Load balancer is confined to a single Availability Zone

Severity
Low
Service
Elastic Load Balancing
Check ID
ELB_NOT_MULTI_AZ

What this check finds

A load balancer with subnets in only one Availability Zone cannot route traffic if that AZ fails, defeating its purpose as a highly available entry point. Enable at least two Availability Zones so the load balancer survives an AZ outage.

Passing looks like: Load balancer spans multiple Availability Zones.

How to fix it

Add a subnet from a second Availability Zone to the load balancer.

AWS console

EC2 → Load Balancers → select the load balancer → Edit subnets → enable a subnet in another AZ. CLI (ALB/NLB): aws elbv2 set-subnets --load-balancer-arn ARN --subnets SUBNET_AZ_A SUBNET_AZ_B.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to Load balancer is confined to a single Availability Zone
FrameworkControls
NIST SP 800-53 Rev5 (Moderate)
  • CP-10 System Recovery and Reconstitution
NIST Cybersecurity Framework 2.0
  • RC.RP-01 The recovery plan is executed
ISO/IEC 27001:2022 Annex A
  • A.5.29 Information security during disruption
  • A.8.14 Redundancy of information processing facilities

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More Elastic Load Balancing checks

All Elastic Load Balancing checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only