{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/",
        "slug": "dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/"
        },
        "title": "Verify the Gateway Load Balancer service chain before claiming inline inspection",
        "summary": "Does enabling Azure DDoS Protection alone demonstrate that traffic traverses a partner L7 appliance?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:03+00:00",
        "modified_at": "2026-09-10T02:08:05+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 249,
        "potentially_affected": "Use this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application's availability.",
        "dse_recommendation": "Accept the appliance path separately from enabling the network-layer protection service.",
        "primary_source": {
            "name": "Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s inline design adds partner NVAs through Gateway Load Balancer, while Azure DDoS Protection supplies network-layer protection. Linking Gateway Load Balancer to a Standard Public Load Balancer frontend or a VM IP configuration routes traffic to and from that endpoint through the gateway. The documented flow sends incoming traffic through the partner appliances before returning clean traffic to the backend. <a href=\"https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application&#8217;s availability.</p>\n<h2>DSE recommendation</h2>\n<p>Accept the appliance path separately from enabling the network-layer protection service. Have the endpoint and appliance owners identify the frontend association and the expected ingress and return path. Record the NVA capacity, health and maintenance requirements that must be validated for the chosen product. Keep the claim of application-layer inspection tied to appliance evidence, not to the presence of a DDoS protection plan alone. Do not generate attack traffic outside an explicitly authorized validation arrangement.</p>\n<h2>Verification</h2>\n<p>Use approved benign application traffic to trace the service chain and correlate endpoint, gateway and appliance observations. Exercise the planned appliance-failure scenario only in its approved test scope. Verify that the application path and intended inspection remain consistent with the design. Record any bypass or missing appliance evidence before representing the endpoint as having validated inline inspection.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs</a>.</p>",
        "content_text": "Source facts\nMicrosoft’s inline design adds partner NVAs through Gateway Load Balancer, while Azure DDoS Protection supplies network-layer protection. Linking Gateway Load Balancer to a Standard Public Load Balancer frontend or a VM IP configuration routes traffic to and from that endpoint through the gateway. The documented flow sends incoming traffic through the partner appliances before returning clean traffic to the backend. Microsoft Learn.\nApplicability\nUse this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application’s availability.\nDSE recommendation\nAccept the appliance path separately from enabling the network-layer protection service. Have the endpoint and appliance owners identify the frontend association and the expected ingress and return path. Record the NVA capacity, health and maintenance requirements that must be validated for the chosen product. Keep the claim of application-layer inspection tied to appliance evidence, not to the presence of a DDoS protection plan alone. Do not generate attack traffic outside an explicitly authorized validation arrangement.\nVerification\nUse approved benign application traffic to trace the service chain and correlate endpoint, gateway and appliance observations. Exercise the planned appliance-failure scenario only in its approved test scope. Verify that the application path and intended inspection remain consistent with the design. Record any bypass or missing appliance evidence before representing the endpoint as having validated inline inspection.\nOfficial references\nMicrosoft Learn: Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs.",
        "content_markdown": "## Source facts\n\nMicrosoft’s inline design adds partner NVAs through Gateway Load Balancer, while Azure DDoS Protection supplies network-layer protection. Linking Gateway Load Balancer to a Standard Public Load Balancer frontend or a VM IP configuration routes traffic to and from that endpoint through the gateway. The documented flow sends incoming traffic through the partner appliances before returning clean traffic to the backend. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb).\n\n## Applicability\n\nUse this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application’s availability.\n\n## DSE recommendation\n\nAccept the appliance path separately from enabling the network-layer protection service. Have the endpoint and appliance owners identify the frontend association and the expected ingress and return path. Record the NVA capacity, health and maintenance requirements that must be validated for the chosen product. Keep the claim of application-layer inspection tied to appliance evidence, not to the presence of a DDoS protection plan alone. Do not generate attack traffic outside an explicitly authorized validation arrangement.\n\n## Verification\n\nUse approved benign application traffic to trace the service chain and correlate endpoint, gateway and appliance observations. Exercise the planned appliance-failure scenario only in its approved test scope. Verify that the application path and intended inspection remain consistent with the design. Record any bypass or missing appliance evidence before representing the endpoint as having validated inline inspection.\n\n## Official references\n\n[Microsoft Learn: Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs](https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Verify the Gateway Load Balancer service chain before claiming inline inspection",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/",
                "headline": "Verify the Gateway Load Balancer service chain before claiming inline inspection",
                "description": "Does enabling Azure DDoS Protection alone demonstrate that traffic traverses a partner L7 appliance?",
                "abstract": "Does enabling Azure DDoS Protection alone demonstrate that traffic traverses a partner L7 appliance?",
                "articleBody": "Source facts\nMicrosoft’s inline design adds partner NVAs through Gateway Load Balancer, while Azure DDoS Protection supplies network-layer protection. Linking Gateway Load Balancer to a Standard Public Load Balancer frontend or a VM IP configuration routes traffic to and from that endpoint through the gateway. The documented flow sends incoming traffic through the partner appliances before returning clean traffic to the backend. Microsoft Learn.\nApplicability\nUse this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application’s availability.\nDSE recommendation\nAccept the appliance path separately from enabling the network-layer protection service. Have the endpoint and appliance owners identify the frontend association and the expected ingress and return path. Record the NVA capacity, health and maintenance requirements that must be validated for the chosen product. Keep the claim of application-layer inspection tied to appliance evidence, not to the presence of a DDoS protection plan alone. Do not generate attack traffic outside an explicitly authorized validation arrangement.\nVerification\nUse approved benign application traffic to trace the service chain and correlate endpoint, gateway and appliance observations. Exercise the planned appliance-failure scenario only in its approved test scope. Verify that the application path and intended inspection remain consistent with the design. Record any bypass or missing appliance evidence before representing the endpoint as having validated inline inspection.\nOfficial references\nMicrosoft Learn: Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs.",
                "datePublished": "2026-09-10T00:24:03+00:00",
                "dateModified": "2026-09-10T02:08:05+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Verify the Gateway Load Balancer service chain before claiming inline inspection"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 249,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb"
                }
            }
        ]
    }
}