Document tenant and subnet identifiers in an HNVv2 overlay network

How should tenant boundaries be represented when HNVv2 virtual networks reuse IP ranges?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

How should tenant boundaries be represented when HNVv2 virtual networks reuse IP ranges?

Potentially affected

Use this review for a documented HNVv2 deployment.

DSE recommendation

Maintain a mapping that records tenant ownership and overlay identifiers alongside address ranges.

Source facts

The implementation described by this Microsoft source is HNVv2. Microsoft models a Hyper-V Network Virtualization customer as an owner of one or more virtual networks, each containing virtual subnets. HNV uses NVGRE or VXLAN encapsulation to isolate overlay networks, allowing different tenants to use overlapping IP subnets. A virtual subnet supplies Layer 3 subnet semantics and a broadcast domain, with isolation associated with an NVGRE TNI or VXLAN VNI. Microsoft documentation.

Applicability

Use this review for a documented HNVv2 deployment. Identify the tenant, virtual network, subnet, and encapsulation in use before interpreting an IP address or troubleshooting a connection. Verify the current platform requirements for that design.

DSE recommendation

Maintain a mapping that records tenant ownership and overlay identifiers alongside address ranges. Have the network owner inspect any reused address ranges and confirm their intended isolation boundaries. Include both permitted intra-tenant paths and prohibited cross-tenant paths in the test plan. Preserve the mapping with the configuration so operational records do not depend on IP addresses alone.

Verification

Test representative connections within an intended virtual network and across a boundary that should remain isolated. Record the tenant and overlay context for every result. Compare the observed path with the approved mapping and investigate a misplaced identifier before changing application addressing. Update the map after any accepted network change.

Official references

Microsoft Learn: Hyper-V Network Virtualization Technical Details in Windows Server. Source reviewed September 8, 2026.

Primary reference

Review the official source

Hyper-V Network Virtualization Technical Details in Windows Server · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE