{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/",
        "slug": "dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/"
        },
        "title": "Separate SDN gateway capacity from tunnel throughput limits",
        "summary": "How should SDN gateway capacity be interpreted when planning tunnel bandwidth?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:14:20+00:00",
        "modified_at": "2026-09-08T18:26:31+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Administrators sizing Windows Server SDN gateway tunnels.",
        "dse_recommendation": "Build a capacity worksheet that names each tunnel, its traffic requirement, configured allocation, and the applicable documented calculation.",
        "primary_source": {
            "name": "Gateway bandwidth allocation",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/sdn/gateway-allocation",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>The 2016 model allocates tunnel bandwidth using ratios of the configured gateway capacity. For the 2019 model, Microsoft describes fixed maximum throughput for each tunnel type; a faster gateway network adapter does not remove that tunnel limit. IPsec defaults to the older allocation behavior; the documented transition requires enabling the gateway service and restarting the gateway VM. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/sdn/gateway-allocation\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Record the active allocation behavior, tunnel type, gateway service state, and pool upgrade state, not just the server version. Consult the documented transition conditions before selecting a calculation. Keep product ceilings separate from measured throughput, and schedule any required restart through the change process.</p>\n<h2>DSE recommendation</h2>\n<p>Build a capacity worksheet that names each tunnel, its traffic requirement, configured allocation, and the applicable documented calculation. Ask the network owner to identify concurrent workloads and the acceptable behavior under contention. Avoid filling the gateway-capacity field with an arbitrary large value to make the worksheet appear sufficient. Have the application owner approve a realistic test load and observation period.</p>\n<h2>Verification</h2>\n<p>Measure traffic through the actual tunnel type while recording gateway resources and simultaneous traffic. Compare observed throughput with the allocation worksheet and investigate the limiting component. Repeat the relevant condition with the planned concurrency. Record both the measured result and the product-model assumption so later version changes trigger a fresh review.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/sdn/gateway-allocation\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Gateway bandwidth allocation</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nThe 2016 model allocates tunnel bandwidth using ratios of the configured gateway capacity. For the 2019 model, Microsoft describes fixed maximum throughput for each tunnel type; a faster gateway network adapter does not remove that tunnel limit. IPsec defaults to the older allocation behavior; the documented transition requires enabling the gateway service and restarting the gateway VM. Microsoft Learn.\nApplicability\nRecord the active allocation behavior, tunnel type, gateway service state, and pool upgrade state, not just the server version. Consult the documented transition conditions before selecting a calculation. Keep product ceilings separate from measured throughput, and schedule any required restart through the change process.\nDSE recommendation\nBuild a capacity worksheet that names each tunnel, its traffic requirement, configured allocation, and the applicable documented calculation. Ask the network owner to identify concurrent workloads and the acceptable behavior under contention. Avoid filling the gateway-capacity field with an arbitrary large value to make the worksheet appear sufficient. Have the application owner approve a realistic test load and observation period.\nVerification\nMeasure traffic through the actual tunnel type while recording gateway resources and simultaneous traffic. Compare observed throughput with the allocation worksheet and investigate the limiting component. Repeat the relevant condition with the planned concurrency. Record both the measured result and the product-model assumption so later version changes trigger a fresh review.\nOfficial references\nMicrosoft Learn: Gateway bandwidth allocation. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nThe 2016 model allocates tunnel bandwidth using ratios of the configured gateway capacity. For the 2019 model, Microsoft describes fixed maximum throughput for each tunnel type; a faster gateway network adapter does not remove that tunnel limit. IPsec defaults to the older allocation behavior; the documented transition requires enabling the gateway service and restarting the gateway VM. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/sdn/gateway-allocation).\n\n## Applicability\n\nRecord the active allocation behavior, tunnel type, gateway service state, and pool upgrade state, not just the server version. Consult the documented transition conditions before selecting a calculation. Keep product ceilings separate from measured throughput, and schedule any required restart through the change process.\n\n## DSE recommendation\n\nBuild a capacity worksheet that names each tunnel, its traffic requirement, configured allocation, and the applicable documented calculation. Ask the network owner to identify concurrent workloads and the acceptable behavior under contention. Avoid filling the gateway-capacity field with an arbitrary large value to make the worksheet appear sufficient. Have the application owner approve a realistic test load and observation period.\n\n## Verification\n\nMeasure traffic through the actual tunnel type while recording gateway resources and simultaneous traffic. Compare observed throughput with the allocation worksheet and investigate the limiting component. Repeat the relevant condition with the planned concurrency. Record both the measured result and the product-model assumption so later version changes trigger a fresh review.\n\n## Official references\n\n[Microsoft Learn: Gateway bandwidth allocation](https://learn.microsoft.com/en-us/windows-server/networking/sdn/gateway-allocation). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate SDN gateway capacity from tunnel throughput limits",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/",
                "headline": "Separate SDN gateway capacity from tunnel throughput limits",
                "description": "How should SDN gateway capacity be interpreted when planning tunnel bandwidth?",
                "abstract": "How should SDN gateway capacity be interpreted when planning tunnel bandwidth?",
                "articleBody": "Source facts\nThe 2016 model allocates tunnel bandwidth using ratios of the configured gateway capacity. For the 2019 model, Microsoft describes fixed maximum throughput for each tunnel type; a faster gateway network adapter does not remove that tunnel limit. IPsec defaults to the older allocation behavior; the documented transition requires enabling the gateway service and restarting the gateway VM. Microsoft Learn.\nApplicability\nRecord the active allocation behavior, tunnel type, gateway service state, and pool upgrade state, not just the server version. Consult the documented transition conditions before selecting a calculation. Keep product ceilings separate from measured throughput, and schedule any required restart through the change process.\nDSE recommendation\nBuild a capacity worksheet that names each tunnel, its traffic requirement, configured allocation, and the applicable documented calculation. Ask the network owner to identify concurrent workloads and the acceptable behavior under contention. Avoid filling the gateway-capacity field with an arbitrary large value to make the worksheet appear sufficient. Have the application owner approve a realistic test load and observation period.\nVerification\nMeasure traffic through the actual tunnel type while recording gateway resources and simultaneous traffic. Compare observed throughput with the allocation worksheet and investigate the limiting component. Repeat the relevant condition with the planned concurrency. Record both the measured result and the product-model assumption so later version changes trigger a fresh review.\nOfficial references\nMicrosoft Learn: Gateway bandwidth allocation. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:14:20+00:00",
                "dateModified": "2026-09-08T18:26:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-171-separate-sdn-gateway-capacity-from-tunnel-throughput-limits/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate SDN gateway capacity from tunnel throughput limits"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Gateway bandwidth allocation",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/sdn/gateway-allocation"
                }
            }
        ]
    }
}