Standard Load Balancer frontend IP in 20.203.0.0/17 (UAE North) partially unreachable from the internet on 6 Oct 2026
Setup
- Standard Load Balancer (Regional), UAE North
- Frontend: Standard static IPv4 public IP in 20.203.0.0/17 (no zones)
- Rules: TCP 80 and TCP 443 to a backend VM
Problem
From around 11:30–12:15 UTC on 6 Oct 2026, the frontend IP was unreachable from many internet locations. Connections either timed out or failed with "No route to host". Other public IPs in the same subscription and region, in 20.160.0.0/12, were reachable from everywhere.
The load balancer and backend look healthy
- Health Probe Status and Data Path Availability have stayed at 100%.
- Resource Health shows "Available", and the built-in Load Balancer diagnostics report no issues.
- From VMs in the same VNet, requests to the frontend IP on ports 80 and 443 succeeded (HTTP 200).
- No UDRs or firewall appliances in the path; effective routes are all system defaults.
- NSG and host firewall were ruled out: the same NSG is used by the backends of a second LB in the same region, which works from everywhere.
External tests (6 Oct, UTC)
- TCP 443 from a public multi-location checker: 7 of 15 locations connected. The rest timed out or returned "No route to host".
- At the same time, an IP in 20.160.0.0/12 in the same region connected from 15 of 15 locations.
- A second Standard LB in the same region, with a frontend IP in 20.160.0.0/12, connected from 10 of 10 locations. The affected IP failed from 4 of those same 10.
- A traceroute from an Asian ISP looped inside a transit provider (Cogent, AS174) and never reached Microsoft. From the same source, the path to the 20.160.0.0/12 IP went directly to Microsoft's network.
- Other Microsoft UAE North IPs in 20.46.32.0/19 and 40.123.192.0/19 failed the same way from the same source.
Public routing data (RIPE RIS)
- 20.203.0.0/17, 20.46.32.0/19 and 40.123.192.0/19 are originated by AS8075. Most monitored paths (about 158 of 192) reach AS8075 via AS8529 (Omantel); the rest go via a few other carriers.
- 20.160.0.0/12 is reached through many different upstreams.
- BGP updates for 20.203.0.0/17: 15 on 4 Oct, 21 on 5 Oct, 2,496 on 6 Oct. . 20.160.0.0/12 had 72 updates over 5–6 Oct.
Mitigation
Traffic has been moved to a second Standard LB with a frontend IP in 20.160.0.0/12, which is reachable everywhere.
Questions
- Was there a known routing or edge issue affecting UAE North prefixes 20.203.123.192.0/19 on 6 Oct 2026, for example on the Omantel (AS8529) path?
- Is it safe to keep using public IPs from 20.203.0.0/17, or is it better to allocate them from another range?
- Is there a way to choose or influence which prefix a new Standard public IP