# Check where SDN virtual network encryption stops

> Which traffic is covered by encryption on an SDN virtual subnet?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-176-check-where-sdn-virtual-network-encryption-stops/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:15+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which traffic is covered by encryption on an SDN virtual subnet?

## Potentially affected

Administrators enabling encryption on Windows Server SDN virtual networks.

## DSE recommendation

Create a protection matrix with one row per application flow.

## Article

## Source facts

Microsoft describes subnet encryption using DTLS for virtual machines communicating inside an encryption-enabled subnet. The configuration requires encryption certificates on the SDN Hyper-V hosts and a Network Controller credential referencing the certificate thumbprint. The source states that traffic crossing between subnets, or leaving the virtual network, is not encrypted by this feature even when the subnets are marked for encryption. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/sdn/vnet-encryption/sdn-config-vnet-encryption).

## Applicability

Map the actual source and destination subnets for the protected workload. Distinguish a same-subnet conversation from cross-subnet and external traffic. Decide which additional protection is needed for each path rather than treating one enabled setting as a complete traffic inventory.

## DSE recommendation

Create a protection matrix with one row per application flow. Identify the certificate and credential objects used by the intended hosts, the subnet setting, and the expected protection at every boundary. Ask the workload owner to approve coverage gaps explicitly. Keep certificate handling and renewal ownership in the configuration record and preserve the original settings for the pilot.

## Verification

Test representative traffic within a protected subnet, across a subnet boundary, and outside the virtual network. Use authorized observations that can distinguish the relevant protection without collecting unnecessary payloads. Compare the evidence with the flow matrix and investigate any unsupported assumption before expanding encryption to more workloads.

## Official references

[Microsoft Learn: Configure Encryption for a Virtual Network](https://learn.microsoft.com/en-us/windows-server/networking/sdn/vnet-encryption/sdn-config-vnet-encryption). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure Encryption for a Virtual Network
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/sdn/vnet-encryption/sdn-config-vnet-encryption
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check where SDN virtual network encryption stops,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-176-check-where-sdn-virtual-network-encryption-stops/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
