An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
As far as I'm aware, there is no Azure Virtual Network or Public IP setting that allows customers to enable out-of-order IP fragment reassembly for traffic destined to an NVA. The reassembly of fragmented packets is typically handled by the destination host or appliance, not by an Azure Public IP resource. Given your symptoms (fragmented UDP traffic over IPsec, missing later fragments, and packet ordering concerns), the usual mitigations are:
- Reduce packet size and adjust MTU/MSS values to avoid fragmentation where possible.
- Enable IPsec fragmentation handling features supported by the FortiGate platform.
- Validate whether UDP encapsulated traffic can be tuned to remain below the path MTU.
- Capture traffic on both sides of the tunnel to determine whether fragments are being dropped before reaching the NVA. (General troubleshooting suggestion.)
Based on the information provided, I am not aware of an Azure feature that can be enabled on a Standard SKU Public IP or NIC specifically to force fragment reordering or reassembly before delivery to the FortiGate NVA.
If Microsoft Support has already reviewed the case and no Azure configuration option was identified, the next step would likely be to investigate MTU/fragmentation behavior and FortiGate-specific handling of fragmented IPsec traffic rather than an Azure networking setting.
If this helps clarify the Azure side of the issue, please mark the answer as helpful or accepted so others troubleshooting fragmented IPsec traffic with NVAs can find it more easily.