{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/",
        "slug": "dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/"
        },
        "title": "Test multi-flow session affinity before evaluating Virtual WAN NVA DNAT",
        "summary": "The preview's per-flow load balancing does not promise that every connection in one application session reaches the same appliance.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:09+00:00",
        "modified_at": "2026-09-10T01:20:46+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 241,
        "potentially_affected": "Nonproduction evaluations of preview DNAT for integrated firewall NVAs in a Virtual WAN hub.",
        "dse_recommendation": "Evaluate related application flows and return-path symmetry together, within the preview's nonproduction boundary.",
        "primary_source": {
            "name": "Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft labels DNAT for integrated Virtual WAN NVAs as Public Preview and says not to use it for production workloads. The guidance excludes SaaS integrations.</p>\n<p>Inbound flows are distributed across healthy appliance instances using five-tuple hashing. Microsoft does not guarantee that related flows, such as FTP control and data connections, reach one instance. Source NAT is generally needed for return-path symmetry, but appliance-specific exceptions require the provider&#8217;s guidance. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Keep this review to an approved nonproduction evaluation of an integrated firewall NVA. Identify applications that open related connections and obtain the appliance provider&#8217;s supported NAT design before building a test configuration.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends documenting the application&#8217;s session model rather than testing only a single connection. Ask the application and appliance owners whether independently distributed flows are acceptable and what evidence will demonstrate return-path symmetry. Keep any eventual production decision separate from this preview evaluation; a successful lab result does not remove the source&#8217;s production restriction.</p>\n<h2>Verification</h2>\n<p>Capture the related flows on the approved test path and identify the appliance instance handling each one. Check application completion and the corresponding return traffic, not merely initial connectivity. Repeat with representative concurrent sessions and record any dependence on same-instance placement. Preserve the observed behavior and unresolved provider questions without claiming affinity that the platform does not promise.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft labels DNAT for integrated Virtual WAN NVAs as Public Preview and says not to use it for production workloads. The guidance excludes SaaS integrations.\nInbound flows are distributed across healthy appliance instances using five-tuple hashing. Microsoft does not guarantee that related flows, such as FTP control and data connections, reach one instance. Source NAT is generally needed for return-path symmetry, but appliance-specific exceptions require the provider’s guidance. Microsoft Learn.\nApplicability\nKeep this review to an approved nonproduction evaluation of an integrated firewall NVA. Identify applications that open related connections and obtain the appliance provider’s supported NAT design before building a test configuration.\nDSE recommendation\nDSE recommends documenting the application’s session model rather than testing only a single connection. Ask the application and appliance owners whether independently distributed flows are acceptable and what evidence will demonstrate return-path symmetry. Keep any eventual production decision separate from this preview evaluation; a successful lab result does not remove the source’s production restriction.\nVerification\nCapture the related flows on the approved test path and identify the appliance instance handling each one. Check application completion and the corresponding return traffic, not merely initial connectivity. Repeat with representative concurrent sessions and record any dependence on same-instance placement. Preserve the observed behavior and unresolved provider questions without claiming affinity that the platform does not promise.\nOfficial references\nMicrosoft Learn: Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft labels DNAT for integrated Virtual WAN NVAs as Public Preview and says not to use it for production workloads. The guidance excludes SaaS integrations.\n\nInbound flows are distributed across healthy appliance instances using five-tuple hashing. Microsoft does not guarantee that related flows, such as FTP control and data connections, reach one instance. Source NAT is generally needed for return-path symmetry, but appliance-specific exceptions require the provider’s guidance. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound).\n\n## Applicability\n\nKeep this review to an approved nonproduction evaluation of an integrated firewall NVA. Identify applications that open related connections and obtain the appliance provider’s supported NAT design before building a test configuration.\n\n## DSE recommendation\n\nDSE recommends documenting the application’s session model rather than testing only a single connection. Ask the application and appliance owners whether independently distributed flows are acceptable and what evidence will demonstrate return-path symmetry. Keep any eventual production decision separate from this preview evaluation; a successful lab result does not remove the source’s production restriction.\n\n## Verification\n\nCapture the related flows on the approved test path and identify the appliance instance handling each one. Check application completion and the corresponding return traffic, not merely initial connectivity. Repeat with representative concurrent sessions and record any dependence on same-instance placement. Preserve the observed behavior and unresolved provider questions without claiming affinity that the platform does not promise.\n\n## Official references\n\n[Microsoft Learn: Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub](https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Test multi-flow session affinity before evaluating Virtual WAN NVA DNAT",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/",
                "headline": "Test multi-flow session affinity before evaluating Virtual WAN NVA DNAT",
                "description": "The preview's per-flow load balancing does not promise that every connection in one application session reaches the same appliance.",
                "abstract": "The preview's per-flow load balancing does not promise that every connection in one application session reaches the same appliance.",
                "articleBody": "Source facts\nMicrosoft labels DNAT for integrated Virtual WAN NVAs as Public Preview and says not to use it for production workloads. The guidance excludes SaaS integrations.\nInbound flows are distributed across healthy appliance instances using five-tuple hashing. Microsoft does not guarantee that related flows, such as FTP control and data connections, reach one instance. Source NAT is generally needed for return-path symmetry, but appliance-specific exceptions require the provider’s guidance. Microsoft Learn.\nApplicability\nKeep this review to an approved nonproduction evaluation of an integrated firewall NVA. Identify applications that open related connections and obtain the appliance provider’s supported NAT design before building a test configuration.\nDSE recommendation\nDSE recommends documenting the application’s session model rather than testing only a single connection. Ask the application and appliance owners whether independently distributed flows are acceptable and what evidence will demonstrate return-path symmetry. Keep any eventual production decision separate from this preview evaluation; a successful lab result does not remove the source’s production restriction.\nVerification\nCapture the related flows on the approved test path and identify the appliance instance handling each one. Check application completion and the corresponding return traffic, not merely initial connectivity. Repeat with representative concurrent sessions and record any dependence on same-instance placement. Preserve the observed behavior and unresolved provider questions without claiming affinity that the platform does not promise.\nOfficial references\nMicrosoft Learn: Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:28:09+00:00",
                "dateModified": "2026-09-10T01:20:46+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Test multi-flow session affinity before evaluating Virtual WAN NVA DNAT"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 241,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound"
                }
            }
        ]
    }
}