{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/",
        "slug": "dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/"
        },
        "title": "Reconcile both halves of a Virtual WAN P2S client pool in the route table",
        "summary": "Why can a configured Virtual WAN P2S /24 address pool appear as two /25 routes?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:26+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 246,
        "potentially_affected": "Use this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route's more-specific prefix as a missing or unexpected address allocation.",
        "dse_recommendation": "Compare the configured pool with the combined effective routes.",
        "primary_source": {
            "name": "Configure address pools for Virtual WAN point-to-site VPN - PowerShell - Azure Virtual WAN | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents that a Virtual WAN point-to-site gateway splits each client address pool between its two active-active instances. The effective route table should show the resulting halves; the source&#8217;s /24 example therefore produces two /25 routes. The configured pool itself cannot be smaller than /24 and must not overlap other connection pools, virtual networks, virtual hubs or on-premises addresses. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route&#8217;s more-specific prefix as a missing or unexpected address allocation.</p>\n<h2>DSE recommendation</h2>\n<p>Compare the configured pool with the combined effective routes. Have the network owner reconcile both halves to the approved address plan and distinguish configured pool size from the routes representing its gateway instances. If a half is absent, investigate the actual gateway and connection configuration before changing the range. Keep the original pool and route observations with the case so a later change does not erase the evidence of what was missing.</p>\n<h2>Verification</h2>\n<p>Inspect the effective route table and verify that the paired prefixes cover the intended pool without introducing overlaps. Test approved client connections and record their assigned addresses alongside the corresponding route. Check required connection associations and propagation if clients cannot receive routes. Do not mark two expected /25 entries as an invalid /25 pool configuration merely because the route and configuration views use different prefix lengths.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure address pools for Virtual WAN point-to-site VPN &#8211; PowerShell</a>.</p>",
        "content_text": "Source facts\nMicrosoft documents that a Virtual WAN point-to-site gateway splits each client address pool between its two active-active instances. The effective route table should show the resulting halves; the source’s /24 example therefore produces two /25 routes. The configured pool itself cannot be smaller than /24 and must not overlap other connection pools, virtual networks, virtual hubs or on-premises addresses. Microsoft Learn.\nApplicability\nUse this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route’s more-specific prefix as a missing or unexpected address allocation.\nDSE recommendation\nCompare the configured pool with the combined effective routes. Have the network owner reconcile both halves to the approved address plan and distinguish configured pool size from the routes representing its gateway instances. If a half is absent, investigate the actual gateway and connection configuration before changing the range. Keep the original pool and route observations with the case so a later change does not erase the evidence of what was missing.\nVerification\nInspect the effective route table and verify that the paired prefixes cover the intended pool without introducing overlaps. Test approved client connections and record their assigned addresses alongside the corresponding route. Check required connection associations and propagation if clients cannot receive routes. Do not mark two expected /25 entries as an invalid /25 pool configuration merely because the route and configuration views use different prefix lengths.\nOfficial references\nMicrosoft Learn: Configure address pools for Virtual WAN point-to-site VPN – PowerShell.",
        "content_markdown": "## Source facts\n\nMicrosoft documents that a Virtual WAN point-to-site gateway splits each client address pool between its two active-active instances. The effective route table should show the resulting halves; the source’s /24 example therefore produces two /25 routes. The configured pool itself cannot be smaller than /24 and must not overlap other connection pools, virtual networks, virtual hubs or on-premises addresses. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell).\n\n## Applicability\n\nUse this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route’s more-specific prefix as a missing or unexpected address allocation.\n\n## DSE recommendation\n\nCompare the configured pool with the combined effective routes. Have the network owner reconcile both halves to the approved address plan and distinguish configured pool size from the routes representing its gateway instances. If a half is absent, investigate the actual gateway and connection configuration before changing the range. Keep the original pool and route observations with the case so a later change does not erase the evidence of what was missing.\n\n## Verification\n\nInspect the effective route table and verify that the paired prefixes cover the intended pool without introducing overlaps. Test approved client connections and record their assigned addresses alongside the corresponding route. Check required connection associations and propagation if clients cannot receive routes. Do not mark two expected /25 entries as an invalid /25 pool configuration merely because the route and configuration views use different prefix lengths.\n\n## Official references\n\n[Microsoft Learn: Configure address pools for Virtual WAN point-to-site VPN – PowerShell](https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Reconcile both halves of a Virtual WAN P2S client pool in the route table",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/",
                "headline": "Reconcile both halves of a Virtual WAN P2S client pool in the route table",
                "description": "Why can a configured Virtual WAN P2S /24 address pool appear as two /25 routes?",
                "abstract": "Why can a configured Virtual WAN P2S /24 address pool appear as two /25 routes?",
                "articleBody": "Source facts\nMicrosoft documents that a Virtual WAN point-to-site gateway splits each client address pool between its two active-active instances. The effective route table should show the resulting halves; the source’s /24 example therefore produces two /25 routes. The configured pool itself cannot be smaller than /24 and must not overlap other connection pools, virtual networks, virtual hubs or on-premises addresses. Microsoft Learn.\nApplicability\nUse this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route’s more-specific prefix as a missing or unexpected address allocation.\nDSE recommendation\nCompare the configured pool with the combined effective routes. Have the network owner reconcile both halves to the approved address plan and distinguish configured pool size from the routes representing its gateway instances. If a half is absent, investigate the actual gateway and connection configuration before changing the range. Keep the original pool and route observations with the case so a later change does not erase the evidence of what was missing.\nVerification\nInspect the effective route table and verify that the paired prefixes cover the intended pool without introducing overlaps. Test approved client connections and record their assigned addresses alongside the corresponding route. Check required connection associations and propagation if clients cannot receive routes. Do not mark two expected /25 entries as an invalid /25 pool configuration merely because the route and configuration views use different prefix lengths.\nOfficial references\nMicrosoft Learn: Configure address pools for Virtual WAN point-to-site VPN – PowerShell.",
                "datePublished": "2026-09-10T00:25:26+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Reconcile both halves of a Virtual WAN P2S client pool in the route table"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 246,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure address pools for Virtual WAN point-to-site VPN - PowerShell - Azure Virtual WAN | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell"
                }
            }
        ]
    }
}