Review Virtual Network DDoS protection plans

Review DDoS coverage and the need for an additional protection plan against the availability requirements of public services.

Description

Azure provides basic infrastructure DDoS protection, so the absence of a separate Virtual Network protection plan does not mean all DDoS defenses are absent. For important internet-facing services, assess the required coverage and response capabilities, then consider DDoS Network Protection or DDoS IP Protection for individual public IP addresses.

DDoS protection primarily mitigates network-layer attacks. It does not replace access controls or a WAF for application-layer attacks.

Potential impact

  • Inadequate protection for the service’s requirements can leave it exposed to delays or outages during large attacks.
  • Missing monitoring and response capabilities can delay identification and recovery.

Remediation

  • Assess public IPs, availability requirements, existing protection and costs before choosing additional protection.
  • To use VNet-level DDoS Network Protection, set the plan ID and enable = true in ddos_protection_plan. If using individual IP protection, verify its application to the actual IP address.
  • Verify coverage, alerts and response procedures, and retain other required controls such as NSGs and WAFs.

Examples

These excerpts require a separately prepared resource group and protection plan. The VNet’s private address range alone does not establish the protection of public IPs or services.

Before

hcl
resource "azurerm_virtual_network" "example" {
  name                = "virtualNetwork1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  address_space       = ["10.0.0.0/16"]
}

After

hcl
resource "azurerm_virtual_network" "example" {
  name                = "virtualNetwork1"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  address_space       = ["10.0.0.0/16"]

  ddos_protection_plan {
    id     = azurerm_network_ddos_protection_plan.example.id
    enable = true
  }
}

Explanation:

  • Before: No DDoS protection plan is associated with the VNet. This does not establish an absence of basic or individual IP protection.
  • After: The prepared DDoS protection plan is associated with the VNet. Verify coverage for the actual public IPs as well.

References