{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/",
        "slug": "dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/"
        },
        "title": "Review StandardV2 NAT Gateway cutover exceptions before relying on session continuity",
        "summary": "Microsoft lists existing-flow and IPv6 load-balancer issues specific to adding StandardV2, despite broader NAT Gateway continuity guidance.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:30+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 229,
        "potentially_affected": "Azure subnets moving existing outbound connectivity to StandardV2 NAT Gateway.",
        "dse_recommendation": "Plan and test StandardV2 association as a cutover with explicit existing-session and IPv6 checks.",
        "primary_source": {
            "name": "What Is Azure NAT Gateway? | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s StandardV2 known-issues section warns that adding the gateway can interrupt outbound connections using a load balancer, Azure Firewall or VM-level public IP. New outbound connections use StandardV2. It also documents disruption of IPv6 outbound traffic using load-balancer outbound rules when the gateway is associated.</p>\n<p>A Standard NAT gateway cannot be upgraded in place to StandardV2: a new gateway must replace it on the subnet. StandardV2 also requires matching StandardV2 public IP addresses or prefixes, not Standard public IPs. <a href=\"https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Inventory existing outbound methods, long-lived sessions, address-family requirements and receiving-service allowlists. Check current regional support and known issues before selecting this SKU.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a bounded cutover with an approved recovery path. Test existing sessions and newly opened connections separately, including IPv6 wherever the workload requires it. Coordinate the changed source identity with downstream owners before association. Do not use general NAT Gateway continuity language to override a documented StandardV2-specific exception.</p>\n<h2>Verification</h2>\n<p>Observe representative sessions across the controlled association and record interruption, reconnection and destination-side source addresses. Verify both address families required by the workload. If the intended existing IPv6 path is incompatible, resolve the design before proceeding. Keep the actual gateway and public-IP SKUs in the evidence so a successful test of another configuration is not reused as approval.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: What Is Azure NAT Gateway?</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s StandardV2 known-issues section warns that adding the gateway can interrupt outbound connections using a load balancer, Azure Firewall or VM-level public IP. New outbound connections use StandardV2. It also documents disruption of IPv6 outbound traffic using load-balancer outbound rules when the gateway is associated.\nA Standard NAT gateway cannot be upgraded in place to StandardV2: a new gateway must replace it on the subnet. StandardV2 also requires matching StandardV2 public IP addresses or prefixes, not Standard public IPs. Microsoft Learn.\nApplicability\nInventory existing outbound methods, long-lived sessions, address-family requirements and receiving-service allowlists. Check current regional support and known issues before selecting this SKU.\nDSE recommendation\nDSE recommends a bounded cutover with an approved recovery path. Test existing sessions and newly opened connections separately, including IPv6 wherever the workload requires it. Coordinate the changed source identity with downstream owners before association. Do not use general NAT Gateway continuity language to override a documented StandardV2-specific exception.\nVerification\nObserve representative sessions across the controlled association and record interruption, reconnection and destination-side source addresses. Verify both address families required by the workload. If the intended existing IPv6 path is incompatible, resolve the design before proceeding. Keep the actual gateway and public-IP SKUs in the evidence so a successful test of another configuration is not reused as approval.\nOfficial references\nMicrosoft Learn: What Is Azure NAT Gateway?. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s StandardV2 known-issues section warns that adding the gateway can interrupt outbound connections using a load balancer, Azure Firewall or VM-level public IP. New outbound connections use StandardV2. It also documents disruption of IPv6 outbound traffic using load-balancer outbound rules when the gateway is associated.\n\nA Standard NAT gateway cannot be upgraded in place to StandardV2: a new gateway must replace it on the subnet. StandardV2 also requires matching StandardV2 public IP addresses or prefixes, not Standard public IPs. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview).\n\n## Applicability\n\nInventory existing outbound methods, long-lived sessions, address-family requirements and receiving-service allowlists. Check current regional support and known issues before selecting this SKU.\n\n## DSE recommendation\n\nDSE recommends a bounded cutover with an approved recovery path. Test existing sessions and newly opened connections separately, including IPv6 wherever the workload requires it. Coordinate the changed source identity with downstream owners before association. Do not use general NAT Gateway continuity language to override a documented StandardV2-specific exception.\n\n## Verification\n\nObserve representative sessions across the controlled association and record interruption, reconnection and destination-side source addresses. Verify both address families required by the workload. If the intended existing IPv6 path is incompatible, resolve the design before proceeding. Keep the actual gateway and public-IP SKUs in the evidence so a successful test of another configuration is not reused as approval.\n\n## Official references\n\n[Microsoft Learn: What Is Azure NAT Gateway?](https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review StandardV2 NAT Gateway cutover exceptions before relying on session continuity",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/",
                "headline": "Review StandardV2 NAT Gateway cutover exceptions before relying on session continuity",
                "description": "Microsoft lists existing-flow and IPv6 load-balancer issues specific to adding StandardV2, despite broader NAT Gateway continuity guidance.",
                "abstract": "Microsoft lists existing-flow and IPv6 load-balancer issues specific to adding StandardV2, despite broader NAT Gateway continuity guidance.",
                "articleBody": "Source facts\nMicrosoft’s StandardV2 known-issues section warns that adding the gateway can interrupt outbound connections using a load balancer, Azure Firewall or VM-level public IP. New outbound connections use StandardV2. It also documents disruption of IPv6 outbound traffic using load-balancer outbound rules when the gateway is associated.\nA Standard NAT gateway cannot be upgraded in place to StandardV2: a new gateway must replace it on the subnet. StandardV2 also requires matching StandardV2 public IP addresses or prefixes, not Standard public IPs. Microsoft Learn.\nApplicability\nInventory existing outbound methods, long-lived sessions, address-family requirements and receiving-service allowlists. Check current regional support and known issues before selecting this SKU.\nDSE recommendation\nDSE recommends a bounded cutover with an approved recovery path. Test existing sessions and newly opened connections separately, including IPv6 wherever the workload requires it. Coordinate the changed source identity with downstream owners before association. Do not use general NAT Gateway continuity language to override a documented StandardV2-specific exception.\nVerification\nObserve representative sessions across the controlled association and record interruption, reconnection and destination-side source addresses. Verify both address families required by the workload. If the intended existing IPv6 path is incompatible, resolve the design before proceeding. Keep the actual gateway and public-IP SKUs in the evidence so a successful test of another configuration is not reused as approval.\nOfficial references\nMicrosoft Learn: What Is Azure NAT Gateway?. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:26:30+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review StandardV2 NAT Gateway cutover exceptions before relying on session continuity"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 229,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "What Is Azure NAT Gateway? | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview"
                }
            }
        ]
    }
}