# Check the limits of SDN virtual network peering

> Which connections must be configured explicitly when SDN virtual networks are peered?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-162-check-the-limits-of-sdn-virtual-network-peering/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:29+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which connections must be configured explicitly when SDN virtual networks are peered?

## Potentially affected

Administrators designing peering between Windows Server SDN virtual networks.

## DSE recommendation

Draw the intended connections as explicit network pairs.

## Article

## Source facts

Microsoft describes peered virtual machines communicating over private addresses through the underlying infrastructure, without an internet connection or gateway for that communication. Peering does not extend transitively: connecting the first network to a second, and the second to a third, does not connect the first and third. Access control lists can restrict communication between peered networks, subnets, or individual virtual machines. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/sdn/vnet-peering/sdn-vnet-peering).

## Applicability

List every network pair that the application requires. Identify the relevant SDN implementation before applying this behavior to another networking product. Treat peering reachability, permitted application flows, and on-premises gateway use as separate design entries.

## DSE recommendation

Draw the intended connections as explicit network pairs. Beside each pair, identify the initiating workload, destination service, and permitted traffic. Have the network owner approve any broad connectivity before the application team enables it. Include a deliberately unpeered pair in the acceptance plan so an indirect relationship cannot silently become the assumed route. Preserve the prior peering and filtering configuration.

## Verification

Test an allowed flow and a prohibited flow across each configured pair. Then test between the first and third networks in the three-network example. Record the actual routes, applied access rules, and results from both ends. Resolve unexpected connectivity before extending the design to additional tenants.

## Official references

[Microsoft Learn: Virtual network peering](https://learn.microsoft.com/en-us/windows-server/networking/sdn/vnet-peering/sdn-vnet-peering). Source reviewed September 8, 2026.

## Primary reference

- Name: Virtual network peering
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/sdn/vnet-peering/sdn-vnet-peering
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check the limits of SDN virtual network peering,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-162-check-the-limits-of-sdn-virtual-network-peering/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
