ACTIVE DDoS ATTACK - Azure DDoS IP Protection is mitigating traffic but legitimate users cannot connect

Alberto Cuello 0 Reputation points
2026-08-31T17:10:48.06+00:00

Hello,

I am currently experiencing an active DDoS attack against a production game server hosted on an Azure Virtual Machine.

I already have Azure DDoS IP Protection enabled on the affected Public IP address.

Azure Monitor confirms that the IP has been under DDoS attack. During the incident, I observed:

  • Under DDoS attack or not: 1
  • Inbound packets DDoS: approximately 78.48k packets/sec
  • Inbound packets forwarded DDoS: approximately 39.07k packets/sec
  • Inbound packets dropped DDoS: approximately 27.95k packets/sec
  • Inbound UDP packets to trigger DDoS mitigation: 20k packets/sec
  • Inbound SYN packets to trigger DDoS mitigation: 10k packets/sec

The problem is that even while Azure DDoS Protection is actively mitigating the attack, legitimate users are still experiencing severe latency, freezes, intermittent connection failures, and in some cases they cannot connect to the game server at all.

This is a production service and the attack appears to occur in waves.

I currently have an Azure Basic Support Plan, so the Azure portal does not allow me to submit a technical support request without purchasing a paid support plan.

I would appreciate assistance from a Microsoft Azure engineer or community support specialist in determining:

  1. Whether the current DDoS mitigation is operating correctly.
  2. Why legitimate connections are still being affected during mitigation.
  3. Whether this appears to be a UDP flood, SYN flood, TCP connection flood, or a combination of attack vectors.
  4. Whether the VM, NIC, Public IP, or network path may be reaching a limit during the attack.
  5. What Azure configuration changes I can make immediately to reduce the impact on legitimate users.
  6. Whether there is any way for this active DDoS incident to be escalated to Microsoft Support given that Azure DDoS IP Protection is already enabled and Azure itself is detecting the attack.

I can provide screenshots of Azure Monitor DDoS metrics, exact attack timestamps, NSG configuration, network metrics, and additional diagnostics if required.

Thank you.Hello,

I am currently experiencing an active DDoS attack against a production game server hosted on an Azure Virtual Machine.

I already have Azure DDoS IP Protection enabled on the affected Public IP address.

Azure Monitor confirms that the IP has been under DDoS attack. During the incident, I observed:

  • Under DDoS attack or not: 1
  • Inbound packets DDoS: approximately 78.48k packets/sec
  • Inbound packets forwarded DDoS: approximately 39.07k packets/sec
  • Inbound packets dropped DDoS: approximately 27.95k packets/sec
  • Inbound UDP packets to trigger DDoS mitigation: 20k packets/sec
  • Inbound SYN packets to trigger DDoS mitigation: 10k packets/sec

The problem is that even while Azure DDoS Protection is actively mitigating the attack, legitimate users are still experiencing severe latency, freezes, intermittent connection failures, and in some cases they cannot connect to the game server at all.

This is a production service and the attack appears to occur in waves.

I currently have an Azure Basic Support Plan, so the Azure portal does not allow me to submit a technical support request without purchasing a paid support plan.

I would appreciate assistance from a Microsoft Azure engineer or community support specialist in determining:

  1. Whether the current DDoS mitigation is operating correctly.
  2. Why legitimate connections are still being affected during mitigation.
  3. Whether this appears to be a UDP flood, SYN flood, TCP connection flood, or a combination of attack vectors.
  4. Whether the VM, NIC, Public IP, or network path may be reaching a limit during the attack.
  5. What Azure configuration changes I can make immediately to reduce the impact on legitimate users.
  6. Whether there is any way for this active DDoS incident to be escalated to Microsoft Support given that Azure DDoS IP Protection is already enabled and Azure itself is detecting the attack.

I can provide screenshots of Azure Monitor DDoS metrics, exact attack timestamps, NSG configuration, network metrics, and additional diagnostics if required.

Thank you.

Azure DDoS Protection
Azure DDoS Protection

An Azure service that provides defense against distributed denial-of-service (DDoS) attacks.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Vinodh247-1375 44,801 Reputation points Volunteer Moderator
    2026-09-01T00:21:22.9366667+00:00

    Yes, the metrics indicate that Azure DDoS IP Protection is detecting and mitigating attack traffic, but that does not necessarily mean legitimate users will be unaffected.

    Based on the values you've shared:

    • 78.48K packets/sec identified as DDoS traffic confirms the public IP is under attack.
    • 27.95K packets/sec dropped shows Azure is actively mitigating traffic.
    • 39.07K packets/sec forwarded indicates a significant volume of traffic is still reaching the VM.
    • The presence of both UDP and SYN mitigation thresholds being triggered suggests the attack may involve multiple vectors, potentially including UDP flood and TCP/SYN-based traffic.

    However, DDoS metrics alone are not sufficient to conclusively determine the exact attack composition.

    Azure DDoS Protection operates at the network edge and is designed to filter malicious traffic before it reaches your resources. However, traffic that is considered legitimate or cannot be confidently identified as malicious may still be forwarded.

    As a result, legitimate users can still be affected if any of the following become constrained during the attack:

    • VM CPU or memory resources
    • VM network packet-processing capacity
    • Guest OS TCP/UDP networking resources
    • Application connection handling limits
    • Game server thread pools, receive buffers, or connection backlogs

    A packet-rate-driven attack can create pressure on the VM even when overall bandwidth consumption appears relatively modest.

    Areas to investigate during the next attack wave:

    Review the following metrics during the attack and compare them with normal operating conditions:

    VM and network metrics

    • CPU utilisation
    • Memory utilisation
    • Network In / Network Out
    • Packet rates
    • Connection counts

    Guest OS and application metrics

    • TCP connection backlog
    • UDP receive errors or buffer exhaustion
    • Socket utilisation
    • Game-server process CPU and memory consumption
    • Active player and connection statistics

    Traffic analysis

    • NSG Flow Logs
    • Azure Network Watcher data
    • Source IP distribution
    • Destination ports and protocols
    • Traffic patterns that differ from normal gameplay activity

    I would recommend:

    1. Verify that only required game ports are exposed.
    2. Restrict administrative access (RDP/SSH) to trusted IPs, VPN, or Azure Bastion.
    3. Remove any unnecessary Internet-facing endpoints.
    4. Confirm the VM size provides sufficient packet-processing capability for the workload.
    5. Review NSG rules to ensure only required protocols and ports are allowed.
    6. Implement application-level rate limiting or connection throttling where supported by the game platform.
    Question Assessment
    Is DDoS mitigation operating correctly? Based on the dropped-packet metrics, mitigation appears to be active and functioning.
    Why are legitimate users affected? Likely because a substantial volume of traffic is still reaching the VM and causing resource pressure at the VM, OS, or application layer.
    Is this UDP, SYN, or another attack type? The metrics suggest multiple vectors may be involved, but the data provided is insufficient to definitively classify the attack.
    Could a limit be reached on the VM, NIC, Public IP, or path? Yes. Packet-processing, connection-tracking, OS, or application limits can be reached even while DDoS mitigation is active.
    What should be checked immediately? VM resource metrics, network metrics, NSG Flow Logs, guest OS networking counters, and application-level connection statistics.

    I would not conclude from the information provided that Azure DDoS Protection is malfunctioning. The more important question is whether the forwarded traffic is causing resource exhaustion at the VM, operating system, or game-server layer.

    The most useful dataset to collect during the next attack wave is:

    DDoS metrics + VM metrics + NSG Flow Logs + guest OS network counters + game-server connection statistics

    Correlating these datasets should help identify whether the bottleneck is occurring at the Azure edge, VM networking layer, operating system, or within the game application itself.

    Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.

    Was this answer helpful?

    0 comments No comments

  2. Jose Benjamin Solis Nolasco 12,691 Reputation points Volunteer Moderator
    2026-08-31T18:41:35.6766667+00:00

    @Alberto Cuello I hope you are doing well,Your telemetry shows that DDoS mitigation has engaged correctly (Under DDoS attack: 1), and the platform is filtering spoofed packets. However, legitimate players are being impacted because the unmitigated portion of the flood exceeds what a single standalone VM and game process can handle.

    • Verify Accelerated Networking: Ensure Accelerated Networking (SR-IOV) is enabled on the VM's Network Interface (NIC). This bypasses the host virtualization switch, drastically increasing packet-handling capacity (PPS) and reducing CPU overhead from network processing.
    • Scale Up the VM Size Temporarily: Move the VM to a compute-optimized or network-optimized series (e.g., Fsv2, Edsv5, or Dsv5 with at least 8–16 vCPUs). Larger VM SKUs provide substantially higher allocated network bandwidth and PPS limits.
    • Strict NSG Filtering: In your Network Security Group (NSG), lock down all ports that are not strictly needed for gameplay (block management ports like SSH/RDP from 0.0.0.0/0, or restrict them to your specific admin IP).

    References:

    If this answer helped clarify the platform capabilities and save you troubleshooting time, please consider marking it as Accepted. This helps others in the community find similar solutions.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.