An Azure service that provides defense against distributed denial-of-service (DDoS) attacks.
Yes, the metrics indicate that Azure DDoS IP Protection is detecting and mitigating attack traffic, but that does not necessarily mean legitimate users will be unaffected.
Based on the values you've shared:
- 78.48K packets/sec identified as DDoS traffic confirms the public IP is under attack.
- 27.95K packets/sec dropped shows Azure is actively mitigating traffic.
- 39.07K packets/sec forwarded indicates a significant volume of traffic is still reaching the VM.
- The presence of both UDP and SYN mitigation thresholds being triggered suggests the attack may involve multiple vectors, potentially including UDP flood and TCP/SYN-based traffic.
However, DDoS metrics alone are not sufficient to conclusively determine the exact attack composition.
Azure DDoS Protection operates at the network edge and is designed to filter malicious traffic before it reaches your resources. However, traffic that is considered legitimate or cannot be confidently identified as malicious may still be forwarded.
As a result, legitimate users can still be affected if any of the following become constrained during the attack:
- VM CPU or memory resources
- VM network packet-processing capacity
- Guest OS TCP/UDP networking resources
- Application connection handling limits
- Game server thread pools, receive buffers, or connection backlogs
A packet-rate-driven attack can create pressure on the VM even when overall bandwidth consumption appears relatively modest.
Areas to investigate during the next attack wave:
Review the following metrics during the attack and compare them with normal operating conditions:
VM and network metrics
- CPU utilisation
- Memory utilisation
- Network In / Network Out
- Packet rates
- Connection counts
Guest OS and application metrics
- TCP connection backlog
- UDP receive errors or buffer exhaustion
- Socket utilisation
- Game-server process CPU and memory consumption
- Active player and connection statistics
Traffic analysis
- NSG Flow Logs
- Azure Network Watcher data
- Source IP distribution
- Destination ports and protocols
- Traffic patterns that differ from normal gameplay activity
I would recommend:
- Verify that only required game ports are exposed.
- Restrict administrative access (RDP/SSH) to trusted IPs, VPN, or Azure Bastion.
- Remove any unnecessary Internet-facing endpoints.
- Confirm the VM size provides sufficient packet-processing capability for the workload.
- Review NSG rules to ensure only required protocols and ports are allowed.
- Implement application-level rate limiting or connection throttling where supported by the game platform.
| Question | Assessment |
| Is DDoS mitigation operating correctly? | Based on the dropped-packet metrics, mitigation appears to be active and functioning. |
| Why are legitimate users affected? | Likely because a substantial volume of traffic is still reaching the VM and causing resource pressure at the VM, OS, or application layer. |
| Is this UDP, SYN, or another attack type? | The metrics suggest multiple vectors may be involved, but the data provided is insufficient to definitively classify the attack. |
| Could a limit be reached on the VM, NIC, Public IP, or path? | Yes. Packet-processing, connection-tracking, OS, or application limits can be reached even while DDoS mitigation is active. |
| What should be checked immediately? | VM resource metrics, network metrics, NSG Flow Logs, guest OS networking counters, and application-level connection statistics. |
I would not conclude from the information provided that Azure DDoS Protection is malfunctioning. The more important question is whether the forwarded traffic is causing resource exhaustion at the VM, operating system, or game-server layer.
The most useful dataset to collect during the next attack wave is:
DDoS metrics + VM metrics + NSG Flow Logs + guest OS network counters + game-server connection statistics
Correlating these datasets should help identify whether the bottleneck is occurring at the Azure edge, VM networking layer, operating system, or within the game application itself.
Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.