Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is OpenVPN S2S /30 topology not recommended anymore ??

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bingo600B
      bingo600 @viragomann
      last edited by bingo600

      @viragomann

      Something is mentioned here.
      https://community.openvpn.net/openvpn/wiki/Topology

      It seems to be for "clients" not site2site , and the net30 seems to some old weird thing , for M$ clients.

      I think (hope) someone saw that, and misunderstood.

      Edit:
      Wuutt: - They are removing net30 in 2.6
      https://community.openvpn.net/openvpn/ticket/1288

      Now i'm getting worried ....

      54c89b24-1acf-4559-a8c5-35775173e2a6-image.png

      Are we using subnet with a /30 , or are we (behind the curtains) specifying net30 , when using a /30 in pfSense ?

      /Bingo

      If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

      pfSense+ 23.05.1 (ZFS)

      QOTOM-Q355G4 Quad Lan.
      CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
      LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

      V 1 Reply Last reply Reply Quote 0
      • PippinP
        Pippin
        last edited by Pippin

        https://forum.netgate.com/topic/92430/heads-up-openvpn-topology-default-changed-to-subnet-was-net30
        .
        https://community.openvpn.net/openvpn/wiki/DeprecatedOptions

        I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
        Halton Arp

        1 Reply Last reply Reply Quote 1
        • V
          viragomann @bingo600
          last edited by

          @bingo600
          Yes, for an access server the subnet topology is recommended now.

          Some old clients are not compatible with subnet topology, however, so the default setting was /30 in previous pfSense versions.

          bingo600B 1 Reply Last reply Reply Quote 0
          • bingo600B
            bingo600 @viragomann
            last edited by bingo600

            @viragomann

            So this is just for Servers with IPv4 Pools (aka not S2S)
            https://community.openvpn.net/openvpn/ticket/1288

            and

            https://patchwork.openvpn.net/project/openvpn2/patch/20200620180532.15738-1-gert@greenie.muc.de/#2289

            I have this selected on my S2S servers
            cb601513-007e-4e74-95e8-a6e3b6a9fb52-image.png

            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @bingo600
              last edited by

              @bingo600 said in Is OpenVPN S2S /30 topology not recommended anymore ??:

              https://community.openvpn.net/openvpn/ticket/1288

              Good to know. One of my access servers still uses /30 topology.

              I have this selected on my S2S servers

              I simply use a /30 tunnel network in my s2s servers. So the topo settings is superfluous with that.

              bingo600B 1 Reply Last reply Reply Quote 0
              • bingo600B
                bingo600 @viragomann
                last edited by

                @viragomann said in Is OpenVPN S2S /30 topology not recommended anymore ??:

                I simply use a /30 tunnel network in my s2s servers. So the topo settings is superfluous with that.

                And you still have the /30 "benefit" , as not having to do CSO's

                I also have /30 tunnel network on my S2S both Client + Server

                5a5376bf-d899-4713-809d-3ca0cfca92e6-image.png

                If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                pfSense+ 23.05.1 (ZFS)

                QOTOM-Q355G4 Quad Lan.
                CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @bingo600
                  last edited by

                  @bingo600
                  Yes, with a /30 tunnel there is only one client possible. Hence you don't need a CSO.

                  bingo600B 1 Reply Last reply Reply Quote 1
                  • bingo600B
                    bingo600 @viragomann
                    last edited by

                    @viragomann
                    I'll try to set topology SUBNET tomorrow on my central server and test-fwall (client) S2S peer

                    Thanx šŸ‘

                    If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                    pfSense+ 23.05.1 (ZFS)

                    QOTOM-Q355G4 Quad Lan.
                    CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                    LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                    V 1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @bingo600
                      last edited by

                      @bingo600
                      If the server uses a /30 tunnel this won't change anything. But yeah, it would be compatible with the next OpenVPN versions.

                      1 Reply Last reply Reply Quote 0
                      • bingo600B
                        bingo600
                        last edited by

                        I changed all my S2S Server & Clients from:
                        Toplogy : NET30 --> Topology: Subnet
                        Remember to do it on the "Remote client first" , then on the "Server".

                        Since i already used a /30 as the Tunnel interface, this was all i had to do.

                        I experienced a brief OpenVPN outage, while the Server & Client restarted/reconnected ...
                        Outage 1..2 minutes.

                        /Bingo

                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                        pfSense+ 23.05.1 (ZFS)

                        QOTOM-Q355G4 Quad Lan.
                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.