What you need to know
Where do GRE endpoints sit when a tenant virtual network needs a provider-side physical service?
Potentially affected
Use this review when designing a specific provider-side service path for a tenant.
DSE recommendation
Draw the tunnel endpoints and the traffic path to the physical service.
Source facts
Microsoft’s GRE implementation can encapsulate IPv4 and IPv6 through virtual point-to-point links over an IP network. In the documented tenant-to-physical-network scenario, one tunnel endpoint is a multitenant gateway and the other is a third-party device on the provider’s physical network. Layer 3 traffic is routed between tenant VMs and that device. Another documented scenario connects a VLAN-isolated physical load balancer to the virtual network through GRE. Microsoft documentation.
Applicability
Use this review when designing a specific provider-side service path for a tenant. Identify the gateway, physical device, tenant network, and required routing behavior. Confirm support on both endpoints before selecting this topology.
DSE recommendation
Draw the tunnel endpoints and the traffic path to the physical service. Have the tenant and provider network owners agree on which routes and service addresses are in scope. Record the third-party device’s role and the configuration owner at each end. Keep the endpoint design distinct from any separate performance, packet-size, or confidentiality requirement.
Verification
Test a representative tenant connection to the intended physical service and record the actual endpoint and routing context. Include a tenant that should not reach that service. Compare both results with the approved diagram and investigate an unexpected cross-tenant path before accepting the connection. Preserve the mapping for later device replacement.
Official references
Microsoft Learn: GRE Tunneling in Windows Server 2016. Source reviewed September 8, 2026.
Review the official source
GRE Tunneling in Windows Server 2016 · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE