# Verify the Gateway Load Balancer service chain before claiming inline inspection

> Does enabling Azure DDoS Protection alone demonstrate that traffic traverses a partner L7 appliance?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:03+00:00
- Modified: 2026-09-10T02:08:05+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Does enabling Azure DDoS Protection alone demonstrate that traffic traverses a partner L7 appliance?

## Potentially affected

Use this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application's availability.

## DSE recommendation

Accept the appliance path separately from enabling the network-layer protection service.

## Article

## Source facts

Microsoft’s inline design adds partner NVAs through Gateway Load Balancer, while Azure DDoS Protection supplies network-layer protection. Linking Gateway Load Balancer to a Standard Public Load Balancer frontend or a VM IP configuration routes traffic to and from that endpoint through the gateway. The documented flow sends incoming traffic through the partner appliances before returning clean traffic to the backend. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb).

## Applicability

Use this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application’s availability.

## DSE recommendation

Accept the appliance path separately from enabling the network-layer protection service. Have the endpoint and appliance owners identify the frontend association and the expected ingress and return path. Record the NVA capacity, health and maintenance requirements that must be validated for the chosen product. Keep the claim of application-layer inspection tied to appliance evidence, not to the presence of a DDoS protection plan alone. Do not generate attack traffic outside an explicitly authorized validation arrangement.

## Verification

Use approved benign application traffic to trace the service chain and correlate endpoint, gateway and appliance observations. Exercise the planned appliance-failure scenario only in its approved test scope. Verify that the application path and intended inspection remain consistent with the design. Record any bypass or missing appliance evidence before representing the endpoint as having validated inline inspection.

## Official references

[Microsoft Learn: Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs](https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb).

## Primary reference

- Name: Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/ddos-protection/inline-protection-glb
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Verify the Gateway Load Balancer service chain before claiming inline inspection,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-473-verify-the-gateway-load-balancer-service-chain-before-claiming-inline-inspection/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
