# Choose a networking approach before enabling nested Hyper-V

> Which networking assumptions should be checked when running Hyper-V inside a virtual machine?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-093-choose-a-networking-approach-before-enabling-nested-hyper-v/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:38+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which networking assumptions should be checked when running Hyper-V inside a virtual machine?

## Potentially affected

Administrators preparing supported nested Hyper-V test environments.

## DSE recommendation

Draw the host, first-level VM, nested guests, switches, and proposed address path.

## Article

## Source facts

Nested virtualization allows Hyper-V to run within a virtual machine. Microsoft performs the processor-exposure configuration while that virtual machine is powered off. For packets to traverse two virtual-switch layers, the documented approach enables MAC address spoofing at the first virtual-machine level. Microsoft also describes NAT as an alternative when spoofing cannot be used, including public-cloud scenarios. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/enable-nested-virtualization).

## Applicability

Check the physical processor, host release, guest release, VM configuration, and platform restrictions against the source prerequisites. Define which nested guests require outside connectivity and which should remain isolated.

## DSE recommendation

Draw the host, first-level VM, nested guests, switches, and proposed address path. Have the network owner approve the chosen method and its boundary. Schedule the required VM shutdown and retain the original processor and network settings before enabling the nested environment.

## Verification

Test connectivity from a nested guest to each intended destination and check an explicitly disallowed path. Confirm the address observed outside the nested environment and record the forwarding configuration. Recheck the first-level VM after a restart, and preserve any difference from the approved network diagram as an unresolved finding.

## Official references

[Microsoft Learn: Run Hyper-V in a Virtual Machine with Nested Virtualization](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/enable-nested-virtualization). Source reviewed September 8, 2026.

## Primary reference

- Name: Run Hyper-V in a Virtual Machine with Nested Virtualization
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/enable-nested-virtualization
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose a networking approach before enabling nested Hyper-V,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-093-choose-a-networking-approach-before-enabling-nested-hyper-v/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
