# Document tenant and subnet identifiers in an HNVv2 overlay network

> How should tenant boundaries be represented when HNVv2 virtual networks reuse IP ranges?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-049-document-tenant-and-subnet-identifiers-in-an-hnvv2-overlay-network/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:22+00:00
- Modified: 2026-09-08T18:17:14+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

How should tenant boundaries be represented when HNVv2 virtual networks reuse IP ranges?

## Potentially affected

Use this review for a documented HNVv2 deployment.

## DSE recommendation

Maintain a mapping that records tenant ownership and overlay identifiers alongside address ranges.

## Article

## Source facts

The implementation described by this Microsoft source is HNVv2. Microsoft models a Hyper-V Network Virtualization customer as an owner of one or more virtual networks, each containing virtual subnets. HNV uses NVGRE or VXLAN encapsulation to isolate overlay networks, allowing different tenants to use overlapping IP subnets. A virtual subnet supplies Layer 3 subnet semantics and a broadcast domain, with isolation associated with an NVGRE TNI or VXLAN VNI. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/sdn/technologies/hyper-v-network-virtualization/hyperv-network-virtualization-technical-details-windows-server).

## Applicability

Use this review for a documented HNVv2 deployment. Identify the tenant, virtual network, subnet, and encapsulation in use before interpreting an IP address or troubleshooting a connection. Verify the current platform requirements for that design.

## DSE recommendation

Maintain a mapping that records tenant ownership and overlay identifiers alongside address ranges. Have the network owner inspect any reused address ranges and confirm their intended isolation boundaries. Include both permitted intra-tenant paths and prohibited cross-tenant paths in the test plan. Preserve the mapping with the configuration so operational records do not depend on IP addresses alone.

## Verification

Test representative connections within an intended virtual network and across a boundary that should remain isolated. Record the tenant and overlay context for every result. Compare the observed path with the approved mapping and investigate a misplaced identifier before changing application addressing. Update the map after any accepted network change.

## Official references

[Microsoft Learn: Hyper-V Network Virtualization Technical Details in Windows Server](https://learn.microsoft.com/en-us/windows-server/networking/sdn/technologies/hyper-v-network-virtualization/hyperv-network-virtualization-technical-details-windows-server). Source reviewed September 8, 2026.

## Primary reference

- Name: Hyper-V Network Virtualization Technical Details in Windows Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/sdn/technologies/hyper-v-network-virtualization/hyperv-network-virtualization-technical-details-windows-server
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Document tenant and subnet identifiers in an HNVv2 overlay network,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-049-document-tenant-and-subnet-identifiers-in-an-hnvv2-overlay-network/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
