Review StandardV2 NAT Gateway cutover exceptions before relying on session continuity

Microsoft lists existing-flow and IPv6 load-balancer issues specific to adding StandardV2, despite broader NAT Gateway continuity guidance.

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Microsoft lists existing-flow and IPv6 load-balancer issues specific to adding StandardV2, despite broader NAT Gateway continuity guidance.

Potentially affected

Azure subnets moving existing outbound connectivity to StandardV2 NAT Gateway.

DSE recommendation

Plan and test StandardV2 association as a cutover with explicit existing-session and IPv6 checks.

Source facts

Microsoft’s StandardV2 known-issues section warns that adding the gateway can interrupt outbound connections using a load balancer, Azure Firewall or VM-level public IP. New outbound connections use StandardV2. It also documents disruption of IPv6 outbound traffic using load-balancer outbound rules when the gateway is associated.

A Standard NAT gateway cannot be upgraded in place to StandardV2: a new gateway must replace it on the subnet. StandardV2 also requires matching StandardV2 public IP addresses or prefixes, not Standard public IPs. Microsoft Learn.

Applicability

Inventory existing outbound methods, long-lived sessions, address-family requirements and receiving-service allowlists. Check current regional support and known issues before selecting this SKU.

DSE recommendation

DSE recommends a bounded cutover with an approved recovery path. Test existing sessions and newly opened connections separately, including IPv6 wherever the workload requires it. Coordinate the changed source identity with downstream owners before association. Do not use general NAT Gateway continuity language to override a documented StandardV2-specific exception.

Verification

Observe representative sessions across the controlled association and record interruption, reconnection and destination-side source addresses. Verify both address families required by the workload. If the intended existing IPv6 path is incompatible, resolve the design before proceeding. Keep the actual gateway and public-IP SKUs in the evidence so a successful test of another configuration is not reused as approval.

Official references

Microsoft Learn: What Is Azure NAT Gateway?. Source retrieved September 9, 2026.

Primary reference

Review the official source

What Is Azure NAT Gateway? | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE