB, NLB, and GWLB together, because each one solves a different problem.
Summary
AWS ALB, NLB, and GWLB serve distinct roles in cloud architectures. ALB excels at HTTP/HTTPS application routing, NLB at high-performance TCP/UDP load balancing with source IP preservation, and GWLB at transparent network traffic forwarding to virtual appliances. Understanding their internal mechanisms, execution boundaries, and use cases is critical for designing scalable, secure, and cost-effective AWS environments.
Key Takeaways
- ALB operates at Layer 7, ideal for HTTP/HTTPS routing with advanced features.
- NLB operates at Layer 4, optimized for high throughput, low latency TCP/UDP traffic with static IP support.
- GWLB operates at Layer 3, enabling transparent forwarding to third-party virtual appliances.
- Choosing the right load balancer depends on protocol, performance, routing, and security requirements.
- Proper configuration, monitoring, and security controls are essential for reliable load balancer operation.
Frequently Asked Questions
Can I use ALB for TCP traffic?+
No, ALB only supports HTTP, HTTPS, and WebSocket protocols at Layer 7. For TCP or UDP traffic, use NLB.
Does NLB support TLS termination?+
Yes, NLB supports TLS termination and passthrough, but it operates at Layer 4 and does not inspect application data.
What is the main purpose of Gateway Load Balancer?+
GWLB is designed to deploy, scale, and manage third-party virtual appliances by transparently forwarding network traffic at Layer 3.
Can I preserve the client source IP with ALB?+
No, ALB terminates client connections and does not preserve the original source IP. NLB preserves source IP by forwarding packets without termination.
How does GWLB integrate with virtual appliances?+
GWLB uses the GENEVE encapsulation protocol to forward traffic to virtual appliances deployed in your VPC, enabling transparent inspection and processing.