{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/",
        "slug": "dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/"
        },
        "title": "Review the routing implications of extending an on-premises subnet into Azure",
        "summary": "What must be evaluated before using extended network for Azure to retain VM addresses?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:27+00:00",
        "modified_at": "2026-09-08T18:29:34+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 231,
        "potentially_affected": "Administrators evaluating extended network for Azure for migrating on-premises VMs.",
        "dse_recommendation": "Have the network and application owners map the intended traffic paths and list which VMs genuinely need their current addresses.",
        "primary_source": {
            "name": "Extend your on-premises subnets into Azure using extended network for Azure",
            "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft describes extending an on-premises subnet so migrated VMs can retain their existing private IP addresses. The documented feature supports extending up to 250 addresses and presents throughput as dependent on appliance CPU performance. Where a firewall lies between the sites, the source requires consideration of asymmetric routing and directs administrators to the firewall vendor&#8217;s instructions. <a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the exact address-retention requirement and compare it with an ordinary routed migration. Review appliance placement, subnet planning, and current capacity guidance before selecting the extension. Treat firewall behavior as part of the design rather than a last-minute connectivity exception.</p>\n<h2>DSE recommendation</h2>\n<p>Have the network and application owners map the intended traffic paths and list which VMs genuinely need their current addresses. Ask the firewall owner to assess the documented asymmetric-routing requirement and any implications for the existing controls. Pilot a small address set with agreed throughput and recovery expectations. Preserve the original route and security configuration before introducing the appliances.</p>\n<h2>Verification</h2>\n<p>Move an approved test workload and confirm its intended address, application reachability, and observed traffic path. Test representative return traffic and the agreed interruption scenario. Measure actual appliance behavior under the pilot load rather than treating an example throughput as a guarantee. Resolve routing or control gaps before extending additional addresses.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Extend your on-premises subnets into Azure using extended network for Azure</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft describes extending an on-premises subnet so migrated VMs can retain their existing private IP addresses. The documented feature supports extending up to 250 addresses and presents throughput as dependent on appliance CPU performance. Where a firewall lies between the sites, the source requires consideration of asymmetric routing and directs administrators to the firewall vendor’s instructions. Microsoft Learn.\nApplicability\nIdentify the exact address-retention requirement and compare it with an ordinary routed migration. Review appliance placement, subnet planning, and current capacity guidance before selecting the extension. Treat firewall behavior as part of the design rather than a last-minute connectivity exception.\nDSE recommendation\nHave the network and application owners map the intended traffic paths and list which VMs genuinely need their current addresses. Ask the firewall owner to assess the documented asymmetric-routing requirement and any implications for the existing controls. Pilot a small address set with agreed throughput and recovery expectations. Preserve the original route and security configuration before introducing the appliances.\nVerification\nMove an approved test workload and confirm its intended address, application reachability, and observed traffic path. Test representative return traffic and the agreed interruption scenario. Measure actual appliance behavior under the pilot load rather than treating an example throughput as a guarantee. Resolve routing or control gaps before extending additional addresses.\nOfficial references\nMicrosoft Learn: Extend your on-premises subnets into Azure using extended network for Azure. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft describes extending an on-premises subnet so migrated VMs can retain their existing private IP addresses. The documented feature supports extending up to 250 addresses and presents throughput as dependent on appliance CPU performance. Where a firewall lies between the sites, the source requires consideration of asymmetric routing and directs administrators to the firewall vendor’s instructions. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network).\n\n## Applicability\n\nIdentify the exact address-retention requirement and compare it with an ordinary routed migration. Review appliance placement, subnet planning, and current capacity guidance before selecting the extension. Treat firewall behavior as part of the design rather than a last-minute connectivity exception.\n\n## DSE recommendation\n\nHave the network and application owners map the intended traffic paths and list which VMs genuinely need their current addresses. Ask the firewall owner to assess the documented asymmetric-routing requirement and any implications for the existing controls. Pilot a small address set with agreed throughput and recovery expectations. Preserve the original route and security configuration before introducing the appliances.\n\n## Verification\n\nMove an approved test workload and confirm its intended address, application reachability, and observed traffic path. Test representative return traffic and the agreed interruption scenario. Measure actual appliance behavior under the pilot load rather than treating an example throughput as a guarantee. Resolve routing or control gaps before extending additional addresses.\n\n## Official references\n\n[Microsoft Learn: Extend your on-premises subnets into Azure using extended network for Azure](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review the routing implications of extending an on-premises subnet into Azure",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/",
                "headline": "Review the routing implications of extending an on-premises subnet into Azure",
                "description": "What must be evaluated before using extended network for Azure to retain VM addresses?",
                "abstract": "What must be evaluated before using extended network for Azure to retain VM addresses?",
                "articleBody": "Source facts\nMicrosoft describes extending an on-premises subnet so migrated VMs can retain their existing private IP addresses. The documented feature supports extending up to 250 addresses and presents throughput as dependent on appliance CPU performance. Where a firewall lies between the sites, the source requires consideration of asymmetric routing and directs administrators to the firewall vendor’s instructions. Microsoft Learn.\nApplicability\nIdentify the exact address-retention requirement and compare it with an ordinary routed migration. Review appliance placement, subnet planning, and current capacity guidance before selecting the extension. Treat firewall behavior as part of the design rather than a last-minute connectivity exception.\nDSE recommendation\nHave the network and application owners map the intended traffic paths and list which VMs genuinely need their current addresses. Ask the firewall owner to assess the documented asymmetric-routing requirement and any implications for the existing controls. Pilot a small address set with agreed throughput and recovery expectations. Preserve the original route and security configuration before introducing the appliances.\nVerification\nMove an approved test workload and confirm its intended address, application reachability, and observed traffic path. Test representative return traffic and the agreed interruption scenario. Measure actual appliance behavior under the pilot load rather than treating an example throughput as a guarantee. Resolve routing or control gaps before extending additional addresses.\nOfficial references\nMicrosoft Learn: Extend your on-premises subnets into Azure using extended network for Azure. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:27+00:00",
                "dateModified": "2026-09-08T18:29:34+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review the routing implications of extending an on-premises subnet into Azure"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 231,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Extend your on-premises subnets into Azure using extended network for Azure",
                    "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network"
                }
            }
        ]
    }
}