Blame

128f1b Samuli Seppänen 2025-02-28 13:15:50 1
# Addressing 
2
3
4
This page discusses the concepts of addressing in OpenVPN.
5
b1af79 Samuli Seppänen 2025-03-18 12:36:10 6
## Addressing Basics for Server/Client
128f1b Samuli Seppänen 2025-02-28 13:15:50 7
8
Addressing in OpenVPN depends on the [in use. The 3 types of possible server/client addressing styles are explained in the Topology page and are:
1893e7 Samuli Seppänen 2025-02-28 13:16:53 9
](/Pages/Topology)
128f1b Samuli Seppänen 2025-02-28 13:15:50 10
11
subnet:: The preferred topology for server/client steups
12
net30:: The deprecated /30 subnet allocation (best to avoid this)
13
p2p:: peer-to-peer addressed setups (non-Windows only; uses Point-To-Point, or PtP networking)
14
15
Note that with net30, non-Windows clients will configure addressing as PtP anyway; Windows uses the /30 as a virtual "network."
16
17
## Addressing in p2p (non-server) mode
18
19
Another operating mode is when you don't run either side as a server, which is when both are using `--mode p2p --topology p2p`. In this case, each end sets its own addressing. The addresses chosen here are completely arbitrary and only define the local verses remote sides. Addressing doesn't even need to be adjacent and "any" 2 addresses can be used.
20
21
If you intend to create a server that multiple clients connect to, you cannot use this mode. Also note that Windows clients do not support this.
22
23
## The Address Pool
24
25
In server mode, an addressing pool is commonly used; when used, clients that do not have server-side static addressing configured will be allocated an IP dynamically from this pool.
26
27
## Static Address Assignment
28
29
It is possible to have the server allocate a static IP to a client based on its commonName. This is done by way of an `--ifconfig-push` command in either a ccd file or (as an advanced alternative) by `--client-connect` script.
30
31
It is important to note that defining static addressing with an address that is also in the pool will result in problematic behavior if that IP was already allocated to another client. For this reason it is critical to reduce your pool range and assign static addresses that are outside the defined pool.
32
33
This means you cannot use the `--server` directive with static addressing as it consumes the entire network for the pool; instead, expand the directive and reduce the pool range to avoid problems.
34
35
## Examples
36
37
The examples below use 10.8.0.0/24 as the VPN network and include samples for both full-pool allocation, and a reduced allocation with static addressing for 2 clients called 'client1' and 'client2'.
38
39
Since the TLS setup is not the focus here, the `--pkcs12` is used here; your setup will likely be different. Addressing is the important part of these examples. Also note that the `--topology` directive is often pushed, and is in these examples.
40
41
### Examples for subnet topology
42
43
#### subnet Example with full pool
44
45
* server config:
46
```
47
--server 10.8.0.0 255.255.255.0
48
--dev tun
49
--topology subnet
50
51
# TLS needs:
52
--pkcs12 /vpn/server.p12
53
--dh /vpn/dh.pem
54
```
55
56
* client config:
57
```
58
--client
59
--dev tun
60
61
# TLS needs:
62
--pkcs12 /vpn/client.p12
63
```
64
65
#### subnet Example with static ccd
66
67
* server config:
68
```
69
--mode server
70
--tls-server
71
--dev tun
72
--topology "subnet"
73
--push "topology subnet"
74
--ifconfig 10.8.0.1 255.255.255.0
75
--push "route-gateway 10.8.0.1"
76
--ifconfig-pool 10.8.0.2 10.8.0.199 255.255.255.0
77
--client-config-dir /vpn/ccd-dir
78
79
# TLS needs:
80
--pkcs12 /vpn/server.p12
81
--dh /vpn/dh.pem
82
```
83
* server's `/vpn/ccd-dir/client1` file:
84
```
85
ifconfig-push 10.8.0.201 255.255.255.0
86
```
87
* server's `/vpn/ccd-dir/client2` file:
88
```
89
ifconfig-push 10.8.0.202 255.255.255.0
90
```
91
92
* client config:
93
```
94
--client
95
--dev tun
96
97
# TLS needs:
98
--pkcs12 /vpn/client.p12
99
```
100
101
### Examples for net30 topology
102
a9ad13 Samuli Seppänen 2025-02-28 13:16:31 103
Read the [page for more details on net30. In short, each client (and the server itself) is allocated a virtual /30 network for compatibility with very old Windows versions. Addressing pushed to Windows clients *must* use the center 2 IPs of this subnet.](/Pages/Topology)
128f1b Samuli Seppänen 2025-02-28 13:15:50 104
105
Note that net30 is the default topology (as of OpenVPN 2.3) and need not be declared explicitly with `--topology`.
106
107
#### net30 Example with full pool
108
109
* server config:
110
```
111
--server 10.8.0.0 255.255.255.0
112
--dev tun
113
114
# TLS needs:
115
--pkcs12 /vpn/server.p12
116
--dh /vpn/dh.pem
117
```
118
119
* client config:
120
```
121
--client
122
--dev tun
123
124
# TLS needs:
125
--pkcs12 /vpn/client.p12
126
```
127
128
#### net30 Example with static ccd
129
130
* server config:
131
```
132
--mode server
133
--tls-server
134
--ifconfig 10.8.0.1 10.8.0.2
135
--push "route-gateway 10.8.0.1"
136
--ifconfig-pool 10.8.0.4 10.8.0.199 255.255.255.0
137
--client-config-dir /vpn/ccd-dir
138
139
# TLS needs:
140
--pkcs12 /vpn/server.p12
141
--dh /vpn/dh.pem
142
```
143
* server's `/vpn/ccd-dir/client1` file:
144
```
145
ifconfig-push 10.8.0.202 10.8.0.201
146
```
147
* server's `/vpn/ccd-dir/client2` file:
148
```
149
ifconfig-push 10.8.0.206 10.8.0.205
150
```
151
152
* client config:
153
```
154
--client
155
--dev tun
156
157
# TLS needs:
158
--pkcs12 /vpn/client.p12
159
```
160
161
162
### Examples for p2p topology
163
164
This topology is only valid when none of your clients are Windows. The benefit is that you can use the entire network range. This can be beneficial when using smaller networks, such as a /29, /30, or even a /31 (normally unusable on "traditional" Ethernet-style networks.)
165
166
An advanced example is also shown at the end where you can use 100% of a given network for client IPs since PtP addressing does not have to be contiguous.
167
168
All these examples push the assigned IPs from the server, so they use a **single** client config common to all examples:
169
170
#### Common client config for p2p examples
171
172
* client config:
173
```
174
--client
175
--dev tun
176
177
# TLS needs:
178
--pkcs12 /vpn/client.p12
179
```
180
181
#### Using a /24
182
183
In this example, we assign the following addressing:
184
* VPN server: 10.8.0.0
185
* client1: 10.8.0.1
186
* client2: 10.8.0.2
187
* dynamic IPs assigned to other clients: 10.8.0.100 - 10.8.0.199
188
* (The IP 10.8.0.255 is used as a common peering IP and not routable)
189
190
* server config:
191
```
192
--mode server
193
--tls-server
194
--dev tun
195
--topology "p2p"
196
--push "topology p2p"
197
--ifconfig 10.8.0.0 10.8.0.255
198
--push "route-gateway 10.8.0.0"
199
--ifconfig-pool 10.8.0.100 10.8.0.199
200
--client-config-dir /vpn/ccd-dir
201
202
# TLS needs:
203
--pkcs12 /vpn/server.p12
204
--dh /vpn/dh.pem
205
```
206
* server's `/vpn/ccd-dir/client1` file:
207
```
208
ifconfig-push 10.8.0.1 10.8.0.0
209
```
210
* server's `/vpn/ccd-dir/client2` file:
211
```
212
ifconfig-push 10.8.0.2 10.8.0.0
213
```
214
215
#### Advanced example: utilizing a /30
216
217
In this example, we assign the following addressing, assigning 4 clients out of the network 203.0.113.252/30. The VPN server uses RFC1918 locally, and a matching RFC1918 is used by clients as the peering address.
218
* VPN server: 192.168.222.0 (peering with 192.168.222.1)
219
* client1: 203.0.113.252
220
* client2: 203.0.113.253
221
* client3: 203.0.113.254
222
* client4: 203.0.113.255
223
224
* server config:
225
```
226
--mode server
227
--tls-server
228
--dev tun
229
--topology "p2p"
230
--push "topology p2p"
231
--ifconfig 192.168.222.0 192.168.222.1
232
--push "route-gateway 192.168.222.0"
233
--client-config-dir /vpn/ccd-dir
234
235
# TLS needs:
236
--pkcs12 /vpn/server.p12
237
--dh /vpn/dh.pem
238
```
239
* server's `/vpn/ccd-dir/client1` file:
240
```
241
ifconfig-push 203.0.113.252 192.168.222.0
242
```
243
* server's `/vpn/ccd-dir/client2` file:
244
```
245
ifconfig-push 203.0.113.253 192.168.222.0
246
```
247
* server's `/vpn/ccd-dir/client3` file:
248
```
249
ifconfig-push 203.0.113.254 192.168.222.0
250
```
251
* server's `/vpn/ccd-dir/client4` file:
252
```
253
ifconfig-push 203.0.113.255 192.168.222.0
254
```