# Reconcile both halves of a Virtual WAN P2S client pool in the route table

> Why can a configured Virtual WAN P2S /24 address pool appear as two /25 routes?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:26+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why can a configured Virtual WAN P2S /24 address pool appear as two /25 routes?

## Potentially affected

Use this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route's more-specific prefix as a missing or unexpected address allocation.

## DSE recommendation

Compare the configured pool with the combined effective routes.

## Article

## Source facts

Microsoft documents that a Virtual WAN point-to-site gateway splits each client address pool between its two active-active instances. The effective route table should show the resulting halves; the source’s /24 example therefore produces two /25 routes. The configured pool itself cannot be smaller than /24 and must not overlap other connection pools, virtual networks, virtual hubs or on-premises addresses. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell).

## Applicability

Use this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route’s more-specific prefix as a missing or unexpected address allocation.

## DSE recommendation

Compare the configured pool with the combined effective routes. Have the network owner reconcile both halves to the approved address plan and distinguish configured pool size from the routes representing its gateway instances. If a half is absent, investigate the actual gateway and connection configuration before changing the range. Keep the original pool and route observations with the case so a later change does not erase the evidence of what was missing.

## Verification

Inspect the effective route table and verify that the paired prefixes cover the intended pool without introducing overlaps. Test approved client connections and record their assigned addresses alongside the corresponding route. Check required connection associations and propagation if clients cannot receive routes. Do not mark two expected /25 entries as an invalid /25 pool configuration merely because the route and configuration views use different prefix lengths.

## Official references

[Microsoft Learn: Configure address pools for Virtual WAN point-to-site VPN – PowerShell](https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell).

## Primary reference

- Name: Configure address pools for Virtual WAN point-to-site VPN - PowerShell - Azure Virtual WAN | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-wan/point-to-site-user-groups-powershell
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Reconcile both halves of a Virtual WAN P2S client pool in the route table,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-390-reconcile-both-halves-of-a-virtual-wan-p2s-client-pool-in-the-route-table/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
