What you need to know
Does enabling Azure DDoS Protection alone demonstrate that traffic traverses a partner L7 appliance?
Potentially affected
Use this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application's availability.
DSE recommendation
Accept the appliance path separately from enabling the network-layer protection service.
Source facts
Microsoft’s inline design adds partner NVAs through Gateway Load Balancer, while Azure DDoS Protection supplies network-layer protection. Linking Gateway Load Balancer to a Standard Public Load Balancer frontend or a VM IP configuration routes traffic to and from that endpoint through the gateway. The documented flow sends incoming traffic through the partner appliances before returning clean traffic to the backend. Microsoft Learn.
Applicability
Use this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application’s availability.
DSE recommendation
Accept the appliance path separately from enabling the network-layer protection service. Have the endpoint and appliance owners identify the frontend association and the expected ingress and return path. Record the NVA capacity, health and maintenance requirements that must be validated for the chosen product. Keep the claim of application-layer inspection tied to appliance evidence, not to the presence of a DDoS protection plan alone. Do not generate attack traffic outside an explicitly authorized validation arrangement.
Verification
Use approved benign application traffic to trace the service chain and correlate endpoint, gateway and appliance observations. Exercise the planned appliance-failure scenario only in its approved test scope. Verify that the application path and intended inspection remain consistent with the design. Record any bypass or missing appliance evidence before representing the endpoint as having validated inline inspection.
Official references
Microsoft Learn: Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs.
Review the official source
Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE