Reconcile both halves of a Virtual WAN P2S client pool in the route table

Why can a configured Virtual WAN P2S /24 address pool appear as two /25 routes?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Why can a configured Virtual WAN P2S /24 address pool appear as two /25 routes?

Potentially affected

Use this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route's more-specific prefix as a missing or unexpected address allocation.

DSE recommendation

Compare the configured pool with the combined effective routes.

Source facts

Microsoft documents that a Virtual WAN point-to-site gateway splits each client address pool between its two active-active instances. The effective route table should show the resulting halves; the source’s /24 example therefore produces two /25 routes. The configured pool itself cannot be smaller than /24 and must not overlap other connection pools, virtual networks, virtual hubs or on-premises addresses. Microsoft Learn.

Applicability

Use this interpretation when reviewing a Virtual WAN P2S multi-pool configuration. Confirm the intended gateway and configured pool before treating a route’s more-specific prefix as a missing or unexpected address allocation.

DSE recommendation

Compare the configured pool with the combined effective routes. Have the network owner reconcile both halves to the approved address plan and distinguish configured pool size from the routes representing its gateway instances. If a half is absent, investigate the actual gateway and connection configuration before changing the range. Keep the original pool and route observations with the case so a later change does not erase the evidence of what was missing.

Verification

Inspect the effective route table and verify that the paired prefixes cover the intended pool without introducing overlaps. Test approved client connections and record their assigned addresses alongside the corresponding route. Check required connection associations and propagation if clients cannot receive routes. Do not mark two expected /25 entries as an invalid /25 pool configuration merely because the route and configuration views use different prefix lengths.

Official references

Microsoft Learn: Configure address pools for Virtual WAN point-to-site VPN – PowerShell.

Primary reference

Review the official source

Configure address pools for Virtual WAN point-to-site VPN - PowerShell - Azure Virtual WAN | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE