Configuration Item | Description |
Listening Protocol | The protocol used by the listener, supporting HTTP and HTTPS. |
Name | The name of the listener, which cannot exceed 255 characters. The system automatically generates a name if this field is left blank. |
Listener Port | The port used by the listener to receive and forward requests to the backend. The port range is 1–65535. Within the same ALB instance, listening ports using the same protocol must be unique. |
Server Certificate | The server certificate used for HTTPS encrypted communication. ALB uses this certificate to complete the TLS handshake with the client. You can select an existing certificate from the SSL Certificates platform or create and upload a new certificate. |
TLS Security Policy | The TLS protocol versions and cipher suites supported by the HTTPS listener, which are used to control the security level of encrypted communication. To customize the protocol versions and cipher suites, you can refer to TLS Security Policies. |
Mutual Authentication | It is disabled by default. After you enable it, in addition to server-side verification, the client must also provide a certificate for ALB to complete verification, achieving mutual authentication. This is suitable for scenarios with high security requirements. After you enable it, configure a CA certificate. |
HTTP 2.0 | It is disabled by default. After you enable it, the listener supports the HTTP/2 protocol, which can improve page loading performance and multiplexing capability. |
Tag |
Configuration Item | Description |
Connection Idle Timeout Period (s) | The maximum duration for which a connection remains idle. If no new request arrives within this duration, the connection is closed. Value range: 1–600. Default value: 15. Unit: Seconds. |
Request Timeout Period (s) | The maximum duration for which ALB waits for a backend response. If no response is received within this duration, the request is considered timed out. Value range: 1–600. Default value: 60. Unit: Seconds. |
GZIP Compression | After it is enabled, ALB compresses response content using GZIP, which can reduce transmission traffic and improve response speed. |
Additional HTTP Header Fields | You can configure the HTTP header fields that ALB adds when forwarding requests to backend services. They are used to pass client and ALB information to the backend. For details, see HTTP Header Field Descriptions below. |
Header Field | Description |
X-Forwarded-Proto | Used to obtain the listening protocol (HTTP/HTTPS) of an ALB instance. |
X-Forwarded-Port | Used to obtain the listening port of ALB instance. |
X-Forwarded-Host | Used to obtain the domain name of a client accessing the ALB instance. |
X-Forwarded-Client-srcport | Used to obtain the port of a client accessing the ALB instance. |
X-Forwarded-Clientcert-subjectdn | Used to obtain the subject DN of a client certificate accessing the ALB instance. It is supported only by HTTPS listeners. |
X-Forwarded-Clientcert-issuerdn | Used to obtain the issuer DN of a client certificate accessing the ALB instance. It is supported only by HTTPS listeners. |
X-Forwarded-Clientcert-fingerprint | Used to obtain the fingerprint value of a client certificate accessing the ALB instance. It is supported only by HTTPS listeners. |
X-Forwarded-Clientcert-clientverify | Used to obtain the verification result of a client certificate accessing the ALB instance. It is supported only by HTTPS listeners. |
Configuration Item | Description |
Forwarding Action Type | The action to be performed after a listener matches a request. Currently, forwarding to a target group is supported, which means forwarding the request to the backend service within the specified target group. |
Select Target Group | The target group to which requests need to be forwarded. If no target group is created, click Create Backend Target Group to create one. The protocol of the target group must match that of the listener. |
Target Group Details | After a target group is selected, its ID, name, and associated VPC information are automatically displayed to facilitate verification. |
Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback