Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.2.2. Tunnel Types and Configuration

P2S supports three tunnel protocols, each with different capabilities:

ProtocolPlatformsPortsBest For
IKEv2Windows, macOS, iOSUDP 500, 4500Native clients, best performance
SSTPWindows onlyTCP 443Restrictive firewalls (HTTPS port)
OpenVPNAll platformsTCP/UDP 443Cross-platform, Azure AD auth

Client Configuration: After configuring the gateway, download the VPN client package:

  • Windows: Native or OpenVPN client
  • macOS/iOS: Native IKEv2 or OpenVPN
  • Linux: OpenVPN client

Address pool defines the IP range assigned to connected clients. This pool must not overlap with VNet address spaces or on-premises networks.

💡 Design tip: Size the address pool for peak concurrent connections plus 20% buffer. A /24 gives you 251 usable addresses—plenty for most scenarios.

Alvin Varughese
Written byAlvin Varughese
Founder•15 professional certifications