Azure can even configure mutual authentication between the LB & the underlying servers, which would cause any direct server access to result in a 401[0].
0 - For API servers. I'm not sure if you could configure this with services like Elasticsearch.
0 - For API servers. I'm not sure if you could configure this with services like Elasticsearch.
You can achieve a similar effect in AWS, by declaring only the LB's security group as the source in servers' security group ingress rule.
Any requests sent directly to the servers simply wouldn't connect.