Help Center/ Virtual Private Network/ FAQs/ FAQs - S2C Enterprise Edition VPN/ Subnet Configurations/ What Are the Precautions for Configuring the Local and Customer Subnets for a VPN Connection?
Updated on 2025-05-14 GMT+08:00

What Are the Precautions for Configuring the Local and Customer Subnets for a VPN Connection?

  • The number of local subnets and the number of customer subnets are limited. If the number of local or customer subnets exceeds the upper limit, aggregate the subnets.
    • Maximum number of local subnets for each VPN gateway: 50
    • Maximum number of customer subnets for each VPN connection: 50
  • A local subnet cannot include the CIDR block of a customer subnet, whereas a customer subnet can include the CIDR block of a local subnet.
  • There are routes pointing to the local subnets in the VPC where the VPN gateway resides.
  • If there are two connections (connection A and connection B) created for a VPN gateway, and the customer subnet of connection A is within that of connection B, when the destination network to be accessed belongs to the overlapped CIDR block, the connection created first is matched first, regardless of the connection status. (Mask length match is not used for VPN connections created in policy-based mode.)