Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is OpenVPN S2S /30 topology not recommended anymore ??

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @bingo600
      last edited by

      @bingo600
      I prefer a /30 tunnel network for a site-to-site as well. The setup seems more clear and reliable to me.

      The docs don't say you should not configure it this way: OpenVPN Site-to-Site Configuration Example with SSL/TLS.
      Check out the first note.

      bingo600B 1 Reply Last reply Reply Quote 0
      • bingo600B
        bingo600 @viragomann
        last edited by bingo600

        @viragomann

        Something is mentioned here.
        https://community.openvpn.net/openvpn/wiki/Topology

        It seems to be for "clients" not site2site , and the net30 seems to some old weird thing , for M$ clients.

        I think (hope) someone saw that, and misunderstood.

        Edit:
        Wuutt: - They are removing net30 in 2.6
        https://community.openvpn.net/openvpn/ticket/1288

        Now i'm getting worried ....

        54c89b24-1acf-4559-a8c5-35775173e2a6-image.png

        Are we using subnet with a /30 , or are we (behind the curtains) specifying net30 , when using a /30 in pfSense ?

        /Bingo

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        V 1 Reply Last reply Reply Quote 0
        • PippinP
          Pippin
          last edited by Pippin

          https://forum.netgate.com/topic/92430/heads-up-openvpn-topology-default-changed-to-subnet-was-net30
          .
          https://community.openvpn.net/openvpn/wiki/DeprecatedOptions

          I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
          Halton Arp

          1 Reply Last reply Reply Quote 1
          • V
            viragomann @bingo600
            last edited by

            @bingo600
            Yes, for an access server the subnet topology is recommended now.

            Some old clients are not compatible with subnet topology, however, so the default setting was /30 in previous pfSense versions.

            bingo600B 1 Reply Last reply Reply Quote 0
            • bingo600B
              bingo600 @viragomann
              last edited by bingo600

              @viragomann

              So this is just for Servers with IPv4 Pools (aka not S2S)
              https://community.openvpn.net/openvpn/ticket/1288

              and

              https://patchwork.openvpn.net/project/openvpn2/patch/20200620180532.15738-1-gert@greenie.muc.de/#2289

              I have this selected on my S2S servers
              cb601513-007e-4e74-95e8-a6e3b6a9fb52-image.png

              If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

              pfSense+ 23.05.1 (ZFS)

              QOTOM-Q355G4 Quad Lan.
              CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
              LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @bingo600
                last edited by

                @bingo600 said in Is OpenVPN S2S /30 topology not recommended anymore ??:

                https://community.openvpn.net/openvpn/ticket/1288

                Good to know. One of my access servers still uses /30 topology.

                I have this selected on my S2S servers

                I simply use a /30 tunnel network in my s2s servers. So the topo settings is superfluous with that.

                bingo600B 1 Reply Last reply Reply Quote 0
                • bingo600B
                  bingo600 @viragomann
                  last edited by

                  @viragomann said in Is OpenVPN S2S /30 topology not recommended anymore ??:

                  I simply use a /30 tunnel network in my s2s servers. So the topo settings is superfluous with that.

                  And you still have the /30 "benefit" , as not having to do CSO's

                  I also have /30 tunnel network on my S2S both Client + Server

                  5a5376bf-d899-4713-809d-3ca0cfca92e6-image.png

                  If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                  pfSense+ 23.05.1 (ZFS)

                  QOTOM-Q355G4 Quad Lan.
                  CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                  LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @bingo600
                    last edited by

                    @bingo600
                    Yes, with a /30 tunnel there is only one client possible. Hence you don't need a CSO.

                    bingo600B 1 Reply Last reply Reply Quote 1
                    • bingo600B
                      bingo600 @viragomann
                      last edited by

                      @viragomann
                      I'll try to set topology SUBNET tomorrow on my central server and test-fwall (client) S2S peer

                      Thanx šŸ‘

                      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                      pfSense+ 23.05.1 (ZFS)

                      QOTOM-Q355G4 Quad Lan.
                      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @bingo600
                        last edited by

                        @bingo600
                        If the server uses a /30 tunnel this won't change anything. But yeah, it would be compatible with the next OpenVPN versions.

                        1 Reply Last reply Reply Quote 0
                        • bingo600B
                          bingo600
                          last edited by

                          I changed all my S2S Server & Clients from:
                          Toplogy : NET30 --> Topology: Subnet
                          Remember to do it on the "Remote client first" , then on the "Server".

                          Since i already used a /30 as the Tunnel interface, this was all i had to do.

                          I experienced a brief OpenVPN outage, while the Server & Client restarted/reconnected ...
                          Outage 1..2 minutes.

                          /Bingo

                          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                          pfSense+ 23.05.1 (ZFS)

                          QOTOM-Q355G4 Quad Lan.
                          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.