tencent cloud

Application Load Balancer

Creating and Managing a Listener

Download
Focus Mode
Font Size
Last updated: 2026-09-28 16:39:09
AI-Translated & Reviewed
A listener checks connection requests from clients and forwards them to a backend target group based on the forwarding policy you configure. You can add HTTP or HTTPS listeners to an Application Load Balancer (ALB) instance to identify and forward layer-7 requests from clients. HTTP/HTTPS protocols are suitable for applications that require content-based request identification, such as web applications and mobile apps.
This document describes how to create, edit, manage, and delete a listener on an ALB instance.

Prerequisites

An ALB instance has been created. If it is not created, create one by referring to Creating an ALB Instance.
A target group has been created, and backend services have been added to it. If it is not created, create one by referring to Creating and Managing a Target Group. An ALB listener forwards requests to backend services by routing them to a target group. Therefore, prepare a target group before you create a listener.
To create an HTTPS listener, you need to make sure that a server certificate is prepared in Certificate Management. You can select an existing certificate from the SSL Certificates platform or upload a new one.

Creating a Listener

Step 1: Configuring a Listener

1. Log in to the ALB console and choose ALB > Instance Management in the left sidebar.
2. Select a region above the instance list, locate the target instance, and click the instance ID/name to go to the instance details page.
3. Select the Listener Management tab and click Create Listener.
4. Configure the basic parameters as follows:
Configuration Item
Description
Listening Protocol
The protocol used by the listener, supporting HTTP and HTTPS.
Name
The name of the listener, which cannot exceed 255 characters. The system automatically generates a name if this field is left blank.
Listener Port
The port used by the listener to receive and forward requests to the backend. The port range is 1–65535. Within the same ALB instance, listening ports using the same protocol must be unique.
Server Certificate
The server certificate used for HTTPS encrypted communication. ALB uses this certificate to complete the TLS handshake with the client. You can select an existing certificate from the SSL Certificates platform or create and upload a new certificate.
TLS Security Policy
The TLS protocol versions and cipher suites supported by the HTTPS listener, which are used to control the security level of encrypted communication. To customize the protocol versions and cipher suites, you can refer to TLS Security Policies.
Mutual Authentication
It is disabled by default. After you enable it, in addition to server-side verification, the client must also provide a certificate for ALB to complete verification, achieving mutual authentication. This is suitable for scenarios with high security requirements. After you enable it, configure a CA certificate.
HTTP 2.0
It is disabled by default. After you enable it, the listener supports the HTTP/2 protocol, which can improve page loading performance and multiplexing capability.
Tag
You can select a tag key and a tag value or add a tag. For details, see Creating a Tag.
5. Configure advanced options: Click Hide Advanced Options/Show Advanced Options to further configure the following parameters. If no special requirements exist, retain the default values.
Configuration Item
Description
Connection Idle Timeout Period (s)
The maximum duration for which a connection remains idle. If no new request arrives within this duration, the connection is closed. Value range: 1–600. Default value: 15. Unit: Seconds.
Request Timeout Period (s)
The maximum duration for which ALB waits for a backend response. If no response is received within this duration, the request is considered timed out. Value range: 1–600. Default value: 60. Unit: Seconds.
GZIP Compression
After it is enabled, ALB compresses response content using GZIP, which can reduce transmission traffic and improve response speed.
Additional HTTP Header Fields
You can configure the HTTP header fields that ALB adds when forwarding requests to backend services. They are used to pass client and ALB information to the backend. For details, see HTTP Header Field Descriptions below.

HTTP Header Field Descriptions

The client IP address of a visitor is obtained from the X-Forwarded-For header field. The following 3 processing methods are supported (single section):
Additional: Before forwarding a request to a backend service, ALB adds the client IP address to the XFF header field of the last hop.
Delete: ALB deletes the XFF header before forwarding a request to a backend service, regardless of whether the request carries the XFF header field.
Passthrough: ALB keeps the X-Forwarded-For header unchanged and directly passes it through to a backend service without any modifications.
Additionally, you can select the following header fields as needed (multiple selection):
Header Field
Description
X-Forwarded-Proto
Used to obtain the listening protocol (HTTP/HTTPS) of an ALB instance.
X-Forwarded-Port
Used to obtain the listening port of ALB instance.
X-Forwarded-Host
Used to obtain the domain name of a client accessing the ALB instance.
X-Forwarded-Client-srcport
Used to obtain the port of a client accessing the ALB instance.
X-Forwarded-Clientcert-subjectdn
Used to obtain the subject DN of a client certificate accessing the ALB instance. It is supported only by HTTPS listeners.
X-Forwarded-Clientcert-issuerdn
Used to obtain the issuer DN of a client certificate accessing the ALB instance. It is supported only by HTTPS listeners.
X-Forwarded-Clientcert-fingerprint
Used to obtain the fingerprint value of a client certificate accessing the ALB instance. It is supported only by HTTPS listeners.
X-Forwarded-Clientcert-clientverify
Used to obtain the verification result of a client certificate accessing the ALB instance. It is supported only by HTTPS listeners.

Step 2: Configuring a Forwarding Action

The forwarding action configuration items are as follows. After you click Confirm, the default forwarding action of the listener is configured, and the listener management list page is returned.
Configuration Item
Description
Forwarding Action Type
The action to be performed after a listener matches a request. Currently, forwarding to a target group is supported, which means forwarding the request to the backend service within the specified target group.
Select Target Group
The target group to which requests need to be forwarded. If no target group is created, click Create Backend Target Group to create one. The protocol of the target group must match that of the listener.
Target Group Details
After a target group is selected, its ID, name, and associated VPC information are automatically displayed to facilitate verification.

Editing a Listener

1. In the listener management list, locate the target listener.
2. Click the listener ID to go to the listener details page.
3. Click Edit Listener to modify the listener properties and forwarding action.
4. After modification, click Finish.

Managing a Listener

Managing a Tag

1. In the Listener Management list, locate the target listener.
2. In the Operation column of the target listener, choose More > Edit Tag.
3. After modification, click OK.

Managing a Certificate (HTTPS Listeners Only)

1. In the listener management list, locate the target listener.
2. Click Listener ID to go to the listener details, and switch to the Certificate Management tab.
3. On the Certificate Management tab, perform operations such as adding an additional certificate, replacing a certificate, and deleting a certificate.

Modifying an SSL Parsing Mode or TLS Security Policy (HTTPS Listeners Only)

1. In the listener management list, locate the target listener.
2. Click the listener ID to go to the listener details page. In the certificate information section, click the edit icon next to SSL Resolution Method or TLS Security Policy to complete the modification.

Deleting Listeners

1. In the Listener Management list, select one or more listeners to be deleted and click Delete above the list. Alternatively, choose More > Delete in the Operation column of the target listener.
2. Confirm information in the Confirmation dialog box to complete the deletion.
Attention:
After a listener is deleted, the forwarding rules on that listener are also deleted and the related service traffic is no longer forwarded. Please proceed with caution.

Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback