NAT Gateway is a fully managed service that securely routes internet traffic from a private virtual network with enterprise-grade performance and low latency.
Hello Yong Heng Khor (NCS),
Welcome to the Microsoft Q&A and thank you for posting your questions here.
I understand that your Azure vTAP captures only one direction of traffic when NAT Gateway is used.
Since the VM, NIC, vTAP configuration, monitoring appliance, workload, and security configuration remain unchanged, and only the outbound connectivity method changed, the evidence points toward an undocumented Azure Networking platform behavior or potential platform issue rather than a configuration problem. There is also no documented evidence that placing Azure Firewall between the VM subnet and NAT Gateway changes Virtual Network TAP mirroring behavior, and Microsoft does not identify Azure Firewall as a supported workaround for this scenario.
What you can do is to collect synchronized packet captures from both the source VM and the monitoring appliance, verify that bidirectional traffic reaches the VM while only one direction is mirrored, and since PCS is already on this, I will suggest you channel your case for Azure Networking Product Group investigation. Include the packet captures, UTC timestamps, Subscription ID, Region, VM NIC Resource ID, Virtual Network TAP Resource ID, and NAT Gateway Resource ID to enable backend validation of the Azure SDN datapath. This is currently the only reliable path to determine whether the behavior is an undocumented platform limitation or a product defect, as no documented configuration change resolves this scenario.
I hope this is helpful. Please! Do not hesitate to let me know if you have any other questions, steps or clarifications.
Please do not close the thread by upvoting and accepting the answer if any part of it is helpful.