Hello,
I am currently experiencing an active DDoS attack against a production game server hosted on an Azure Virtual Machine.
I already have Azure DDoS IP Protection enabled on the affected Public IP address.
Azure Monitor confirms that the IP has been under DDoS attack. During the incident, I observed:
- Under DDoS attack or not: 1
- Inbound packets DDoS: approximately 78.48k packets/sec
- Inbound packets forwarded DDoS: approximately 39.07k packets/sec
- Inbound packets dropped DDoS: approximately 27.95k packets/sec
- Inbound UDP packets to trigger DDoS mitigation: 20k packets/sec
- Inbound SYN packets to trigger DDoS mitigation: 10k packets/sec
The problem is that even while Azure DDoS Protection is actively mitigating the attack, legitimate users are still experiencing severe latency, freezes, intermittent connection failures, and in some cases they cannot connect to the game server at all.
This is a production service and the attack appears to occur in waves.
I currently have an Azure Basic Support Plan, so the Azure portal does not allow me to submit a technical support request without purchasing a paid support plan.
I would appreciate assistance from a Microsoft Azure engineer or community support specialist in determining:
- Whether the current DDoS mitigation is operating correctly.
- Why legitimate connections are still being affected during mitigation.
- Whether this appears to be a UDP flood, SYN flood, TCP connection flood, or a combination of attack vectors.
- Whether the VM, NIC, Public IP, or network path may be reaching a limit during the attack.
- What Azure configuration changes I can make immediately to reduce the impact on legitimate users.
- Whether there is any way for this active DDoS incident to be escalated to Microsoft Support given that Azure DDoS IP Protection is already enabled and Azure itself is detecting the attack.
I can provide screenshots of Azure Monitor DDoS metrics, exact attack timestamps, NSG configuration, network metrics, and additional diagnostics if required.
Thank you.Hello,
I am currently experiencing an active DDoS attack against a production game server hosted on an Azure Virtual Machine.
I already have Azure DDoS IP Protection enabled on the affected Public IP address.
Azure Monitor confirms that the IP has been under DDoS attack. During the incident, I observed:
- Under DDoS attack or not: 1
- Inbound packets DDoS: approximately 78.48k packets/sec
- Inbound packets forwarded DDoS: approximately 39.07k packets/sec
- Inbound packets dropped DDoS: approximately 27.95k packets/sec
- Inbound UDP packets to trigger DDoS mitigation: 20k packets/sec
- Inbound SYN packets to trigger DDoS mitigation: 10k packets/sec
The problem is that even while Azure DDoS Protection is actively mitigating the attack, legitimate users are still experiencing severe latency, freezes, intermittent connection failures, and in some cases they cannot connect to the game server at all.
This is a production service and the attack appears to occur in waves.
I currently have an Azure Basic Support Plan, so the Azure portal does not allow me to submit a technical support request without purchasing a paid support plan.
I would appreciate assistance from a Microsoft Azure engineer or community support specialist in determining:
- Whether the current DDoS mitigation is operating correctly.
- Why legitimate connections are still being affected during mitigation.
- Whether this appears to be a UDP flood, SYN flood, TCP connection flood, or a combination of attack vectors.
- Whether the VM, NIC, Public IP, or network path may be reaching a limit during the attack.
- What Azure configuration changes I can make immediately to reduce the impact on legitimate users.
- Whether there is any way for this active DDoS incident to be escalated to Microsoft Support given that Azure DDoS IP Protection is already enabled and Azure itself is detecting the attack.
I can provide screenshots of Azure Monitor DDoS metrics, exact attack timestamps, NSG configuration, network metrics, and additional diagnostics if required.
Thank you.