Skip to content

Commit a83000e

Browse files
Merge pull request #238980 from AbdullahBell/patch-71
DDoS Protection: SKU Article Updated limitations - added note.
2 parents d68d9f9 + b0134f4 commit a83000e

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

articles/ddos-protection/ddos-protection-sku-comparison.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ author: AbdullahBell
55
ms.author: Abell
66
ms.service: ddos-protection
77
ms.topic: conceptual
8-
ms.date: 05/11/2023
8+
ms.date: 05/23/2023
99
ms.custom: template-concept, ignite-2022
1010
---
1111

@@ -59,7 +59,6 @@ DDoS Network Protection and DDoS IP Protection have the following limitations:
5959
- PaaS services (multi-tenant), which includes Azure App Service Environment for Power Apps, Azure API Management in deployment modes other than APIM with virtual network integration (For more informaiton see https://techcommunity.microsoft.com/t5/azure-network-security-blog/azure-ddos-standard-protection-now-supports-apim-in-vnet/ba-p/3641671), and Azure Virtual WAN aren't currently supported.
6060
- Protecting a public IP resource attached to a NAT Gateway isn't supported.
6161
- Virtual machines in Classic/RDFE deployments aren't supported.
62-
- Scenarios in which a single VM is running behind a public IP is not recommended. For more information, see [Fundamental best practices](./fundamental-best-practices.md#design-for-scalability)
6362
- VPN gateway or Virtual network gateway is protected by a fixed DDoS policy. Adaptive tuning is not supported at this stage.
6463
- Disabling DDoS protection for a public IP address is currently a preview feature. If you disable DDoS protection for a public IP resource that is linked to a virtual network with an active DDoS protection plan, you will still be billed for DDoS Network Protection. However, the following functionalities will be suspended: mitigation of DDoS attacks, telemetry, and logging of DDoS mitigation events.
6564
- Partially supported: the Azure DDoS Protection service can protect a public load balancer with a public IP address prefix linked to its frontend. It effectively detects and mitigates DDoS attacks. However, telemetry and logging for the protected public IP addresses within the prefix range are currently unavailable.
@@ -69,6 +68,8 @@ DDoS IP Protection is similar to Network Protection, but has the following addit
6968

7069
- Public IP Basic SKU protection isn't supported.
7170

71+
>[!Note]
72+
>Scenarios in which a single VM is running behind a public IP is supported, but not recommended. For more information, see [Fundamental best practices](./fundamental-best-practices.md#design-for-scalability).
7273
7374
For more information, see [Azure DDoS Protection reference architectures](./ddos-protection-reference-architectures.md).
7475

0 commit comments

Comments
 (0)