It is Azure Traffic Manager or Azure front Door in-front for multi region system architecture?

Viewed 6293

We have web API application and its related supporting background services hosted on Azure service fabric cluster on 2 different geographical regions (Japan East and West) to over Azure region outage. They are Active-Passive High-Availability clusters.

Expected incoming traffic is only HTTPS.

Traffic will come to our application only from specific country(Japan) not from all over the world.

Is it better to put traffic manager or Azure front door in-front these multi region set up? Which one failover fast during outage? when to choose which one? pros & cons?

Gone through the documents no specific answers for those above questions.

3 Answers

With HTTPS traffic, Azure Front Door is probably your best option in this situation. Not only can it failover fast (depending on configuration), but also provides other features that could benefit you such as TLS termination; caching; path based routing; as well as WAF policies.

This page covers the options, as well as having a decision tree for load balancing options, which although you're looking at options for failover for region outage, is still relevant:

https://docs.microsoft.com/en-us/azure/architecture/guide/technology-choices/load-balancing-overview

enter image description here

Azure Traffic Manager is DNS based. It is mainly for systems that are used across the world to redirect traffic to the nearest service, since all your resources and users are in Japan, it may not be the best fit.

The fail over will depend on the settings. In the example in the link below a probe every 10 seconds with 3 retrys before fail over and a 10 second TTL would give a 40 second failover.

https://docs.microsoft.com/en-us/azure/networking/disaster-recovery-dns-traffic-manager

Azure frontdoor promises "near real-time failover"

https://docs.microsoft.com/en-us/azure/frontdoor/front-door-faq

I found this intersting article which present differences between Front Door and Trafic manager in Azure : https://www.iamashishsharma.com/2020/04/difference-between-azure-front-door.html

Azure Front Door service can be compared to Azure Traffic Manager in a way that this also provides global HTTP load balancing to distribute traffic across different Azure regions, cloud providers or even with your on-premises.

Both AFD & Traffic Manager support:

Multi-geo redundancy: If one region goes down, traffic routes to the closest region without any intervention.

Closest region routing: Traffic is automatically routed to the closest region.

Differences:

Azure Front Door provides TLS protocol termination (SSL offload), and Azure Traffic Manager does not. It means AFDs take load off from the Web Front Ends, which do not have to encrypt or decrypt the request.

Azure Front Door provides application layer processing, and Azure Traffic Manager does not.

While using AFS, user will experience better performance than traffic manager as AFD uses Anycast, which provides lower latency, thereby providing higher performance.

AFD provides WAF feature for your application to provide security from DDoS attacks.

We can perform URL rewriting in Azure Front Door but not in Traffic Manager.

Traffic manager relies on DNS lookup for network routing while AFD uses reverse proxy which provides faster failover support.

AFD caches the static content while no caching mechanism is available in Traffic Manager.

Related