Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 18: Load Balancing

18.18 Cross-zone load balancing, enabled and disabled

Why the zone of the node matters

Each load balancer node sits in one Availability Zone. Clients are spread across those nodes by DNS. If one zone has 2 instances and the other has 4, "share the work evenly" depends on whether a node may send traffic outside its own zone.

With cross-zone off, a node only sends traffic to healthy targets in its own zone. The zone with fewer instances gives each of them a larger share of that node's traffic. Those few instances can overload while the other zone stays quieter. If one zone has zero healthy targets and cross-zone is off, that zone's node cannot send to the other zone. It fails closed for that node.

With cross-zone on, every node can send traffic to healthy targets in all enabled zones. The 2 and the 4 share one pool. A zone with zero healthy targets can still be served by the other zone's targets.

What is fixed, and what you can switch

On an Application Load Balancer, cross-zone is always on at the balancer. You cannot turn that balancer attribute off. Do not look for a toggle on the internet-facing Application Load Balancer, or on the internal Application Load Balancer in section 18.17. Both already balance across zones. AWS does allow a target group to override this. This lesson does not. Do not turn it off on those groups.

On a Network Load Balancer, cross-zone is off by default at the balancer. You can turn it on for the balancer, or per target group. When we enable it, charges can apply for data transfer that crosses Availability Zones. This lesson does not quote a price. The enable and disable steps below are only for a Network Load Balancer.

How the same six targets behave off and on

Network Load Balancer in ap-south-1, two Availability Zones. These counts are the example we set.

NLB cross-zone DISABLED · 2 vs 4 targets AZ a node NLB node a t1~25% t2~25% only local targets AZ b node NLB node b t312.5% t412.5% t512.5% t612.5% No packets cross the zone boundary when disabled

With cross-zone off on an NLB, the AZ a node only talks to its 2 targets (~25% each of total if DNS splits clients in half). The AZ b node only talks to its 4 (~12.5% each).

Zone Healthy targets
AZ a 2
AZ b 4

Cross-zone disabled:

  1. A request that lands on the AZ a node is split only across the 2 targets in AZ a.
  2. Each of those 2 gets about 50 percent of that node's traffic.
  3. A request that lands on the AZ b node is split only across the 4 targets in AZ b.
  4. Each of those 4 gets about 25 percent of that node's traffic.
  5. If DNS sends roughly half the clients to each node, each AZ a target gets about 25 percent of total traffic (half of the clients, then half of that node's share).
  6. Each AZ b target gets about 12.5 percent of total traffic (half of the clients, then a quarter of that node's share).
  7. The split is uneven: 25 percent against 12.5 percent. The two instances in AZ a work harder.

Cross-zone enabled, same 2 and 4 targets:

NLB cross-zone ENABLED · all 6 share ~16.7% each node a node b One pool · 6 healthy targets t1 16.7% t2 16.7% t3 16.7% t4 16.7% t5 16.7% t6 16.7% ALB cross-zone is always on — this toggle picture is an NLB.

With cross-zone on, both nodes reach all 6 targets. Each target gets about 16.7%. ALB cross-zone is always on; this toggle is an NLB.

  1. All 6 targets are one pool.
  2. Each target gets about 1/6 of the traffic.
  3. 1/6 is about 16.7 percent.
  4. It does not matter which node received the request.
  5. The AZ a targets drop from about 25 percent each to about 16.7 percent each. The AZ b targets rise from about 12.5 percent each to about 16.7 percent each.

Second look at a failure, same balancer.

  1. AZ a has 2 healthy targets. AZ b has 0 healthy targets.
  2. Cross-zone disabled: the AZ b node cannot send to AZ a. Clients that DNS sent to the AZ b node are not served by the other zone.
  3. Cross-zone enabled: the AZ a targets still receive that traffic, including clients that arrived at the AZ b node.
  4. You should see that "enabled" is what keeps a zone with no healthy targets from dropping its clients.
Packets cross zones only when enabled (NLB) node a AZ a AZ a node b b b b b enabled → cross First half: stays in AZ a. Second half (enabled): node a can reach AZ b targets.

Packets stay inside a zone when cross-zone is off. When enabled on an NLB, a node can send across the zone boundary.

How to enable it, and how to turn it off again

Console labels may vary. This is a Network Load Balancer, not the Application Load Balancers from the three-tier picture.

  1. Open Load Balancers.
  2. Select the Network Load Balancer.
  3. Open Attributes.
  4. Find Cross-zone load balancing.
  5. Set it to Enabled. That is the value we choose for the even-share example. The default on a new Network Load Balancer is off. We are changing it.
  6. Save.
  7. You should see the attribute as Enabled.
  8. If one target group must differ, open that target group, open its attributes, and set cross-zone there. The group setting wins for that group.
  9. Disabling is the same control set back to Disabled.

On an ALB, cross-zone is always on. There is no switch. On an NLB, that switch exists. When it is off, each zone sends traffic only to its own servers.