# Distinguish SDN load balancing from outbound NAT and full VIP forwarding

> Which SDN load-balancer rule matches the required traffic direction and exposure?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-104-distinguish-sdn-load-balancing-from-outbound-nat-and-full-vip-forwarding/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:27+00:00
- Modified: 2026-09-08T18:23:26+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which SDN load-balancer rule matches the required traffic direction and exposure?

## Potentially affected

Administrators configuring Microsoft SDN Software Load Balancer rules.

## DSE recommendation

Create a traffic contract listing the required source, destination, direction, and scope.

## Article

## Source facts

Microsoft documents Software Load Balancer for incoming distribution, inbound NAT, and outbound NAT. Its outbound NAT example gives a VM in private virtual-network address space an internet-bound translation path. An L3 forwarding rule maps a virtual IP to one VM network interface without specifying individual ports. Microsoft describes that rule as forwarding all traffic to and from that VM through the assigned VIP. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Configure-SLB-and-NAT).

## Applicability

Identify the traffic direction, intended virtual IP, backend interfaces, approved ports, and service owner. Review whether the requirement is a shared service, outbound access, or a whole-address mapping before adapting an example.

## DSE recommendation

Create a traffic contract listing the required source, destination, direction, and scope. Have the application and network owners review any whole-address forwarding request explicitly. Record the backend membership and avoid substituting a broad rule merely because a narrower service test failed.

## Verification

Test the required traffic and a deliberately excluded path from the intended networks. Confirm which backend receives the request and which translated address is observed. Preserve the actual rule and membership with the test results, and investigate unexpected exposure before placing the rule into wider service.

## Official references

[Microsoft Learn: Configure the Software Load Balancer for Load Balancing and Network Address Translation (NAT)](https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Configure-SLB-and-NAT). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure the Software Load Balancer for Load Balancing and Network Address Translation (NAT)
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Configure-SLB-and-NAT
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Distinguish SDN load balancing from outbound NAT and full VIP forwarding,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-104-distinguish-sdn-load-balancing-from-outbound-nat-and-full-vip-forwarding/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
