What you need to know
Why can a Tunnel gateway fail to route a corporate network even when its client pool is distinct?
Potentially affected
Apply this review to the Linux container-host network for Microsoft Tunnel. Inspect the active runtime and bridge configuration rather than assuming the documented default is still in use.
DSE recommendation
Add the container bridge as its own entry in the gateway's address inventory.
Source facts
Microsoft Tunnel’s Docker and Podman containers use a bridge network to forward traffic through their Linux host. If that bridge overlaps a corporate network, the gateway cannot successfully route traffic to that network. The documented defaults are 172.17.0.0/16 for Docker and 10.88.0.0/16 for Podman. Microsoft provides procedures for changing them, but requires Tunnel Gateway installation before changing the bridge configuration. Microsoft Learn.
Applicability
Apply this review to the Linux container-host network for Microsoft Tunnel. Inspect the active runtime and bridge configuration rather than assuming the documented default is still in use.
DSE recommendation
Add the container bridge as its own entry in the gateway’s address inventory. Compare the actual bridge range with the corporate destinations that clients must reach. If a conflict is found, have the network and Linux owners plan the runtime-specific change through an approved maintenance procedure. Preserve the initial bridge and routing state, select an agreed nonoverlapping range, and follow the documented installation-order requirement. Do not paste the source’s example replacement address into a production design.
Verification
After an approved change, inspect the effective bridge configuration and test a named destination in the formerly conflicting network from an intended tunnel client. Also verify an unaffected destination to detect unintended routing changes. Keep the client address pool and container bridge results separate so a successful check of one is not recorded as proof of the other.
Official references
Microsoft Learn: Prerequisites the Microsoft Tunnel VPN for Microsoft Intune.
Review the official source
Prerequisites the Microsoft Tunnel VPN for Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE