`--route` and `--route-ipv6` cannot currently be used in ccd/ (`--client-config-dir`) config files. The limitation isn't due to a fundamental reason; rather, it's because implementing this feature is complex, and the typical use case can be addressed more flexibly using a `--learn-address` script. This script is triggered on client-connect/client-disconnect and can set up routing based on the information from `--iroute/--iroute-ipv6`. Here is an example of a very basic script: ```bash #!/bin/bash add_del="$1" route="$2" cname="$3" case "$route" in *:*) six=-6 ;; *) six="" ;; esac if [ -n "$dev" ] then device="dev $dev" else device="" fi ip $six route "$add_del" "$route" $device ``` This example is derived from Samuel Thibault's contribution to the openvpn-devel mailing list regarding this topic ([source](http://article.gmane.org/gmane.network.openvpn.devel/11129)). For connections over UDP, it's advisable to add `--explicit-exit-notification` to the client configuration to ensure quicker disconnection notifications. A typical use case involves a client subnet that needs routing to a specific client, with multiple OpenVPN servers available for connection (across multiple ports or even different machines for failover). This requires the "route this network to my tun interface" logic to dynamically adapt upon client connection.
