> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# Create a load balancer

> Create an L4 or L7 load balancer on IBEE Solutions — choose a protocol, add backends, set the routing algorithm, and configure health checks.

Create a load balancer from the portal in a few minutes. Choose the layer and protocol, add one or more backends, and set routing and health-check behavior. Optional behaviors — sticky sessions, proxy protocol, automatic retries, and L7 routing rules — are on the same form.

## Before you begin

* A verified IBEE Solutions organization — creation requires identity verification ([Verify your identity](/docs/getting-started/account-setup/verify-account))
* The address and port of at least one backend (a Cloud VM private IP, a hostname, or a service name)

> **Info**
>
> A load balancer cannot be edited after it is created. To change its backends, routing, health checks, or other settings, delete it and create a new one.

## Create a load balancer

### Open Load Balancers

In the portal sidebar, click **Load Balancer** under **Network & Security**, then click **Create Load Balancer**.

### Set the traffic profile

| Field        | Description                                                                                  |
| ------------ | -------------------------------------------------------------------------------------------- |
| **Name**     | Unique per account — e.g. `orders-gateway`                                                   |
| **Layer**    | **Layer 7** for HTTP/HTTPS or **Layer 4** for TCP and TLS passthrough                        |
| **Protocol** | Layer 7: **HTTPS** (default) or **HTTP** · Layer 4: **TCP** (default) or **TLS passthrough** |

### Add backends

Add one row per backend. Click **Add backend** for more.

| Field      | Description                                                                                                                             |
| ---------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| **Type**   | **Service** (default), **IP address**, or **Hostname**. Hostnames must be fully qualified domain names.                                 |
| **Target** | The service name, IP address, or hostname — e.g. `orders-service` or `10.8.0.12`                                                        |
| **Port**   | Backend port, `1`–`65535` (default `8080`)                                                                                              |
| **Weight** | Relative share of traffic, `1`–`1000` (default `100`) — a backend with weight `200` receives twice the traffic of one with weight `100` |

Tick **Encrypt traffic from the load balancer to this backend** if the load balancer should connect to that backend over TLS.

### Configure routing and health

In **Routing and health**, select a **Routing algorithm** — **Round robin** (default), **Least request**, **Random**, or **Consistent hash** — and a **Request timeout** in milliseconds (default `30000`).

Set the **Active health check**:

| Field                      | Default                            |
| -------------------------- | ---------------------------------- |
| **Type**                   | **HTTP** (also **HTTPS**, **TCP**) |
| **Path** (HTTP/HTTPS only) | `/health`                          |
| **Interval (ms)**          | `10000`                            |
| **Timeout (ms)**           | `2000`                             |
| **Healthy threshold**      | `2` consecutive passes             |
| **Unhealthy threshold**    | `3` consecutive failures           |

### Set advanced behavior

* **Sticky sessions** (Layer 7 only) — route requests with the same header value to the same backend. Set the **Sticky header name** (default `X-User-ID`).
* **Proxy protocol** — forward client connection metadata to compatible backends so they see the original client IP.
* **Automatic retries** — retry requests that fail with a `5xx` response, a connection reset, or a connection failure. Set **Attempts** (default `3`) and **Per-retry timeout (ms)** (default `5000`).
* **L7 routing rules** (Layer 7 only) — click **Add rule** for each priority-ordered rule. Each rule has a **Priority**, a **Path prefix** (e.g. `/api`), and an optional **Header name** and **Header value** match. With no rules, all requests use the default `/` route.

### Create

Click **Create Load Balancer**. You are redirected to the load balancer's detail page, which shows its status and public endpoint.

## Detail page

Click a load balancer in the list to open its detail page. The header shows the layer, protocol, and current status. The page has these sections:

| Section              | Contents                                                         |
| -------------------- | ---------------------------------------------------------------- |
| **Overview**         | Name, namespace, load balancer ID, and last-updated time         |
| **Public endpoint**  | Host, listener port, and public URL (with copy and open buttons) |
| **Backends**         | Type, target, port, weight, and TLS for every backend            |
| **L7 routing rules** | Priority, path prefix, and header matches (Layer 7 only)         |

Click **Refresh** to re-poll status. If provisioning fails, a **Provisioning error** message appears on the page.

## Delete a load balancer

On the **Load Balancers** list, click the delete icon on the load balancer's row, then click **Delete** to confirm. Deletion is permanent.

## Troubleshooting

**"Backend port must be between 1 and 65535"**
Each backend needs a valid numeric port.

**Creation blocked with a verification message**
Complete identity verification — the create button is disabled until your organization is verified.

**Status stays in a provisioning state**
Click **Refresh** on the detail page. If a **Provisioning error** appears, delete the load balancer, fix the reported issue, and create it again; otherwise contact support.

**Need to change a setting**
Load balancers cannot be edited in place. Delete the load balancer and create a new one with the updated settings, then point your clients or DNS at the new endpoint.

## Related pages

* [Load balancer overview](/docs/network-security/load-balancer)
* [Algorithms](/docs/network-security/load-balancer/algorithms)
* [SSL and TLS termination](/docs/network-security/load-balancer/ssl-and-tls-termination)
* [Attach VMs as backends](/docs/network-security/load-balancer/attach-vms)