One front door. Every server behind it. Balanced in milliseconds.
QCloud Elastic Load Balancer (ELB) automatically distributes incoming traffic across multiple servers — Layer-4 for raw throughput, Layer-7 for HTTP content routing — with SSL offloading, sticky sessions, and sub-second failover. Hosted inside KHI-1 and ISB-1. Billed by the hour.
Production telemetry · KHI-1 + ISB-1 · 12-month rolling window
One overloaded server is one outage away. ELB is the difference.
Without a load balancer, every request hits the same server until it cracks. With QCloud ELB, traffic flows across a pool of healthy servers — automatically, intelligently, and without changing a single line of your application.
Without a load balancer
- ✕ One slow request blocks all others
- ✕ Hardware failure = total outage
- ✕ Scaling means manual DNS surgery
With QCloud ELB
- ✓ Slow requests routed away from busy nodes
- ✓ Failed servers automatically removed from rotation
- ✓ Scale horizontally without touching DNS
Pick the load balancer that fits your traffic.
Three load-balancer shapes on one elastic platform — switch between them online, no detach, no downtime.
Smart routing for modern web apps.
Routes requests by URL path, host, header, cookie, or query parameter. Native WebSocket and HTTP/2 support. Ideal for microservices and container workloads.
- ✓Path-based and host-based routing rules
- ✓SSL/TLS termination with cipher policy control
- ✓Sticky sessions via cookies
- ✓Native WebSocket & HTTP/2 support
Extreme throughput, ultra-low latency.
Operates at the connection level for raw TCP/UDP traffic. Static IP per zone, millions of connections per second, sub-100µs added latency. Ideal for gaming, real-time, and database front-ends.
- ✓Millions of concurrent connections per node
- ✓Static IP per availability zone (Elastic-IP ready)
- ✓TLS passthrough or termination
- ✓Long-lived connections (WebSocket, gRPC, MQTT)
Insert security appliances into the traffic path — invisibly.
A transparent network gateway that lets you scale third-party firewalls, IDS/IPS, and packet inspection appliances inline. Perfect for sovereign-cloud security pipelines and Zero-Trust architectures.
- ✓Bump-in-the-wire transparent routing
- ✓Scale virtual security appliances horizontally
- ✓Health-check across appliance fleet
- ✓Integrates with QCloud WAF and Firewall services
Why teams pick QCloud ELB — over building their own.
Every promise is built into the default. No checkbox. No extra SKU. No upcharge.
Enhanced Performance
Handles millions of concurrent connections per node. Auto-scales without warming.
Highly Available
Multi-AZ by default. Health checks every 15s. Auto-failover in under a second.
Easy to Configure
Console, REST API, or Terraform. Six load-balancing algorithms, one-click switch.
Intelligent Routing
Deeply integrated with Auto Scaling, ECS, KCS, EVS. Detects unhealthy backends instantly.
SSL Offloading + WAF
Terminate TLS at the load balancer, integrate with WAF for OWASP Top-10 protection.
Sovereign Networking
Every packet, every route, every replication hop stays inside Pakistan.
Enhanced Performance
Handles millions of concurrent connections per node. Auto-scales without warming.
Highly Available
Multi-AZ by default. Health checks every 15s. Auto-failover in under a second.
Easy to Configure
Console, REST API, or Terraform. Six load-balancing algorithms, one-click switch.
Intelligent Routing
Deeply integrated with Auto Scaling, ECS, KCS, EVS. Detects unhealthy backends instantly.
SSL Offloading + WAF
Terminate TLS at the load balancer, integrate with WAF for OWASP Top-10 protection.
Sovereign Networking
Every packet, every route, every replication hop stays inside Pakistan.
All six on by default · no opt-in checkboxes · no extra cost
Six algorithms. Pick the one that fits your traffic shape.
Switch between algorithms with one click. Change them again next week. ELB applies the new policy without dropping a connection.
One backend dies. Your users never know.
ELB pings every backend every 15 seconds. The moment a node fails 3 consecutive checks, it's removed from rotation. Existing connections drain gracefully. New traffic routes to healthy nodes. Total customer-visible impact: zero.
Configurable: HTTP / HTTPS / TCP / gRPC health probes · interval 5s–300s · success/failure thresholds 2–10 · DPD-style fast failover available
Six patterns we ship every month — for the workloads that move Pakistan.
- ▸Core banking front-ends balanced across multi-AZ ECS pools
- ▸Sticky sessions for payment flows · TLS termination · WAF integration
- ▸SBP-compliant data residency — every byte stays in-country
- ▸4 of Pakistan's top 12 banks live
- ▸Customer portals scaled elastically through peak hours
- ▸IVR SIP traffic routed via NLB for ultra-low latency
- ▸Multi-region tunnels balanced for active-active resilience
- ▸3 national telcos · 14 active ELB pairs
- ▸Storefront frontends auto-scaled during sale events
- ▸Sticky sessions for cart and checkout flows
- ▸WAF integration for OWASP Top-10 + bot management
- ▸Pre-scale 30 minutes before Black Friday / Eid sale
- ▸Video origin servers balanced via NLB for raw throughput
- ▸Match-day cricket / election-night traffic absorbed in seconds
- ▸Long-lived TCP connections optimised
- ▸12 streaming platforms in production
- ▸Federal portals balanced inside fully sovereign VPCs
- ▸100% in-country traffic — zero offshore hop
- ▸Air-gapped option for sensitive workloads
- ▸7 federal agencies onboarded
- ▸Per-tenant routing via host-based ALB rules
- ▸Quota-bound throughput per tenant
- ▸One ELB pair, hundreds of customer namespaces
- ▸30+ Pakistani SaaS vendors in production
Four security layers. One load balancer. Zero certificate management headaches.
Terminate TLS at the load balancer, inspect every request, and forward only clean traffic to your backends. Your application doesn't even need to know HTTPS exists.
DDoS Scrubbing
Volumetric DDoS attacks absorbed at the network edge. No charge, no setup. Enhanced anti-DDoS available on request for Tbps-class mitigation.
Health + Routing
Every backend probed every 15 seconds. Unhealthy nodes drained gracefully. Six load-balancing algorithms to pick from.
WAF Integration
Native one-click integration with QCloud Web Application Firewall. Blocks SQLi, XSS, RCE, and bot traffic before it touches your servers.
TLS Termination
Offload the CPU-intensive work of encryption/decryption to the load balancer. HSM-backed certificate custody. Configurable cipher policy. ACME / Let's Encrypt support.
Two regions. One country. Active-active balanced.
Distribute traffic across QCloud's two Pakistani regions — Karachi (KHI-1) and Islamabad (ISB-1) — automatically. If one region degrades, the other absorbs the entire load in under 30 seconds.
GSLB · DNS-based weighted routing · failover in < 30s · zero customer-side DNS changes required
Cheaper. Closer. In-country. No FX risk.
Most teams cut their load-balancing spend 30–50% in the first quarter by eliminating FX exposure and per-LCU data charges.
Transparent prices, without surprises.
No hidden charges. No billing surprises. Choose the model that fits your business — pay as you go for full flexibility, or commit to a saving plan for lower rates.
- ▸Pay only for resources consumed
- ▸No upfront commitment required
- ▸Scale up or down at any time
- ▸Billed hourly · no hidden fees
- ▸No FX exposure · no hidden fees
- ▸Significant savings vs. on-demand
- ▸1-year or 3-year commitment options
- ▸No upfront, partial, or full prepayment
- ▸Customised to your traffic profile
- ▸Named account manager included
- ▸Dedicated load-balancer fleet
- ▸Air-gapped option · BYO cert
- ▸Custom SLAs · named TAM
- ▸Volume-based pricing
- ▸24/7 in-country support
QCloud ELB pricing is transparent and flexible. Whether you're a startup or an enterprise, our team will help you find the right plan — no hidden charges, no currency surprises.
All ELB plans include: 99.999% SLA · Health checks · SSL termination · 🇵🇰 100% in-country data residency · No hidden charges
Five steps. Under five minutes. Three commands.
Create the listener
Pick L4 or L7, region (KHI-1 / ISB-1 / both), and listening port. ELB is provisioned in under 60 seconds.
$ qcloud elb create \
--name elb-prod-01 \
--type application \
--region khi-1,isb-1
✓ elb-prod-01 created · 0.4s
Register backends
Add your ECS instances, container services, or IP targets. ELB starts probing them immediately.
$ qcloud elb target-group add \
--backends ecs-web-01,ecs-web-02,ecs-web-03
✓ 3 backends registered · all healthy
Pick an algorithm
Round Robin, Least Connections, IP Hash, Weighted, Least Response Time, or Consistent Hashing.
$ qcloud elb policy set \
--algorithm least-connections \
--sticky cookie-based
✓ policy applied · effective immediately
Attach TLS + WAF
Upload your certificate (or use ACME), enable WAF for OWASP protection. One click.
$ qcloud elb tls attach --cert prod-cert.pem $ qcloud elb waf enable --rules owasp-top-10 ✓ TLS termination active · WAF enabled
Point DNS at the ELB
Use the ELB's static IP or DNS name. Traffic starts flowing.
$ dig api.your-domain.pk api.your-domain.pk. 60 IN A 203.135.12.42 ← your ELB
Median provisioning time across all customers: 3m 22s · Last 30 days · KHI-1 + ISB-1
ELB is the front door. Everything else plugs in.
Once your ELB is provisioned, every other QCloud service can attach to it — by default, zero extra config.
Plus — Terraform provider · REST API · Helm chart · GitHub Actions runner integration · Prometheus metrics
Everything you wanted to know — before you point your DNS.
Provision your first load balancer — on the house.
$100 in QCloud credit. A 1-month free trial of ELB, ECS, and VPC. A real load-balancing architect on the call from day one. Migration support for teams moving off AWS, Azure, self-managed HAProxy, or on-prem F5 / Citrix — all included.