Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is OpenVPN S2S /30 topology not recommended anymore ??

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bingo600B
      bingo600
      last edited by bingo600

      Edit: It is the NET30 Topology that will be deprecated in OpenVPN 2.6
      See
      https://community.openvpn.net/openvpn/ticket/1288
      and
      https://patchwork.openvpn.net/project/openvpn2/patch/20200620180532.15738-1-gert@greenie.muc.de/#2289

      TLDR:
      Think i saw someone post that OpenVPN /30 topology was not recommended anymore.

      I'm using that for all my Site to Site VPN's, and would like to know if that is correct ?

      Why would they deprecate /30 Topology ?
      It's a "Clean" solution , and avoids the hassle of CSO's

      /Bingo

      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

      pfSense+ 23.05.1 (ZFS)

      QOTOM-Q355G4 Quad Lan.
      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @bingo600
        last edited by

        @bingo600
        I prefer a /30 tunnel network for a site-to-site as well. The setup seems more clear and reliable to me.

        The docs don't say you should not configure it this way: OpenVPN Site-to-Site Configuration Example with SSL/TLS.
        Check out the first note.

        bingo600B 1 Reply Last reply Reply Quote 0
        • bingo600B
          bingo600 @viragomann
          last edited by bingo600

          @viragomann

          Something is mentioned here.
          https://community.openvpn.net/openvpn/wiki/Topology

          It seems to be for "clients" not site2site , and the net30 seems to some old weird thing , for M$ clients.

          I think (hope) someone saw that, and misunderstood.

          Edit:
          Wuutt: - They are removing net30 in 2.6
          https://community.openvpn.net/openvpn/ticket/1288

          Now i'm getting worried ....

          54c89b24-1acf-4559-a8c5-35775173e2a6-image.png

          Are we using subnet with a /30 , or are we (behind the curtains) specifying net30 , when using a /30 in pfSense ?

          /Bingo

          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

          pfSense+ 23.05.1 (ZFS)

          QOTOM-Q355G4 Quad Lan.
          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

          V 1 Reply Last reply Reply Quote 0
          • PippinP
            Pippin
            last edited by Pippin

            https://forum.netgate.com/topic/92430/heads-up-openvpn-topology-default-changed-to-subnet-was-net30
            .
            https://community.openvpn.net/openvpn/wiki/DeprecatedOptions

            I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
            Halton Arp

            1 Reply Last reply Reply Quote 1
            • V
              viragomann @bingo600
              last edited by

              @bingo600
              Yes, for an access server the subnet topology is recommended now.

              Some old clients are not compatible with subnet topology, however, so the default setting was /30 in previous pfSense versions.

              bingo600B 1 Reply Last reply Reply Quote 0
              • bingo600B
                bingo600 @viragomann
                last edited by bingo600

                @viragomann

                So this is just for Servers with IPv4 Pools (aka not S2S)
                https://community.openvpn.net/openvpn/ticket/1288

                and

                https://patchwork.openvpn.net/project/openvpn2/patch/20200620180532.15738-1-gert@greenie.muc.de/#2289

                I have this selected on my S2S servers
                cb601513-007e-4e74-95e8-a6e3b6a9fb52-image.png

                If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                pfSense+ 23.05.1 (ZFS)

                QOTOM-Q355G4 Quad Lan.
                CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @bingo600
                  last edited by

                  @bingo600 said in Is OpenVPN S2S /30 topology not recommended anymore ??:

                  https://community.openvpn.net/openvpn/ticket/1288

                  Good to know. One of my access servers still uses /30 topology.

                  I have this selected on my S2S servers

                  I simply use a /30 tunnel network in my s2s servers. So the topo settings is superfluous with that.

                  bingo600B 1 Reply Last reply Reply Quote 0
                  • bingo600B
                    bingo600 @viragomann
                    last edited by

                    @viragomann said in Is OpenVPN S2S /30 topology not recommended anymore ??:

                    I simply use a /30 tunnel network in my s2s servers. So the topo settings is superfluous with that.

                    And you still have the /30 "benefit" , as not having to do CSO's

                    I also have /30 tunnel network on my S2S both Client + Server

                    5a5376bf-d899-4713-809d-3ca0cfca92e6-image.png

                    If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                    pfSense+ 23.05.1 (ZFS)

                    QOTOM-Q355G4 Quad Lan.
                    CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                    LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                    V 1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @bingo600
                      last edited by

                      @bingo600
                      Yes, with a /30 tunnel there is only one client possible. Hence you don't need a CSO.

                      bingo600B 1 Reply Last reply Reply Quote 1
                      • bingo600B
                        bingo600 @viragomann
                        last edited by

                        @viragomann
                        I'll try to set topology SUBNET tomorrow on my central server and test-fwall (client) S2S peer

                        Thanx šŸ‘

                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                        pfSense+ 23.05.1 (ZFS)

                        QOTOM-Q355G4 Quad Lan.
                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                        V 1 Reply Last reply Reply Quote 0
                        • V
                          viragomann @bingo600
                          last edited by

                          @bingo600
                          If the server uses a /30 tunnel this won't change anything. But yeah, it would be compatible with the next OpenVPN versions.

                          1 Reply Last reply Reply Quote 0
                          • bingo600B
                            bingo600
                            last edited by

                            I changed all my S2S Server & Clients from:
                            Toplogy : NET30 --> Topology: Subnet
                            Remember to do it on the "Remote client first" , then on the "Server".

                            Since i already used a /30 as the Tunnel interface, this was all i had to do.

                            I experienced a brief OpenVPN outage, while the Server & Client restarted/reconnected ...
                            Outage 1..2 minutes.

                            /Bingo

                            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                            pfSense+ 23.05.1 (ZFS)

                            QOTOM-Q355G4 Quad Lan.
                            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.