• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Why is /30 not allowed for OpenVPN server tunnel subnet?

Scheduled Pinned Locked Moved OpenVPN
7 Posts 2 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    JimPhreak
    last edited by Mar 31, 2017, 5:00 PM

    If I only need 2 client IP addresses why is /30 not allowed?  If I try to set /30 the service won't start and I get the following in the log:

    Options error: –server directive when used with --dev tun must define a subnet of 255.255.255.248 (/29) or lower

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Apr 3, 2017, 5:16 PM

      Because you can't use directives that require –server when it's in peer-to-peer mode (/30) with SSL/TLS.

      What exact choices did you make in the GUI? If you chose Remote Access SSL/TLS, change it to Peer-to-Peer SSL/TLS instead.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • J
        JimPhreak
        last edited by Apr 3, 2017, 6:53 PM

        @jimp:

        Because you can't use directives that require –server when it's in peer-to-peer mode (/30) with SSL/TLS.

        What exact choices did you make in the GUI? If you chose Remote Access SSL/TLS, change it to Peer-to-Peer SSL/TLS instead.

        Yes it's set to Remote Access SSL/TLS.  What does changing it to Peer-to-Peer affect?

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Apr 3, 2017, 7:10 PM

          It changes the visible options and some backend behavior to allow a peer-to-peer style configuration.

          You shouldn't use "Remote Access" modes for site-to-site VPNs, that's what the peer-to-peer modes are for.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • J
            JimPhreak
            last edited by Apr 3, 2017, 7:19 PM

            @jimp:

            It changes the visible options and some backend behavior to allow a peer-to-peer style configuration.

            You shouldn't use "Remote Access" modes for site-to-site VPNs, that's what the peer-to-peer modes are for.

            This isn't a site-to-site VPN.  I have one of those configured as Peer-to-Peer but this is for mine and my wife's mobile devices to be able to VPN into my home network.

            1 Reply Last reply Reply Quote 0
            • J
              jimp Rebel Alliance Developer Netgate
              last edited by Apr 3, 2017, 7:39 PM

              A /30 makes no sense for remote access. OpenVPN's internal behavior changes significantly when using a /30 tunnel network, it's intended only for site-to-site VPNs.

              When using a /30 the server cannot push settings and it has several other limitations.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • J
                JimPhreak
                last edited by Apr 3, 2017, 8:27 PM

                @jimp:

                A /30 makes no sense for remote access. OpenVPN's internal behavior changes significantly when using a /30 tunnel network, it's intended only for site-to-site VPNs.

                When using a /30 the server cannot push settings and it has several other limitations.

                Understood.  Thanks for the clarification.  I'll just use a /29.

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received