Skip to main content

Azure DDoS Protection

Azure DDoS Protection defends public endpoints against distributed denial-of-service (DDoS) attacks. Every Azure public IP has the default infrastructure protection; the Azure Enterprise Baseline can add a DDoS Network Protection plan for its virtual networks with one switch, off by default.

What it does​

Without any configuration, Azure's infrastructure protection absorbs large network-layer floods at the edge for every public IP. A DDoS Network Protection plan adds protection tuned to the traffic of each protected public IP: adaptive thresholds, attack metrics and alerts, mitigation reports, cost protection for resources that scale out during an attack, and access to the DDoS Rapid Response team. One plan can cover virtual networks in any subscription of the tenant; it protects the public IPs of resources in the virtual networks associated with it, and it is billed per plan plus per public IP above the included 100.

How BuiltForProd uses it​

The switch is in environments/core/security/security.hcl:

Azure/acme-azure-platform-baseline/environments/core/security/security.hcl (lines 43-43)
enable_ddos_protection = false # @optional: DDoS Network Protection plan ($2,944/month, 100 public IPs)

When it is true:

  1. The ddos-plan unit in acme-core-security creates the resource group acme-eus2-security-ddos-rg and the plan acme-eus2-security-ddos-plan (modules/ddos-protection-plan).
  2. The virtual network units read the same switch, gain a dependency on the plan and associate their networks with it: the hub (vnet-hub, acme-core-network), every stage spoke (vnet-spoke) and the runner network (vnet-runner, acme-core-auto).

When it is false, the plan unit creates nothing and the virtual networks have no dependency on it, so the switch costs nothing while off.

The web application's public entry is Azure Front Door, whose global edge carries its own network-layer DDoS protection in front of the origins; the Front Door web application firewall adds a rate limit per client at the application layer. The plan matters for public IPs that sit inside the virtual networks themselves.

Cost: the module comment lists $2,944 per month for the plan, including 100 public IPs, and $29.50 per additional IP, as list prices.

Terms you will see​

TermMeaning
Infrastructure protectionThe default, always-on DDoS defense of every Azure public IP.
DDoS Network ProtectionThe paid plan with tuned mitigation, telemetry, cost protection and support.
Protection planThe resource that virtual networks associate with, one per tenant here.
Protected public IPA public IP in an associated virtual network; 100 are included in the plan.
enable_ddos_protectionThe security.hcl switch both the plan and the network units read.

Where to read more​