{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/",
        "slug": "dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/"
        },
        "title": "Validate VPN gateway traffic before committing the Basic public-IP migration",
        "summary": "Keeping the numerical IP address does not remove the validation and commit stages or the accompanying gateway SKU change.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:26+00:00",
        "modified_at": "2026-09-10T02:11:17+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 246,
        "potentially_affected": "Eligible non-Basic-SKU VPN gateways using the documented Basic public-IP migration workflow.",
        "dse_recommendation": "Validate actual tunnel traffic and the gateway change before the final migration commit.",
        "primary_source": {
            "name": "How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway - Azure VPN Gateway | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>The guided process preserves the gateway&#8217;s numerical IP address while moving it to a Standard public-IP resource. It also changes a non-AZ VPN gateway SKU to its AZ counterpart. Microsoft&#8217;s documented workflow excludes the Basic gateway SKU, which requires a different procedure.</p>\n<p>Before committing, Microsoft directs operators to validate receiving and transmitting traffic. Abort is the rollback path before commitment. Without the final commit, the old Basic public-IP resource remains pending rather than being deleted. <a href=\"https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Confirm gateway and public-IP SKUs separately, migration eligibility, subnet capacity and any special legacy-DNS P2S requirements. Do not apply this workflow to a gateway solely because its public IP is Basic.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends defining traffic acceptance checks and rollback authority before starting. Review the accompanying gateway SKU transition with its owner. Do not treat retention of the IP address as proof that tunnels, routing and required client paths work. Keep the validation decision separate from the action that finalizes the migration.</p>\n<h2>Verification</h2>\n<p>During an approved window, compare the gateway&#8217;s ingress and egress evidence with the agreed end-to-end connection tests. Resolve failures before committing and use the documented pre-commit abort path if required. After an approved commit, inspect the final resource and gateway state and preserve the receipt with traffic evidence. A resource left pending should remain an open migration item.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nThe guided process preserves the gateway’s numerical IP address while moving it to a Standard public-IP resource. It also changes a non-AZ VPN gateway SKU to its AZ counterpart. Microsoft’s documented workflow excludes the Basic gateway SKU, which requires a different procedure.\nBefore committing, Microsoft directs operators to validate receiving and transmitting traffic. Abort is the rollback path before commitment. Without the final commit, the old Basic public-IP resource remains pending rather than being deleted. Microsoft Learn.\nApplicability\nConfirm gateway and public-IP SKUs separately, migration eligibility, subnet capacity and any special legacy-DNS P2S requirements. Do not apply this workflow to a gateway solely because its public IP is Basic.\nDSE recommendation\nDSE recommends defining traffic acceptance checks and rollback authority before starting. Review the accompanying gateway SKU transition with its owner. Do not treat retention of the IP address as proof that tunnels, routing and required client paths work. Keep the validation decision separate from the action that finalizes the migration.\nVerification\nDuring an approved window, compare the gateway’s ingress and egress evidence with the agreed end-to-end connection tests. Resolve failures before committing and use the documented pre-commit abort path if required. After an approved commit, inspect the final resource and gateway state and preserve the receipt with traffic evidence. A resource left pending should remain an open migration item.\nOfficial references\nMicrosoft Learn: How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nThe guided process preserves the gateway’s numerical IP address while moving it to a Standard public-IP resource. It also changes a non-AZ VPN gateway SKU to its AZ counterpart. Microsoft’s documented workflow excludes the Basic gateway SKU, which requires a different procedure.\n\nBefore committing, Microsoft directs operators to validate receiving and transmitting traffic. Abort is the rollback path before commitment. Without the final commit, the old Basic public-IP resource remains pending rather than being deleted. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto).\n\n## Applicability\n\nConfirm gateway and public-IP SKUs separately, migration eligibility, subnet capacity and any special legacy-DNS P2S requirements. Do not apply this workflow to a gateway solely because its public IP is Basic.\n\n## DSE recommendation\n\nDSE recommends defining traffic acceptance checks and rollback authority before starting. Review the accompanying gateway SKU transition with its owner. Do not treat retention of the IP address as proof that tunnels, routing and required client paths work. Keep the validation decision separate from the action that finalizes the migration.\n\n## Verification\n\nDuring an approved window, compare the gateway’s ingress and egress evidence with the agreed end-to-end connection tests. Resolve failures before committing and use the documented pre-commit abort path if required. After an approved commit, inspect the final resource and gateway state and preserve the receipt with traffic evidence. A resource left pending should remain an open migration item.\n\n## Official references\n\n[Microsoft Learn: How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway](https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Validate VPN gateway traffic before committing the Basic public-IP migration",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/",
                "headline": "Validate VPN gateway traffic before committing the Basic public-IP migration",
                "description": "Keeping the numerical IP address does not remove the validation and commit stages or the accompanying gateway SKU change.",
                "abstract": "Keeping the numerical IP address does not remove the validation and commit stages or the accompanying gateway SKU change.",
                "articleBody": "Source facts\nThe guided process preserves the gateway’s numerical IP address while moving it to a Standard public-IP resource. It also changes a non-AZ VPN gateway SKU to its AZ counterpart. Microsoft’s documented workflow excludes the Basic gateway SKU, which requires a different procedure.\nBefore committing, Microsoft directs operators to validate receiving and transmitting traffic. Abort is the rollback path before commitment. Without the final commit, the old Basic public-IP resource remains pending rather than being deleted. Microsoft Learn.\nApplicability\nConfirm gateway and public-IP SKUs separately, migration eligibility, subnet capacity and any special legacy-DNS P2S requirements. Do not apply this workflow to a gateway solely because its public IP is Basic.\nDSE recommendation\nDSE recommends defining traffic acceptance checks and rollback authority before starting. Review the accompanying gateway SKU transition with its owner. Do not treat retention of the IP address as proof that tunnels, routing and required client paths work. Keep the validation decision separate from the action that finalizes the migration.\nVerification\nDuring an approved window, compare the gateway’s ingress and egress evidence with the agreed end-to-end connection tests. Resolve failures before committing and use the documented pre-commit abort path if required. After an approved commit, inspect the final resource and gateway state and preserve the receipt with traffic evidence. A resource left pending should remain an open migration item.\nOfficial references\nMicrosoft Learn: How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:23:26+00:00",
                "dateModified": "2026-09-10T02:11:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Validate VPN gateway traffic before committing the Basic public-IP migration"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 246,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway - Azure VPN Gateway | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto"
                }
            }
        ]
    }
}