Azure vTAP captures only one direction of traffic when NAT Gateway is used

Bigfour 0 Reputation points
2026-07-20T15:08:17.8566667+00:00

We are running a POC using Azure Virtual Network TAP to mirror traffic from a VM NIC to an NDR sensor.

Observed behaviour:

  • When the VM uses a directly assigned Public IP, the sensor receives bidirectional TCP traffic.

When the same VM uses an Azure NAT Gateway for internet access, the sensor receives only one direction of the TCP session.

The application connection itself is successful.

Packet capture on the source VM confirms that both outbound and return traffic reach the VM.

The VM, NIC, vTAP configuration, destination sensor, test traffic, and security rules remain unchanged. The only change is the outbound connectivity method.

Architecture:

VM NIC with vTAP → Azure Firewall, if applicable → NAT Gateway → Internet

Please confirm:

  1. Is Azure vTAP expected to mirror both outbound and return traffic when the source VM uses NAT Gateway?
  2. Are there any known limitations involving vTAP, NAT Gateway, SNAT, accelerated networking, or the Azure fast path?
  3. Would placing Azure Firewall between the VM subnet and NAT Gateway change the vTAP mirroring behaviour?
  4. Is this a known issue or expected platform behaviour?
  5. Are there any recommended configuration changes or supported workarounds?
Azure NAT Gateway
Azure NAT Gateway

NAT Gateway is a fully managed service that securely routes internet traffic from a private virtual network with enterprise-grade performance and low latency.


1 answer

Sort by: Most helpful
  1. Sina Salam 31,456 Reputation points Volunteer Moderator
    2026-07-21T10:41:04.8166667+00:00

    Hello Yong Heng Khor (NCS),

    Welcome to the Microsoft Q&A and thank you for posting your questions here.

    I understand that your Azure vTAP captures only one direction of traffic when NAT Gateway is used.

    Since the VM, NIC, vTAP configuration, monitoring appliance, workload, and security configuration remain unchanged, and only the outbound connectivity method changed, the evidence points toward an undocumented Azure Networking platform behavior or potential platform issue rather than a configuration problem. There is also no documented evidence that placing Azure Firewall between the VM subnet and NAT Gateway changes Virtual Network TAP mirroring behavior, and Microsoft does not identify Azure Firewall as a supported workaround for this scenario.

    What you can do is to collect synchronized packet captures from both the source VM and the monitoring appliance, verify that bidirectional traffic reaches the VM while only one direction is mirrored, and since PCS is already on this, I will suggest you channel your case for Azure Networking Product Group investigation. Include the packet captures, UTC timestamps, Subscription ID, Region, VM NIC Resource ID, Virtual Network TAP Resource ID, and NAT Gateway Resource ID to enable backend validation of the Azure SDN datapath. This is currently the only reliable path to determine whether the behavior is an undocumented platform limitation or a product defect, as no documented configuration change resolves this scenario.

    I hope this is helpful. Please! Do not hesitate to let me know if you have any other questions, steps or clarifications.


    Please do not close the thread by upvoting and accepting the answer if any part of it is helpful.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.