What you need to know
When the on-premises peering address needs translation, the documented design uses a separate static mapping and the translated link address.
Potentially affected
BGP-enabled Virtual WAN site-to-site VPN connections using dynamic NAT for overlapping address ranges.
DSE recommendation
Review the BGP peer's static mapping and link address separately from the dynamic application-address pool.
Source facts
Microsoft says the on-premises BGP peer cannot be included in a dynamic rule’s pre-NAT mapping because the translated address and port are not fixed. If that peer needs translation, the documented approach is a separate static rule for the peering address.
The VPN site’s link-connection BGP address must then use the translated address. The guidance also excludes site-to-site connections that use policy-based traffic selectors from this NAT capability. Microsoft Learn.
Applicability
Identify the original peer address, intended translated peer address, dynamic application range and connection type. Keep the routing-control endpoint distinct from the traffic whose overlapping addresses motivated NAT.
DSE recommendation
DSE recommends a mapping worksheet that shows the BGP peer’s dedicated static translation alongside the dynamic pool. Have both VPN owners check the link-connection setting and expected route advertisements before the change. Do not assume that a working translated application flow demonstrates the BGP peering configuration is correct. Review the full source for ingress, egress and route-translation settings.
Verification
In an approved test connection, inspect the deployed NAT rules and the configured BGP link address, then verify peering and learned routes. Exercise an intended translated application path and its return traffic separately. Retain the original and translated identities with the observed routes so future address changes do not accidentally move the control-plane peer into the dynamic mapping.
Official references
Microsoft Learn: Configure VPN NAT rules for your gateway. Source retrieved September 9, 2026.
Review the official source
Configure VPN NAT rules for your gateway - Azure Virtual WAN | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE