Application Load Balancer (ALB) is available in the following editions:
Basic: Provides basic application load balancing capabilities and supports forwarding based on domain names, URLs, and HTTP headers.
Standard: In addition to the Basic edition features, the Standard edition offers more capabilities with comprehensive enhancements in forwarding, security, monitoring, and connection management.
WAF-Enabled: In addition to the Standard edition features, the WAF-Enabled edition integrates Web Application Firewall (WAF 3.0) to provide application-layer security protection for web services.
The instance performance metrics of ALB are independent of the edition.
Upgraded ALB instances support traffic management through security groups or access control lists (ACLs), while instances before upgrade only support ACLs. To use security groups, create a new instance or contact your account manager to upgrade existing instance.
Feature | Basic | Standard | WAF-Enabled |
Listener protocols | |||
QUIC | |||
HTTP/2 | |||
HTTP/3 | |||
WebSocket | |||
Forwarding rules | |||
Host- or path-based routing | |||
HTTP header-based routing | |||
Query string-based routing | |||
Cookie-based routing | |||
HTTP method-based routing | |||
Source IP-based routing | |||
Response status code-based routing | |||
Response header-based routing | |||
Forward to | |||
Redirect | |||
Rewrite or return fixed response | |||
Add or remove headers | |||
Traffic mirroring | |||
QPS throttling | |||
CORS | |||
AScript | |||
Server group types | |||
Server, IP, and Function Compute types | |||
Security | |||
Access control allowlist/denylist | |||
Security groups | |||
TLS cipher suites | |||
SNI multi-certificate support | |||
RSA and ECC dual certificates | |||
ECC certificates | |||
End-to-end HTTPS | |||
Mutual TLS (mTLS) | |||
Custom TLS security policy | |||
TLS 1.3 | |||
Monitoring and statistics | |||
Access logs | |||
Basic monitoring metrics | |||
Tracing analysis | |||
Advanced features | |||
Retrieve real client source IP | |||
Web Application Firewall (WAF) | (can upgrade to WAF-Enabled) | (can upgrade to WAF-Enabled) | |
Global Accelerator (GA) | |||
Session persistence | |||
Backend persistent connections | |||
Instance cloning | |||
Slow start | |||
Connection draining | |||
Disable cross-zone load balancing | |||