Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security 4via6 Subnet Routing
Cyber Security

4via6 Subnet Routing

← Back to Glossary
By NHI Mgmt Group Updated September 10, 2026 Domain: Cyber Security

4via6 subnet routing is a connectivity model for linking networks that share overlapping IP ranges or sit behind restrictive NAT and firewall conditions. It gives each connected network a unique identifier so devices can be reached directly without redesigning address plans, opening inbound ports, or forcing every deployment into a traditional site-to-site VPN pattern.

Expanded Definition

4via6 subnet routing is a connectivity approach for making one network reachable through another network path even when the original IPv4 ranges overlap or when inbound connectivity is constrained by NAT and firewall policy. The practical purpose is not to replace routing design, but to preserve reachability without forcing every environment to renumber or expose broad inbound access.

The key boundary is that 4via6 subnet routing solves a transport and reachability problem, not an application discovery or identity problem. It is typically used where two sites, tenants, or enclaves need deterministic network paths despite address collisions or restrictive edge controls. In that sense, it is closer to an overlay routing choice than to a general security control. The common misunderstanding is to treat it as a VPN synonym; while both can create connectivity, 4via6-style routing is specifically about preserving subnet-level routing semantics across constrained networks.

For readers who want a baseline on how routing and security controls are usually framed at the policy level, the NIST SP 800-53 Rev 5 Security and Privacy Controls catalogue is a useful reference point for the broader control environment around network connectivity decisions.

Examples and Use Cases

  • A multi-site organisation uses 4via6 subnet routing so two branches with overlapping RFC 1918 address space can communicate without readdressing either side.
  • A hosted service provider uses it to link customer enclaves that sit behind strict NAT devices, while still avoiding inbound port exposure at the edge.
  • A migration team uses it during phased cloud adoption, where legacy networks and new environments must coexist before a longer-term address redesign is complete.
  • An engineering group uses it for lab-to-production adjacency where isolated test networks need controlled reachability without building a full mesh of traditional site-to-site tunnels.
  • Operators prefer it when the practical tradeoff is accepting an overlay path and added routing complexity rather than a disruptive renumbering programme.

The main operational tradeoff is that simplicity at the address-plan layer often shifts complexity into routing policy, path visibility, and troubleshooting. The more environments you bridge, the more important it becomes to understand which subnet should be reachable, which should remain isolated, and where route leakage would create unintended lateral connectivity.

Security Implications

4via6 subnet routing can reduce pressure to open inbound ports or flatten network design, but it can also create a false sense of containment if the overlay is treated as inherently trusted. The security outcome depends on how well routing scope, edge filtering, and path authorization are maintained.

When subnet-to-subnet connectivity is extended across constrained boundaries, unintended reachability becomes the main failure mode. A route that was meant to support one application path can expose adjacent systems if prefix controls are too coarse, if firewall policy follows the tunnel too loosely, or if operational changes are not reflected in the overlay map. Misrouting is especially dangerous in overlapping-address environments because operators may assume they are talking to one enclave while actually reaching another.

The practical symptom is often not an obvious breach but an unexplained change in who can talk to what. That makes logging, route review, and boundary validation more important than in a simple point-to-point setup. For security teams, the key question is whether the overlay preserved segmentation intent, not just whether packets flow.

Domain and Governance Relevance

In network architecture governance, 4via6 subnet routing matters because it changes how organisations define reachability, ownership, and boundary control across sites that cannot be cleanly renumbered. It is most useful when the primary constraint is connectivity design, not user access policy or application authorisation.

Where non-human systems are involved, the governance question becomes more specific: the routing layer may enable machine-to-machine communication across environments that would otherwise remain isolated. That does not make the term an identity concept on its own, but it does mean the overlay can expand the effective trust boundary for workloads, automation systems, and management services. Practitioners should therefore treat the routing map as part of the control surface, especially where service traffic, administration traffic, and production traffic share the same path assumptions.

For NHIMG readers, the most important shift is that connectivity convenience can quietly alter blast radius. If the route exists, the control boundary may already have moved, even when the address plan has not.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-3 — Remote Access4via6 changes remote reachability across constrained network boundaries.
PR.AC-5 — Network IntegritySubnet routing must preserve intended segmentation and prevent route leakage.
Recommendation — Restrict overlay reachability to approved paths and enforce explicit remote-access boundaries. Validate routes and filtering so the overlay cannot bypass network segmentation intent.
CIS Controls v8CIS Control 12 — Network Infrastructure ManagementThis routing model depends on disciplined control of network paths and boundaries.
CIS Control 6 — Access Control ManagementConnectivity expansion should be tied to explicit authorization of reachable systems.
Recommendation — Document and review overlay routes, firewall rules, and boundary changes as infrastructure assets. Allow only the minimum reachable subnets needed for approved business traffic.
MITRE ATT&CKT1021 — Remote ServicesAdversaries can abuse routed connectivity to move across exposed network paths.
Recommendation — Monitor remote access paths for unexpected use and investigate lateral movement over routed links.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 10, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org