Busy Azure VMs moving 50 MB/s or more with accelerated networking turned off
What does ZopNight detect here?
Accelerated Networking lets an Azure VM's NIC bypass the host's virtual switch, cutting latency, jitter and CPU use. ZopNight flags running VMs whose NIC has it disabled and whose `Network In Total` or `Network Out Total` peaked at a rate of 50 MB/s or more in the last 30 days. The finding is a performance advisory with no saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-263 |
| Category | performance |
| Severity | low |
| Metric | Network In Total / Network Out Total |
| Threshold | peak of 50 MB/s sustained over a minute |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read · Microsoft.Network/networkInterfaces/read · Microsoft.Insights/Metrics/Read |
Where it applies
What the VM loses without Accelerated Networking
Without it, every packet a VM sends or receives passes through the virtual switch on the host, where policy is applied in software. Microsoft’s Accelerated Networking overview explains that enabling SR-IOV on supported sizes takes the host out of the data path, giving lower latency, higher packets per second, reduced jitter and lower CPU use for network processing. For a VM that pushes heavy traffic, that host overhead is paid on every packet.
Finding NICs with the feature off
az network nic list \ --query "[?enableAcceleratedNetworking==\`false\`].{nic:name, group:resourceGroup, vm:virtualMachine.id}" -o table
az monitor metrics list \ --resource /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Compute/virtualMachines/<vm> \ --metric "Network In Total" "Network Out Total" --aggregation Maximum --interval PT1M --offset 30dTo check whether a size supports it, query the SKU capability, as Microsoft documents:
az vm list-skus --location <region> --resource-type virtualMachines \ --query "[].{size:name, accel:capabilities[?name=='AcceleratedNetworkingEnabled'].value | [0]}" -o tableTraffic that makes the advisory worth raising
- The VM is running.
- ZopNight’s scan recorded accelerated networking as explicitly disabled on the VM’s NIC. If the setting could not be read, there is no finding.
- The highest one-minute total of
Network In TotalorNetwork Out Totalacross the 30-day window reaches 3,000,000,000 bytes, a sustained 50 MB/s for that minute. Either direction is enough.
Quiet VMs are not flagged even when the feature is off, because the benefit is small when there is little traffic to accelerate.
Where the rule does not help
If neither network metric is available, the rule says nothing. It does not check the VM size, so confirm support before changing anything: Microsoft lists most general-purpose and compute-optimized sizes with two or more vCPUs (four or more on sizes with hyperthreading), and notes that NC and NV sizes appear in the SKU output but do not support it.
Performance, not a price cut
The saving is $0 and the cost after the change equals the cost before. The value is lower latency and freed CPU on a VM that is already working hard. For VMs that are saturated on CPU rather than network, see Azure VM High CPU, Upsize Recommendation.
Turning Accelerated Networking on
- Confirm the VM size supports it with the
az vm list-skusquery above. - Stop and deallocate the VM:
az vm deallocate --resource-group <rg> --name <vm>. Microsoft states the feature cannot be enabled on a running VM. - Enable it on the NIC:
az network nic update --resource-group <rg> --name <nic> --accelerated-networking true. - Start the VM and watch network latency and CPU in Azure Monitor.