Last updated on March 8, 2023
Azure DDoS Protection Cheat Sheet
- Allows you to protect your Azure resources from denial of service (DoS) attacks.
- DDoS protection (layers 3 and 4) offers two service tiers: Basic and Standard.
Features
- Basic
-
- Enabled by default (free).
- It mitigates common network attacks.
- Both basic and standard protects IPv4 and IPv6 public IP addresses.
- Standard
-
- It has advanced capabilities to protect you against network attacks such as logging, alerting, and telemetry.
- Mitigates the following attacks:
- Volumetric attacks – flood the network layer with attacks.
- Protocol attacks – exploit a weakness in layers 3 and 4.
- Resource layer attacks – a layer 7 attack that disrupts the transmission of data between hosts.
- Enables you to configure alerts at the start and stop of an attack.
- The metric data is retained for 30 days.
- Provides autotuned mitigation policies (TCP/TCP SYN/UDP) for each public IP.
Feature |
Basic |
Standard |
Active traffic monitoring & always-on detection |
Yes |
Yes |
Automatic attack mitigations |
Yes |
Yes |
Availability guarantee |
Azure Region |
Application |
Mitigation policies |
Tuned for Azure traffic region volume |
Tuned for application traffic volume |
Metrics & alerts |
No |
Real-time attack metrics and resource logs via Azure Monitor |
Mitigation reports |
No |
Post attack mitigation reports |
Mitigation flow logs |
No |
NRT log stream for SIEM integration |
Mitigation policy customization |
No |
Engage DDoS Experts |
Azure DDoS Protection Pricing
- Basic DDoS Protection provides protection at no additional charge.
- Standard DDoS Protection is a paid service. You are charged for the processed data every month (per GB).
How to Defend Against Denial of Service Attacks with Azure DDoS Protection
Want to learn more about Azure? Watch the official Microsoft Azure YouTube channel’s video series called Azure Tips and Tricks.
Azure DDoS Protection Cheat Sheet References:
https://azure.microsoft.com/en-us/services/ddos-protection/
https://docs.microsoft.com/en-us/azure/virtual-network/ddos-protection-overview
https://docs.microsoft.com/en-us/azure/security/fundamentals/ddos-best-practices