# Choose GRE endpoints for a tenant-to-physical-network connection

> Where do GRE endpoints sit when a tenant virtual network needs a provider-side physical service?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-009-choose-gre-endpoints-for-a-tenant-to-physical-network-connection/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:17:02+00:00
- Modified: 2026-09-08T18:17:13+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Where do GRE endpoints sit when a tenant virtual network needs a provider-side physical service?

## Potentially affected

Use this review when designing a specific provider-side service path for a tenant.

## DSE recommendation

Draw the tunnel endpoints and the traffic path to the physical service.

## Article

## Source facts

Microsoft’s GRE implementation can encapsulate IPv4 and IPv6 through virtual point-to-point links over an IP network. In the documented tenant-to-physical-network scenario, one tunnel endpoint is a multitenant gateway and the other is a third-party device on the provider’s physical network. Layer 3 traffic is routed between tenant VMs and that device. Another documented scenario connects a VLAN-isolated physical load balancer to the virtual network through GRE. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras-gateway/gre-tunneling-windows-server).

## Applicability

Use this review when designing a specific provider-side service path for a tenant. Identify the gateway, physical device, tenant network, and required routing behavior. Confirm support on both endpoints before selecting this topology.

## DSE recommendation

Draw the tunnel endpoints and the traffic path to the physical service. Have the tenant and provider network owners agree on which routes and service addresses are in scope. Record the third-party device’s role and the configuration owner at each end. Keep the endpoint design distinct from any separate performance, packet-size, or confidentiality requirement.

## Verification

Test a representative tenant connection to the intended physical service and record the actual endpoint and routing context. Include a tenant that should not reach that service. Compare both results with the approved diagram and investigate an unexpected cross-tenant path before accepting the connection. Preserve the mapping for later device replacement.

## Official references

[Microsoft Learn: GRE Tunneling in Windows Server 2016](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras-gateway/gre-tunneling-windows-server). Source reviewed September 8, 2026.

## Primary reference

- Name: GRE Tunneling in Windows Server 2016
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras-gateway/gre-tunneling-windows-server
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose GRE endpoints for a tenant-to-physical-network connection,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-009-choose-gre-endpoints-for-a-tenant-to-physical-network-connection/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
