How to enable/configure Basic DDOS Protection

Brent Long 1 Reputation point
2024-07-11T23:18:52.5466667+00:00

An Azure support chat agent stated that all Public IP addresses have Basic DDOS protection available at no extra cost, but it must be enabled. When I follow tutorial at https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-ip-protection-portal, my portal does not show the DDOS Protection configuration section under properties.

My Public IP is Basic SKU, Regional Tier and Dynamic (meaning it wasn't allocated until it was associated to the VM). It is currently allocated to a VM.

  1. Is it true that there is a Basic DDOS protection available for Public IP Addresses at no extra cost?
  2. If so, is it automatically enabled now, meaning the documentation is out of date?
  3. Is the tutorial provided by the agent only for the $200/IP/month Standard DDOS Protection option?
Azure DDos Protection
Azure DDos Protection
An Azure service that provides defense against distributed denial-of-service (DDoS) attacks.
68 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Silvia Wibowo 3,491 Reputation points Microsoft Employee
    2024-07-12T01:53:26.1066667+00:00

    Hi @Brent Long , I understand that you have questions regarding DDoS protection in Azure.

    Answering your question:

    1. If you have DDoS Network Protection, you need to register your virtual networks into the DDoS protection. After that, all of your Public IP addresses in those virtual networks are protected, including Public IP Basic SKU. There is cost for DDoS Network Protection - see "Network Protection" from this page: https://azure.microsoft.com/en-us/pricing/details/ddos-protection/
    2. Documentation is not out of date.
    3. DDoS IP Protection does not support Public IP Basic SKU. You need to use Public IP Standard SKU if you want to enable DDoS IP Protection.

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    0 comments No comments

  2. KapilAnanth-MSFT 40,336 Reputation points Microsoft Employee
    2024-07-15T08:21:29.6233333+00:00

    @Brent Long ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    Azure DDOS has two tiers,

    • DDoS Network Protection - Protects upto 100 IP Addresses at fixed cost and additional IPs are charged extra
    • DDoS IP Protection - Protects individual IP Address at fixed cost

    There is no explicit tier called "Basic" tier. What actually happens is,

    Services running on Azure are inherently protected by the default infrastructure-level DDoS protection. However, the protection that safeguards the infrastructure has a much higher threshold than most applications have the capacity to handle, and does not provide telemetry or alerting, so while a traffic volume may be perceived as harmless by the platform, it can be devastating to the application that receives it.

    2.If so, is it automatically enabled now, meaning the documentation is out of date?

    • As mentioned, the infrastructure-level DDoS protection comes into picture

    3.Is the tutorial provided by the agent only for the $200/IP/month Standard DDOS Protection option?

    NOTE:

    As mentioned by , Basic Public IP is not covered by "DDoS IP Protection"

    • See : DDOS Limitations
    • This means, you have to either upgrade your Public IP to Standard SKU
    • or use DDoS Network Protection (which is comparatively costlier)

    I would greatly appreciate if you could Accept the answer and close this thread

    Original posters help the community find answers faster by identifying the correct answer.

    Cheers,

    Kapil@Brent Long ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    Azure DDOS has two tiers,

    • DDoS Network Protection - Protects upto 100 IP Addresses at fixed cost and additional IPs are charged extra
    • DDoS IP Protection - Protects individual IP Address at fixed cost

    There is no explicit tier called "Basic" tier. What actually happens is,

    Services running on Azure are inherently protected by the default infrastructure-level DDoS protection. However, the protection that safeguards the infrastructure has a much higher threshold than most applications have the capacity to handle, and does not provide telemetry or alerting, so while a traffic volume may be perceived as harmless by the platform, it can be devastating to the application that receives it.

    2.If so, is it automatically enabled now, meaning the documentation is out of date?

    • As mentioned, the infrastructure-level DDoS protection comes into picture

    3.Is the tutorial provided by the agent only for the $200/IP/month Standard DDOS Protection option?

    NOTE:

    As mentioned by , Basic Public IP is not covered by "DDoS IP Protection"

    • See : DDOS Limitations
    • This means, you have to either upgrade your Public IP to Standard SKU
    • or use DDoS Network Protection (which is comparatively costlier)

    I would greatly appreciate if you could Accept the answer and close this thread

    Original posters help the community find answers faster by identifying the correct answer.

    Cheers,

    Kapil

    0 comments No comments