BGP VPN Subnet Generator

Generate point-to-point subnets for route-based IPsec VPNs and BGP peering. Easily split IP pools into Local and Remote endpoints, including CVI and NDI assignments for HA firewall clusters.

Configuration

Why use 169.254.0.0/16 for VPNs?

The 169.254.0.0/16 subnet is officially designated as Link-Local IPv4 address space. In the context of route-based VPNs (especially in cloud environments like AWS, Azure, and GCP), it is the "gold standard" for Virtual Tunnel Interfaces (VTIs) because:

Which subnet mask should I choose?

How to use BGP VPN P2P Generator

Allocate aligned point-to-point transit networks and endpoint addresses for VPN and BGP peerings.

Worked example

A /30 provides two traditional usable endpoints; a /31 provides two RFC 3021 peer addresses without network and broadcast waste.

Common mistake

Confirm both devices support /31 point-to-point addressing before choosing it.