The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect NLB feature | Get-WindowsFeature NLB,RSAT-NLB | View examples |
| Inspect network adapters | Get-NetAdapter |
Select-Object Name,InterfaceDescription,Status,MacAddress,LinkSpeed | View examples |
| List NLB clusters | Get-NlbCluster | View examples |
| List cluster nodes | Get-NlbClusterNode -HostName NLB01 | View examples |
| List port rules | Get-NlbClusterPortRule -HostName NLB01 | View examples |
| Create cluster | New-NlbCluster -InterfaceName 'Ethernet' `
-ClusterPrimaryIP 192.0.2.20 -ClusterName `
web.contoso.example -OperationMode Multicast | View examples |
| Add node | Add-NlbClusterNode -NewNodeName NLB02 -NewNodeInterface `
'Ethernet' -InterfaceName 'Ethernet' -HostName NLB01 | View examples |
| Add balanced HTTPS rule | Add-NlbClusterPortRule -InterfaceName 'Ethernet' `
-StartPort 443 -EndPort 443 -Protocol TCP -Affinity `
Single | View examples |
| Set node load weight | Get-NlbClusterPortRule -HostName NLB01 -StartPort 443 |
Set-NlbClusterPortRuleNodeWeight -LoadWeight 50 | View examples |
| Drain node traffic | Stop-NlbClusterNode -HostName NLB01 -Drain | View examples |
| Resume node traffic | Start-NlbClusterNode -HostName NLB01 | View examples |
| Suspend NLB control | Suspend-NlbClusterNode -HostName NLB01 | View examples |
| Read node operational state | Get-NlbClusterNode -HostName NLB01 |
Select-Object HostName,State,Status,Priority | View examples |
| Test application endpoint | Test-NetConnection web.contoso.example -Port 443 | View examples |
| Read NLB events | Get-WinEvent -ProviderName Microsoft-Windows-NLB `
-MaxEvents 100 | View examples |
| Remove a drained node | Remove-NlbClusterNode -HostName NLB02 | View examples |
Windows Network Load Balancing distributes TCP or UDP traffic among Windows Server hosts sharing virtual IP addresses. It does not inspect application health, synchronize content, provide a stateful proxy, or replace a firewall. Stable deployments require compatible network design, identical applications and certificates, external health monitoring, deliberate affinity, port-rule parity, DNS planning, and a tested drain procedure. For SDN, non-Windows, NAT, Layer 3, or richer health-routing needs, use an appropriate load balancer instead.
Step by step
Detailed examples
Choose NLB only for a fitting network and application
NLB runs on supported Windows Server and clusters two or more hosts at the IP layer. It does not probe URL health, synchronize configuration, replicate session state, terminate TLS centrally, or route non-TCP/UDP protocols. Applications must be independently healthy and equivalent on every node. Choose unicast, multicast, or IGMP multicast with the network team; switch flooding, router ARP behavior, virtualization MAC settings, and management connectivity differ. Installing NLB requires elevation and network rebinding can briefly disrupt connectivity or require restart.
Get-WindowsFeature NLB, RSAT-NLB
Get-NetAdapter | Select-Object Name, InterfaceDescription, Status, MacAddress, LinkSpeed
Get-NetIPConfiguration | Select-Object InterfaceAlias, IPv4Address, IPv4DefaultGateway, DnsServer
Get-ComputerInfo -Property WindowsProductName,WindowsVersion,OsBuildNumber Inventory cluster identity before any mutation
Use the NetworkLoadBalancingClusters module from an elevated management session with firewall and administrative access to all nodes. Record cluster primary and additional virtual IPs, operation mode, dedicated IPs, interface names, node priorities, port rules, and DNS. Interface names are host-local and can differ. NLB configuration should match across hosts; drift can produce partial reachability. Cmdlets using HostName act remotely and rely on management connectivity independent of the virtual service.
Get-NlbCluster -HostName NLB01 | Format-List *
Get-NlbClusterNode -HostName NLB01 | Format-Table HostName, Priority, State, Status
Get-NlbClusterVip -HostName NLB01 | Format-Table IPAddress, SubnetMask
Get-NlbClusterPortRule -HostName NLB01 | Format-Table StartPort, EndPort, Protocol, Mode, Affinity Create and expand only after end-to-end network validation
New-NlbCluster creates live cluster binding on the selected interface and adds a virtual IP. Confirm the exact adapter, dedicated IP, subnet, unused VIP, DNS TTL, switch configuration, firewall, certificate bindings, and management path first. Add-NlbClusterNode should follow application deployment, local health validation, policy parity, and certificate verification. These cmdlets do not provide a reliable full dry run even where common parameters exist; build in a lab and schedule a rollback window.
$Plan = [pscustomobject]@{
Interface='Ethernet'; VirtualIP='192.0.2.20'; Name='web.contoso.example'
Mode='Multicast'; Nodes=@('NLB01','NLB02'); Ports=@(80,443)
}
$Plan | ConvertTo-Json -Depth 3
Resolve-DnsName $Plan.Name -ErrorAction SilentlyContinue
Test-Connection NLB01,NLB02 -Count 2 Make port-rule behavior identical and intentional
Port rules define a destination VIP, port range, TCP/UDP protocol, multiple-host or single-host mode, affinity, and load. All hosts must agree. None affinity maximizes distribution but breaks source-dependent sessions; Single pins one client IP; Network groups class-C-style networks and is rarely appropriate for modern NAT populations. Affinity is not durable session storage. Broad rules can expose unintended services; pair NLB rules with firewalls. Rule and node-weight mutations have no WhatIf, so capture state and canary carefully.
$Hosts = 'NLB01','NLB02'
$Rules = foreach ($HostName in $Hosts) {
Get-NlbClusterPortRule -HostName $HostName |
Select-Object @{n='Host';e={$HostName}}, StartPort, EndPort, Protocol, Mode, Affinity, LoadWeight
}
$Rules | Sort-Object StartPort, Host | Format-Table
# Add-NlbClusterPortRule and Set-NlbClusterPortRuleNodeWeight change live traffic and have no WhatIf. Drain new traffic and verify sessions externally
Stop-NlbClusterNode -Drain stops accepting new connections while letting NLB-tracked active connections complete. It cannot understand application transactions, long polling, UDP state, background work, or connections bypassing the VIP. Watch external load-balancer probes, application metrics, and server connections until a defined threshold and timeout, then stop the application if required. Suspend controls NLB operations and is not equivalent to draining. Start only after local and VIP health pass.
Get-NlbClusterNode -HostName NLB01 | Select-Object HostName, State, Status
Get-NetTCPConnection -State Established | Group-Object LocalPort | Sort-Object Count -Descending
# Approved maintenance only:
# Stop-NlbClusterNode -HostName NLB01 -Drain
# Validate external application health and connection drain before servicing. Monitor application health beyond NLB convergence
Converged means hosts agree on NLB membership; it does not mean IIS, the application, database dependencies, certificates, or response content are healthy. Probe the VIP externally and each node directly through a safe health endpoint, validate status, body, TLS identity, latency, and dependency state. NLB can continue sending traffic to an unhealthy application unless automation drains the node. Avoid health checks that mutate data or require user sessions.
$Targets = 'web.contoso.example','nlb01.contoso.example','nlb02.contoso.example'
foreach ($Target in $Targets) {
$Tcp = Test-NetConnection $Target -Port 443 -WarningAction SilentlyContinue
[pscustomobject]@{ Target=$Target; Tcp443=$Tcp.TcpTestSucceeded; Address=$Tcp.RemoteAddress }
}
Get-NlbClusterNode -HostName NLB01 | Select-Object HostName, State, Status Troubleshoot ARP, switch, DNS, firewall, and application layers separately
Unicast changes cluster MAC behavior and can limit same-subnet node communication on the cluster adapter; multicast adds a multicast MAC to a unicast IP and may require static switch/router entries; IGMP multicast can reduce switch flooding when supported. Packet capture and switch tables often reveal problems that NLB state cannot. Restrict management protocols to dedicated networks, keep host firewall rules narrow, and never assume a VIP hides backend addresses or secures the application.
Resolve-DnsName web.contoso.example
Get-NetNeighbor -AddressFamily IPv4 | Sort-Object IPAddress
Get-NetAdapterStatistics -Name 'Ethernet'
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction
Get-WinEvent -ProviderName Microsoft-Windows-NLB -MaxEvents 100 -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Id, LevelDisplayName, Message Version configuration and preserve an out-of-band recovery path
Before changing VIPs, rules, mode, or membership, export a complete inventory from every node and record DNS, switch, firewall, application, and certificate state. Drain before removal. The NetworkLoadBalancingClusters mutation cmdlets shown here do not expose WhatIf and cannot model live flows or network equipment. Removal can break access immediately; keep dedicated management IPs and console access. Rollback may require restoring node configuration and external ARP, switch, DNS, or firewall changes together.
$Snapshot = [ordered]@{
Cluster = Get-NlbCluster -HostName NLB01
Nodes = Get-NlbClusterNode -HostName NLB01
VIPs = Get-NlbClusterVip -HostName NLB01
Rules = Get-NlbClusterPortRule -HostName NLB01
}
$Snapshot | Export-Clixml '.\nlb-before.clixml'
Get-FileHash '.\nlb-before.clixml' -Algorithm SHA256 Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- Microsoft LearnNetwork Load Balancing overviewlearn.microsoft.com
- Microsoft LearnNetworkLoadBalancingClusters modulelearn.microsoft.com
- Microsoft LearnNew-NlbClusterlearn.microsoft.com
- Microsoft LearnAdd-NlbClusterPortRulelearn.microsoft.com
- Microsoft LearnStop-NlbClusterNodelearn.microsoft.com
- Microsoft LearnNLB deployment considerationslearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



