# Budget Application Gateway v2 subnet addresses for peak instance count

> Include Azure reservations, gateway instances, and private frontend addresses in subnet capacity planning.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-116-budget-application-gateway-v2-subnet-addresses-for-peak-instance-count/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:00+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Include Azure reservations, gateway instances, and private frontend addresses in subnet capacity planning.

## Potentially affected

Azure Application Gateway v2 deployments planning subnet capacity.

## DSE recommendation

Calculate subnet capacity against the intended maximum gateway instances, not just visible network-interface addresses.

## Article

## Source facts

Azure reserves five addresses in each subnet. Application Gateway additionally consumes an address for every instance and another for a private frontend configuration. Microsoft recommends a /24 for v2 growth and maintenance, while explicitly saying that size is not mandatory.

Application Gateway v2 instance addresses are managed by Azure and are not individually listed as NIC IP configurations. Microsoft directs owners to include them through capacity calculation rather than relying only on visible allocations. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/application-gateway/configuration-infrastructure).

## Applicability

Inventory every gateway sharing the dedicated subnet, each intended maximum instance count, and its private frontend configuration. Keep the v2 calculation separate from older deployment assumptions and unrelated subnet examples.

## DSE recommendation

DSE recommends an address budget with explicit rows for reserved addresses, each gateway’s planned instances, and frontends. Compare it with the available subnet range before increasing scale settings or adding another gateway. Record the expected traffic-driven instance requirement and the owner approving remaining headroom.

## Verification

Reconcile the budget with the actual gateway configuration and visible allocated addresses. In an approved test, observe a planned scale change and check that the application remains reachable. Treat a clean NIC listing as incomplete capacity evidence, and investigate any discrepancy before expanding production traffic.

## Official references

[Microsoft Learn: Azure Application Gateway infrastructure configuration](https://learn.microsoft.com/en-us/azure/application-gateway/configuration-infrastructure). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Application Gateway infrastructure configuration | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/application-gateway/configuration-infrastructure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Budget Application Gateway v2 subnet addresses for peak instance count,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-116-budget-application-gateway-v2-subnet-addresses-for-peak-instance-count/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
