What you need to know
The preview's per-flow load balancing does not promise that every connection in one application session reaches the same appliance.
Potentially affected
Nonproduction evaluations of preview DNAT for integrated firewall NVAs in a Virtual WAN hub.
DSE recommendation
Evaluate related application flows and return-path symmetry together, within the preview's nonproduction boundary.
Source facts
Microsoft labels DNAT for integrated Virtual WAN NVAs as Public Preview and says not to use it for production workloads. The guidance excludes SaaS integrations.
Inbound flows are distributed across healthy appliance instances using five-tuple hashing. Microsoft does not guarantee that related flows, such as FTP control and data connections, reach one instance. Source NAT is generally needed for return-path symmetry, but appliance-specific exceptions require the provider’s guidance. Microsoft Learn.
Applicability
Keep this review to an approved nonproduction evaluation of an integrated firewall NVA. Identify applications that open related connections and obtain the appliance provider’s supported NAT design before building a test configuration.
DSE recommendation
DSE recommends documenting the application’s session model rather than testing only a single connection. Ask the application and appliance owners whether independently distributed flows are acceptable and what evidence will demonstrate return-path symmetry. Keep any eventual production decision separate from this preview evaluation; a successful lab result does not remove the source’s production restriction.
Verification
Capture the related flows on the approved test path and identify the appliance instance handling each one. Check application completion and the corresponding return traffic, not merely initial connectivity. Repeat with representative concurrent sessions and record any dependence on same-instance placement. Preserve the observed behavior and unresolved provider questions without claiming affinity that the platform does not promise.
Official references
Microsoft Learn: Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub. Source retrieved September 9, 2026.
Review the official source
Azure Virtual WAN: Configure Destination NAT for Network Virtual Appliance (NVA) in the hub | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE