# Allocate one coherent address plan for a Hyper-V NAT host

> How should VM and container address ranges be planned for a shared Windows NAT instance?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-190-allocate-one-coherent-address-plan-for-a-hyper-v-nat-host/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:01+00:00
- Modified: 2026-09-08T18:26:32+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

How should VM and container address ranges be planned for a shared Windows NAT instance?

## Potentially affected

Administrators configuring WinNAT connectivity for Hyper-V VMs and containers.

## DSE recommendation

Reserve a host-level address plan that shows the overall internal prefix and the ranges assigned by each service.

## Article

## Source facts

Microsoft documents a limit of one NAT network per host in this Hyper-V setup. A VM connects to the NAT network through the internal virtual switch created by the procedure. When VMs and containers share one NAT, the internal prefix must cover their assigned ranges, and the configuration must avoid reusing addresses. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/setup-nat-network).

## Applicability

List the VMs, containers, and applications already managing addresses on the host. Inspect existing NAT and switch configuration before adding another network. Review the documented WinNAT limits alongside the intended topology rather than choosing an isolated range for each tool.

## DSE recommendation

Reserve a host-level address plan that shows the overall internal prefix and the ranges assigned by each service. Name the owner of every allocation and the procedure for adding another VM or container. Preserve current switch and NAT settings before the pilot. Require an address-collision check before an application is allowed to introduce its own range.

## Verification

Verify that each test endpoint uses the intended switch and a unique address inside the approved range. Exercise the required outbound connection from both a VM and a container when both are in scope. Record the effective NAT configuration and any unexpected address assignment before accepting the shared-host design.

## Official references

[Microsoft Learn: Set up a NAT network](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/setup-nat-network). Source reviewed September 8, 2026.

## Primary reference

- Name: Set up a NAT network
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/setup-nat-network
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Allocate one coherent address plan for a Hyper-V NAT host,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-190-allocate-one-coherent-address-plan-for-a-hyper-v-nat-host/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
