VPN: Address Conflicts
Your personal VPN reaches every private address in the plant networks you are authorized for — the whole of 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 and 100.64.0.0/10. Plant networks do not have to avoid the address ranges Mirox uses internally: the platform keeps its own traffic apart from yours.
Only the few addresses below are reserved. Most plants are never affected.
Overview
| Address / range | Affects | What cannot be reached | What to do |
|---|---|---|---|
10.112.0.1 | every plant | this single address | re-address the device, or open its web interface through the Proxy |
10.112.0.0/16 | every plant, only you | the one address your own VPN profile uses | revoke your profile and issue a new one; keep plant networks out of this range |
the Direct VPN tunnel network: 10.95.0.0/16 (WireGuard), 10.94.0.0/16 (OpenVPN), 10.92.0.0/24 (IPsec) | plants whose Direct VPN is hosted by Mirox | the tunnel's own address and the tunnel addresses of connected peers — if the plant network contains the tunnel's own address, that whole plant subnet | keep the plant network outside the tunnel network, or contact support to move the tunnel |
172.16.10.0/24 | plants connected through an Organization VPN Service | the addresses the organization VPN uses in this range — if the plant network is wider than this range, the whole range | keep plant networks outside 172.16.10.0/24 |
The Reserved Addresses in Detail
10.112.0.1 — the VPN's own address
Every VPN profile connects to 10.112.0.1 — it is the VPN's own address, the point where your connection arrives at Mirox. A plant device that also uses 10.112.0.1 cannot be addressed over the VPN: your request reaches the VPN itself instead of the device. This is by design and cannot be removed, because the VPN needs one address of its own.
Workaround: give the device a different address, or open its web interface through the Proxy, which does not use the VPN.
10.112.0.0/16 — your own profile address
Each VPN profile receives one address from 10.112.0.0/16, chosen at random when the profile is issued. Your computer treats that address as itself, so if a plant device happens to use exactly the same address, only you cannot reach that one device. The platform cannot change this — the collision happens on your own device.
Workaround: revoke your VPN profile and issue a new one — a newly issued profile receives a new, randomly chosen address. Rotating is not enough: it replaces the keys but keeps the address. To avoid the situation altogether, keep plant networks out of 10.112.0.0/16.
The Direct VPN tunnel network
When a plant's router connects to Mirox through a Direct VPN, the tunnel between the router and Mirox runs on its own network: 10.95.0.0/16 for WireGuard, 10.94.0.0/16 for OpenVPN and 10.92.0.0/24 for IPsec. The addresses inside that tunnel belong to Mirox and to the connecting peers, not to the plant, so they cannot be reached as plant devices: the tunnel's own address (10.95.0.1, 10.94.0.1 or 10.92.0.1) and the address of each connected peer.
One case costs more. Mirox sends all traffic into the plant from the tunnel's own address. If the plant network contains that address, the plant devices treat it as a neighbour on their own network and answer it directly instead of through the router — the replies never arrive, and the whole plant subnet that contains the address cannot be reached.
Plants whose Direct VPN runs the other way — Mirox connecting out to the plant's router — are not affected: there, the plant's router assigns the tunnel addresses.
Workaround: choose plant networks outside the tunnel network. If a plant network cannot move, contact support to place the tunnel on a different network.
172.16.10.0/24 — Organization VPN Services
Plants connected through an Organization VPN Service share a common internal network, 172.16.10.0/24. The addresses the organization VPN uses in this range cannot be reached as plant devices. If the plant network is wider than this range — for example 172.16.0.0/16 — the whole of 172.16.10.0/24 cannot be reached.
Workaround: keep plant networks outside 172.16.10.0/24. Plants that are not connected through an Organization VPN Service are not affected — for them this range works normally.
Other Reasons an Address Is Not Reachable
These situations are not reserved addresses, but they cause the same symptom.
Two of your plants use the same subnet
Your tunnel can route one subnet to only one plant at a time. If two plants you can reach both use, for example, 192.168.1.0/24, the route overview marks the conflict and you choose which plant wins — you can switch at any time. See Resolve a Conflicting Subnet.
Your own local network overlaps the plant
If the network your computer is on — office, home or mobile hotspot — uses the same range as the plant, your computer sends that traffic to your local network instead of into the tunnel. This happens on your own device, so the platform cannot change it.
Workaround: connect from a different network, or ask your IT department to use a different local range.
The plant network uses public addresses
Only traffic for private address ranges enters the tunnel; everything else stays on your normal internet connection. A plant network that is numbered with public (non-private) addresses is therefore not reachable over the VPN.
Workaround: open the device's web interface through the Proxy, or have the plant network re-addressed into a private range.