# Test multi-flow session affinity before evaluating Virtual WAN NVA DNAT

> The preview's per-flow load balancing does not promise that every connection in one application session reaches the same appliance.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:09+00:00
- Modified: 2026-09-10T01:20:46+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

The preview's per-flow load balancing does not promise that every connection in one application session reaches the same appliance.

## Potentially affected

Nonproduction evaluations of preview DNAT for integrated firewall NVAs in a Virtual WAN hub.

## DSE recommendation

Evaluate related application flows and return-path symmetry together, within the preview's nonproduction boundary.

## Article

## Source facts

Microsoft labels DNAT for integrated Virtual WAN NVAs as Public Preview and says not to use it for production workloads. The guidance excludes SaaS integrations.

Inbound flows are distributed across healthy appliance instances using five-tuple hashing. Microsoft does not guarantee that related flows, such as FTP control and data connections, reach one instance. Source NAT is generally needed for return-path symmetry, but appliance-specific exceptions require the provider’s guidance. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound).

## Applicability

Keep this review to an approved nonproduction evaluation of an integrated firewall NVA. Identify applications that open related connections and obtain the appliance provider’s supported NAT design before building a test configuration.

## DSE recommendation

DSE recommends documenting the application’s session model rather than testing only a single connection. Ask the application and appliance owners whether independently distributed flows are acceptable and what evidence will demonstrate return-path symmetry. Keep any eventual production decision separate from this preview evaluation; a successful lab result does not remove the source’s production restriction.

## Verification

Capture the related flows on the approved test path and identify the appliance instance handling each one. Check application completion and the corresponding return traffic, not merely initial connectivity. Repeat with representative concurrent sessions and record any dependence on same-instance placement. Preserve the observed behavior and unresolved provider questions without claiming affinity that the platform does not promise.

## Official references

[Microsoft Learn: Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub](https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-network-virtual-appliance-inbound
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Test multi-flow session affinity before evaluating Virtual WAN NVA DNAT,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-227-test-multi-flow-session-affinity-before-evaluating-virtual-wan-nva-dnat/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
