Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Backend health is an Azure Application Gateway report that shows the current status of each backend server. Default and custom health probes continuously monitor the servers in a backend pool, and the gateway sends traffic only to servers that can receive it. This article explains the possible backend health states and how to view the report by using the Azure portal, Azure CLI, REST API, or Azure PowerShell. Use the report to identify unhealthy servers and troubleshoot problems that prevent traffic from reaching your application.
Backend health report
The possible statuses for a server's health report are:
- Healthy - Application Gateway probes receive an expected response code from the backend server.
- Unhealthy - Probes don't receive a response, or the response doesn't match the expected response code or body.
- Unknown - The Application Gateway control plane can't communicate with the application gateway instances, or the fully qualified domain name (FQDN) can't be resolved.
For causes and solutions for the Unhealthy and Unknown states, see Troubleshoot backend health issues in Azure Application Gateway.
Note
The backend health report updates based on the respective probe's refresh interval. Refreshing the page or making a backend health API request doesn't update the report immediately.
Methods to view backend health
You can generate the backend server health report through the Azure portal, REST API, PowerShell, and Azure CLI.
The Application Gateway portal provides a backend health report with visualizations and troubleshooting tools. Each row shows the target server, its backend pool, its backend setting association (including port and protocol), and the response received by the latest probe. To learn how the report is composed based on the number of backend pools, servers, and backend settings, see Application Gateway health probes overview.
For Unhealthy and Unknown statuses, you can also use a Troubleshoot link that provides the following tools:
Azure Network Watcher Connection troubleshoot - To learn how to use this tool, see Manage Connection troubleshoot.
Backend server certificate visualization - The visualization shows the client, the application gateway, and the backend server. The troubleshooting details focus on the Transport Layer Security (TLS) connection between the application gateway and the backend server.
Reading the illustration
- A red connection line between the application gateway and backend server marks a problem with the TLS connection.
- Red certificate-chain lines in the backend server block mark a problem with the certificate components. Labels identify the leaf, intermediate, and root certificates, and an Expected order column shows the correct sequence.
- Red text in the Application Gateway or Backend Server block identifies a problem with the backend settings or server certificate, respectively.
- Use the error location and the provided solution to determine whether to update the application gateway backend setting or the backend server.
Example backend health response
The response identifies each backend address pool and backend settings collection. For each server, the address field identifies the backend target and the health field reports its current status.
The following snippet shows an example of the response:
{
"backendAddressPools": [
{
"backendAddressPool": {
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/resourceGroup/providers/Microsoft.Network/applicationGateways/applicationGateway01/backendAddressPools/appGatewayBackendPool"
},
"backendHttpSettingsCollection": [
{
"backendHttpSettings": {
"id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/resourceGroup/providers/Microsoft.Network/applicationGateways/applicationGateway01/backendHttpSettingsCollection/well-known-ca"
},
"servers": [
{
"address": "www.cloudflare.com",
"health": "Healthy",
"healthProbeLog": "Success. Received 200 status code"
}
]
}
]
}
]
}
Next steps
- Learn about Application Gateway health probes.
- Generate a self-signed certificate with a custom root certificate authority (CA).