# Validate VPN gateway traffic before committing the Basic public-IP migration

> Keeping the numerical IP address does not remove the validation and commit stages or the accompanying gateway SKU change.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:26+00:00
- Modified: 2026-09-10T02:11:17+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Keeping the numerical IP address does not remove the validation and commit stages or the accompanying gateway SKU change.

## Potentially affected

Eligible non-Basic-SKU VPN gateways using the documented Basic public-IP migration workflow.

## DSE recommendation

Validate actual tunnel traffic and the gateway change before the final migration commit.

## Article

## Source facts

The guided process preserves the gateway’s numerical IP address while moving it to a Standard public-IP resource. It also changes a non-AZ VPN gateway SKU to its AZ counterpart. Microsoft’s documented workflow excludes the Basic gateway SKU, which requires a different procedure.

Before committing, Microsoft directs operators to validate receiving and transmitting traffic. Abort is the rollback path before commitment. Without the final commit, the old Basic public-IP resource remains pending rather than being deleted. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto).

## Applicability

Confirm gateway and public-IP SKUs separately, migration eligibility, subnet capacity and any special legacy-DNS P2S requirements. Do not apply this workflow to a gateway solely because its public IP is Basic.

## DSE recommendation

DSE recommends defining traffic acceptance checks and rollback authority before starting. Review the accompanying gateway SKU transition with its owner. Do not treat retention of the IP address as proof that tunnels, routing and required client paths work. Keep the validation decision separate from the action that finalizes the migration.

## Verification

During an approved window, compare the gateway’s ingress and egress evidence with the agreed end-to-end connection tests. Resolve failures before committing and use the documented pre-commit abort path if required. After an approved commit, inspect the final resource and gateway state and preserve the receipt with traffic evidence. A resource left pending should remain an open migration item.

## Official references

[Microsoft Learn: How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway](https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto). Source retrieved September 9, 2026.

## Primary reference

- Name: How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway - Azure VPN Gateway | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Validate VPN gateway traffic before committing the Basic public-IP migration,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-510-validate-vpn-gateway-traffic-before-committing-the-basic-public-ip-migration/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
