# Review StandardV2 NAT Gateway cutover exceptions before relying on session continuity

> Microsoft lists existing-flow and IPv6 load-balancer issues specific to adding StandardV2, despite broader NAT Gateway continuity guidance.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:30+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Microsoft lists existing-flow and IPv6 load-balancer issues specific to adding StandardV2, despite broader NAT Gateway continuity guidance.

## Potentially affected

Azure subnets moving existing outbound connectivity to StandardV2 NAT Gateway.

## DSE recommendation

Plan and test StandardV2 association as a cutover with explicit existing-session and IPv6 checks.

## Article

## Source facts

Microsoft’s StandardV2 known-issues section warns that adding the gateway can interrupt outbound connections using a load balancer, Azure Firewall or VM-level public IP. New outbound connections use StandardV2. It also documents disruption of IPv6 outbound traffic using load-balancer outbound rules when the gateway is associated.

A Standard NAT gateway cannot be upgraded in place to StandardV2: a new gateway must replace it on the subnet. StandardV2 also requires matching StandardV2 public IP addresses or prefixes, not Standard public IPs. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview).

## Applicability

Inventory existing outbound methods, long-lived sessions, address-family requirements and receiving-service allowlists. Check current regional support and known issues before selecting this SKU.

## DSE recommendation

DSE recommends a bounded cutover with an approved recovery path. Test existing sessions and newly opened connections separately, including IPv6 wherever the workload requires it. Coordinate the changed source identity with downstream owners before association. Do not use general NAT Gateway continuity language to override a documented StandardV2-specific exception.

## Verification

Observe representative sessions across the controlled association and record interruption, reconnection and destination-side source addresses. Verify both address families required by the workload. If the intended existing IPv6 path is incompatible, resolve the design before proceeding. Keep the actual gateway and public-IP SKUs in the evidence so a successful test of another configuration is not reused as approval.

## Official references

[Microsoft Learn: What Is Azure NAT Gateway?](https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview). Source retrieved September 9, 2026.

## Primary reference

- Name: What Is Azure NAT Gateway? | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/nat-gateway/nat-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review StandardV2 NAT Gateway cutover exceptions before relying on session continuity,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-326-review-standardv2-nat-gateway-cutover-exceptions-before-relying-on-session/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
