Choose GRE endpoints for a tenant-to-physical-network connection

Where do GRE endpoints sit when a tenant virtual network needs a provider-side physical service?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Where do GRE endpoints sit when a tenant virtual network needs a provider-side physical service?

Potentially affected

Use this review when designing a specific provider-side service path for a tenant.

DSE recommendation

Draw the tunnel endpoints and the traffic path to the physical service.

Source facts

Microsoft’s GRE implementation can encapsulate IPv4 and IPv6 through virtual point-to-point links over an IP network. In the documented tenant-to-physical-network scenario, one tunnel endpoint is a multitenant gateway and the other is a third-party device on the provider’s physical network. Layer 3 traffic is routed between tenant VMs and that device. Another documented scenario connects a VLAN-isolated physical load balancer to the virtual network through GRE. Microsoft documentation.

Applicability

Use this review when designing a specific provider-side service path for a tenant. Identify the gateway, physical device, tenant network, and required routing behavior. Confirm support on both endpoints before selecting this topology.

DSE recommendation

Draw the tunnel endpoints and the traffic path to the physical service. Have the tenant and provider network owners agree on which routes and service addresses are in scope. Record the third-party device’s role and the configuration owner at each end. Keep the endpoint design distinct from any separate performance, packet-size, or confidentiality requirement.

Verification

Test a representative tenant connection to the intended physical service and record the actual endpoint and routing context. Include a tenant that should not reach that service. Compare both results with the approved diagram and investigate an unexpected cross-tenant path before accepting the connection. Preserve the mapping for later device replacement.

Official references

Microsoft Learn: GRE Tunneling in Windows Server 2016. Source reviewed September 8, 2026.

Primary reference

Review the official source

GRE Tunneling in Windows Server 2016 · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE