{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/",
        "slug": "dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/"
        },
        "title": "Give each SDN appliance adapter an explicit management or traffic role",
        "summary": "Which interface bindings should be reviewed when deploying a multi-adapter network virtual appliance?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:14:50+00:00",
        "modified_at": "2026-09-08T18:23:27+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 197,
        "potentially_affected": "Administrators attaching network virtual appliances to SDN tenant networks.",
        "dse_recommendation": "Prepare an interface table showing every adapter, controller object, host binding, subnet, and intended role.",
        "primary_source": {
            "name": "Use network virtual appliances on a virtual network",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Use-Network-Virtual-Appliances-on-a-VN",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft describes network appliances used for user-defined routing and port mirroring in tenant virtual networks. User-defined routing can place an appliance in the routing path between virtual subnets. For appliances with multiple adapters, Microsoft requires each interface to be created in Network Controller and the corresponding interface IDs assigned on the hosts. The source distinguishes a management adapter from adapters processing traffic. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Use-Network-Virtual-Appliances-on-a-VN\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the appliance’s documented adapter requirements, management network, data subnets, and forwarding purpose. Review the supported appliance deployment and the actual SDN resource identities before adapting the example.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare an interface table showing every adapter, controller object, host binding, subnet, and intended role. Have the appliance and SDN owners review the table together. Explicitly identify the management path that should remain available during a forwarding or inspection test.</p>\n<h2>Verification</h2>\n<p>Verify each binding and test management separately from the intended data path. Exercise allowed and excluded routes or mirrored traffic according to the approved design. Record the actual path observed and investigate an unbound adapter or unexpected bypass before accepting the appliance deployment.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Use-Network-Virtual-Appliances-on-a-VN\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use network virtual appliances on a virtual network</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft describes network appliances used for user-defined routing and port mirroring in tenant virtual networks. User-defined routing can place an appliance in the routing path between virtual subnets. For appliances with multiple adapters, Microsoft requires each interface to be created in Network Controller and the corresponding interface IDs assigned on the hosts. The source distinguishes a management adapter from adapters processing traffic. Microsoft documentation.\nApplicability\nIdentify the appliance’s documented adapter requirements, management network, data subnets, and forwarding purpose. Review the supported appliance deployment and the actual SDN resource identities before adapting the example.\nDSE recommendation\nPrepare an interface table showing every adapter, controller object, host binding, subnet, and intended role. Have the appliance and SDN owners review the table together. Explicitly identify the management path that should remain available during a forwarding or inspection test.\nVerification\nVerify each binding and test management separately from the intended data path. Exercise allowed and excluded routes or mirrored traffic according to the approved design. Record the actual path observed and investigate an unbound adapter or unexpected bypass before accepting the appliance deployment.\nOfficial references\nMicrosoft Learn: Use network virtual appliances on a virtual network. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft describes network appliances used for user-defined routing and port mirroring in tenant virtual networks. User-defined routing can place an appliance in the routing path between virtual subnets. For appliances with multiple adapters, Microsoft requires each interface to be created in Network Controller and the corresponding interface IDs assigned on the hosts. The source distinguishes a management adapter from adapters processing traffic. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Use-Network-Virtual-Appliances-on-a-VN).\n\n## Applicability\n\nIdentify the appliance’s documented adapter requirements, management network, data subnets, and forwarding purpose. Review the supported appliance deployment and the actual SDN resource identities before adapting the example.\n\n## DSE recommendation\n\nPrepare an interface table showing every adapter, controller object, host binding, subnet, and intended role. Have the appliance and SDN owners review the table together. Explicitly identify the management path that should remain available during a forwarding or inspection test.\n\n## Verification\n\nVerify each binding and test management separately from the intended data path. Exercise allowed and excluded routes or mirrored traffic according to the approved design. Record the actual path observed and investigate an unbound adapter or unexpected bypass before accepting the appliance deployment.\n\n## Official references\n\n[Microsoft Learn: Use network virtual appliances on a virtual network](https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Use-Network-Virtual-Appliances-on-a-VN). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Give each SDN appliance adapter an explicit management or traffic role",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/",
                "headline": "Give each SDN appliance adapter an explicit management or traffic role",
                "description": "Which interface bindings should be reviewed when deploying a multi-adapter network virtual appliance?",
                "abstract": "Which interface bindings should be reviewed when deploying a multi-adapter network virtual appliance?",
                "articleBody": "Source facts\nMicrosoft describes network appliances used for user-defined routing and port mirroring in tenant virtual networks. User-defined routing can place an appliance in the routing path between virtual subnets. For appliances with multiple adapters, Microsoft requires each interface to be created in Network Controller and the corresponding interface IDs assigned on the hosts. The source distinguishes a management adapter from adapters processing traffic. Microsoft documentation.\nApplicability\nIdentify the appliance’s documented adapter requirements, management network, data subnets, and forwarding purpose. Review the supported appliance deployment and the actual SDN resource identities before adapting the example.\nDSE recommendation\nPrepare an interface table showing every adapter, controller object, host binding, subnet, and intended role. Have the appliance and SDN owners review the table together. Explicitly identify the management path that should remain available during a forwarding or inspection test.\nVerification\nVerify each binding and test management separately from the intended data path. Exercise allowed and excluded routes or mirrored traffic according to the approved design. Record the actual path observed and investigate an unbound adapter or unexpected bypass before accepting the appliance deployment.\nOfficial references\nMicrosoft Learn: Use network virtual appliances on a virtual network. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:14:50+00:00",
                "dateModified": "2026-09-08T18:23:27+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-141-give-each-sdn-appliance-adapter-an-explicit-management-or-traffic-role/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Give each SDN appliance adapter an explicit management or traffic role"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 197,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use network virtual appliances on a virtual network",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Use-Network-Virtual-Appliances-on-a-VN"
                }
            }
        ]
    }
}