Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Why is /30 not allowed for OpenVPN server tunnel subnet?

    Scheduled Pinned Locked Moved OpenVPN
    7 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JimPhreak
      last edited by

      If I only need 2 client IP addresses why is /30 not allowed?  If I try to set /30 the service won't start and I get the following in the log:

      Options error: –server directive when used with --dev tun must define a subnet of 255.255.255.248 (/29) or lower

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Because you can't use directives that require –server when it's in peer-to-peer mode (/30) with SSL/TLS.

        What exact choices did you make in the GUI? If you chose Remote Access SSL/TLS, change it to Peer-to-Peer SSL/TLS instead.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • J
          JimPhreak
          last edited by

          @jimp:

          Because you can't use directives that require –server when it's in peer-to-peer mode (/30) with SSL/TLS.

          What exact choices did you make in the GUI? If you chose Remote Access SSL/TLS, change it to Peer-to-Peer SSL/TLS instead.

          Yes it's set to Remote Access SSL/TLS.  What does changing it to Peer-to-Peer affect?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            It changes the visible options and some backend behavior to allow a peer-to-peer style configuration.

            You shouldn't use "Remote Access" modes for site-to-site VPNs, that's what the peer-to-peer modes are for.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • J
              JimPhreak
              last edited by

              @jimp:

              It changes the visible options and some backend behavior to allow a peer-to-peer style configuration.

              You shouldn't use "Remote Access" modes for site-to-site VPNs, that's what the peer-to-peer modes are for.

              This isn't a site-to-site VPN.  I have one of those configured as Peer-to-Peer but this is for mine and my wife's mobile devices to be able to VPN into my home network.

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                A /30 makes no sense for remote access. OpenVPN's internal behavior changes significantly when using a /30 tunnel network, it's intended only for site-to-site VPNs.

                When using a /30 the server cannot push settings and it has several other limitations.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • J
                  JimPhreak
                  last edited by

                  @jimp:

                  A /30 makes no sense for remote access. OpenVPN's internal behavior changes significantly when using a /30 tunnel network, it's intended only for site-to-site VPNs.

                  When using a /30 the server cannot push settings and it has several other limitations.

                  Understood.  Thanks for the clarification.  I'll just use a /29.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.