Verify the Gateway Load Balancer service chain before claiming inline inspection

Does enabling Azure DDoS Protection alone demonstrate that traffic traverses a partner L7 appliance?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Does enabling Azure DDoS Protection alone demonstrate that traffic traverses a partner L7 appliance?

Potentially affected

Use this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application's availability.

DSE recommendation

Accept the appliance path separately from enabling the network-layer protection service.

Source facts

Microsoft’s inline design adds partner NVAs through Gateway Load Balancer, while Azure DDoS Protection supplies network-layer protection. Linking Gateway Load Balancer to a Standard Public Load Balancer frontend or a VM IP configuration routes traffic to and from that endpoint through the gateway. The documented flow sends incoming traffic through the partner appliances before returning clean traffic to the backend. Microsoft Learn.

Applicability

Use this architecture check for an approved Gateway Load Balancer and partner-NVA deployment. Confirm the actual supported appliance and endpoint combination. This article does not promise an attack-response time or a particular application’s availability.

DSE recommendation

Accept the appliance path separately from enabling the network-layer protection service. Have the endpoint and appliance owners identify the frontend association and the expected ingress and return path. Record the NVA capacity, health and maintenance requirements that must be validated for the chosen product. Keep the claim of application-layer inspection tied to appliance evidence, not to the presence of a DDoS protection plan alone. Do not generate attack traffic outside an explicitly authorized validation arrangement.

Verification

Use approved benign application traffic to trace the service chain and correlate endpoint, gateway and appliance observations. Exercise the planned appliance-failure scenario only in its approved test scope. Verify that the application path and intended inspection remain consistent with the design. Record any bypass or missing appliance evidence before representing the endpoint as having validated inline inspection.

Official references

Microsoft Learn: Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs.

Primary reference

Review the official source

Inline L7 DDoS Protection with Gateway Load Balancer and partner NVAs | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE