MiroxMirox
  • Platform

    • Philosophy
    • Platform Overview
    • Platform Resources
  • Mirox-Cloud

    • Cloud Overview
    • Connected Microservices
  • Mirox-Agent

    • Agent Overview
    • Deployment Options
    • Data Scraper
    • Digital Twin
  • Technical Details

    • Metric Collection
  • Information

    • Supported Plants
  • Plant Types

    • Solar Plants
    • Wind Plants
    • Battery Storage
    • Alarm System
  • Monitoring & Visualization

    • Real-time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits & Curtailment
    • Efficiency Detection
    • KPI Dashboard
  • Data Management

    • Events
    • Tickets
    • Forecasts
    • Reports
    • Metrics
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • VPN Address Conflicts
    • Proxy
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Lockout
    • Permission System
    • Network Segmentation
    • Cooperation Restrictions
    • Access Audit Logging
    • Activity & Audit Trail
  • Nodes

    • mrxnode
  • Application

    • Door Control
    • Generic Relay
  • Edge Cluster

    • Orchestration
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Two-Factor Authentication
    • Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Contacts
    • Network Devices
    • Data Loggers
    • Components
    • Direct VPN (per Agent)
    • Data Volume
    • History Import
  • Organization

    • Member Permissions
    • Cooperations
    • File Storage
    • VPN Services
    • Working with Reports
  • Data Export

    • Export Metric API
    • MiroxQL Query Language
    • External Report Generation
    • Grafana
    • Grafana Dashboards
    • API Overview
  • Support

    • Request an Integration
  • mrxnode

    • Overview
    • How-To Guide
    • Container Deployment
    • Command Cheatsheet
    • Troubleshooting
  • Reporting

    • External Report Generator
    • Raw Data Export for Excel
  • Remote Access
  • AI in Mirox
  • History Import
  • Reports
  • English
  • Deutsch
  • Español
  • Français
  • Português
  • Italiano
  • English
  • Platform

    • Philosophy
    • Platform Overview
    • Platform Resources
  • Mirox-Cloud

    • Cloud Overview
    • Connected Microservices
  • Mirox-Agent

    • Agent Overview
    • Deployment Options
    • Data Scraper
    • Digital Twin
  • Technical Details

    • Metric Collection
  • Information

    • Supported Plants
  • Plant Types

    • Solar Plants
    • Wind Plants
    • Battery Storage
    • Alarm System
  • Monitoring & Visualization

    • Real-time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits & Curtailment
    • Efficiency Detection
    • KPI Dashboard
  • Data Management

    • Events
    • Tickets
    • Forecasts
    • Reports
    • Metrics
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • VPN Address Conflicts
    • Proxy
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Lockout
    • Permission System
    • Network Segmentation
    • Cooperation Restrictions
    • Access Audit Logging
    • Activity & Audit Trail
  • Nodes

    • mrxnode
  • Application

    • Door Control
    • Generic Relay
  • Edge Cluster

    • Orchestration
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Two-Factor Authentication
    • Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Contacts
    • Network Devices
    • Data Loggers
    • Components
    • Direct VPN (per Agent)
    • Data Volume
    • History Import
  • Organization

    • Member Permissions
    • Cooperations
    • File Storage
    • VPN Services
    • Working with Reports
  • Data Export

    • Export Metric API
    • MiroxQL Query Language
    • External Report Generation
    • Grafana
    • Grafana Dashboards
    • API Overview
  • Support

    • Request an Integration
  • mrxnode

    • Overview
    • How-To Guide
    • Container Deployment
    • Command Cheatsheet
    • Troubleshooting
  • Reporting

    • External Report Generator
    • Raw Data Export for Excel
  • Remote Access
  • AI in Mirox
  • History Import
  • Reports
  • English
  • Deutsch
  • Español
  • Français
  • Português
  • Italiano
  • English
  • Monitoring & Visualization

    • Real-Time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits and Curtailment
    • Efficiency Detection (PRRC)
    • Local Network Inspector
    • Access Monitoring
    • KPI Dashboard
    • Graph Visualization
  • Data Management

    • Events
    • Tickets
    • Forecasts
    • Reports
    • Metrics
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • VPN: Address Conflicts
    • Proxy (Web Access to Plant Devices)
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Temporarily Locked
    • Permission System
    • Network Segmentation
    • Cooperation Permission Restrictions
    • Access Audit Logging
    • Activity & Audit Trail

VPN: Address Conflicts

Your personal VPN reaches every private address in the plant networks you are authorized for — the whole of 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 and 100.64.0.0/10. Plant networks do not have to avoid the address ranges Mirox uses internally: the platform keeps its own traffic apart from yours.

Only the few addresses below are reserved. Most plants are never affected.

Overview

Address / rangeAffectsWhat cannot be reachedWhat to do
10.112.0.1every plantthis single addressre-address the device, or open its web interface through the Proxy
10.112.0.0/16every plant, only youthe one address your own VPN profile usesrevoke your profile and issue a new one; keep plant networks out of this range
the Direct VPN tunnel network: 10.95.0.0/16 (WireGuard), 10.94.0.0/16 (OpenVPN), 10.92.0.0/24 (IPsec)plants whose Direct VPN is hosted by Miroxthe tunnel's own address and the tunnel addresses of connected peers — if the plant network contains the tunnel's own address, that whole plant subnetkeep the plant network outside the tunnel network, or contact support to move the tunnel
172.16.10.0/24plants connected through an Organization VPN Servicethe addresses the organization VPN uses in this range — if the plant network is wider than this range, the whole rangekeep plant networks outside 172.16.10.0/24

The Reserved Addresses in Detail

10.112.0.1 — the VPN's own address

Every VPN profile connects to 10.112.0.1 — it is the VPN's own address, the point where your connection arrives at Mirox. A plant device that also uses 10.112.0.1 cannot be addressed over the VPN: your request reaches the VPN itself instead of the device. This is by design and cannot be removed, because the VPN needs one address of its own.

Workaround: give the device a different address, or open its web interface through the Proxy, which does not use the VPN.

10.112.0.0/16 — your own profile address

Each VPN profile receives one address from 10.112.0.0/16, chosen at random when the profile is issued. Your computer treats that address as itself, so if a plant device happens to use exactly the same address, only you cannot reach that one device. The platform cannot change this — the collision happens on your own device.

Workaround: revoke your VPN profile and issue a new one — a newly issued profile receives a new, randomly chosen address. Rotating is not enough: it replaces the keys but keeps the address. To avoid the situation altogether, keep plant networks out of 10.112.0.0/16.

The Direct VPN tunnel network

When a plant's router connects to Mirox through a Direct VPN, the tunnel between the router and Mirox runs on its own network: 10.95.0.0/16 for WireGuard, 10.94.0.0/16 for OpenVPN and 10.92.0.0/24 for IPsec. The addresses inside that tunnel belong to Mirox and to the connecting peers, not to the plant, so they cannot be reached as plant devices: the tunnel's own address (10.95.0.1, 10.94.0.1 or 10.92.0.1) and the address of each connected peer.

One case costs more. Mirox sends all traffic into the plant from the tunnel's own address. If the plant network contains that address, the plant devices treat it as a neighbour on their own network and answer it directly instead of through the router — the replies never arrive, and the whole plant subnet that contains the address cannot be reached.

Plants whose Direct VPN runs the other way — Mirox connecting out to the plant's router — are not affected: there, the plant's router assigns the tunnel addresses.

Workaround: choose plant networks outside the tunnel network. If a plant network cannot move, contact support to place the tunnel on a different network.

172.16.10.0/24 — Organization VPN Services

Plants connected through an Organization VPN Service share a common internal network, 172.16.10.0/24. The addresses the organization VPN uses in this range cannot be reached as plant devices. If the plant network is wider than this range — for example 172.16.0.0/16 — the whole of 172.16.10.0/24 cannot be reached.

Workaround: keep plant networks outside 172.16.10.0/24. Plants that are not connected through an Organization VPN Service are not affected — for them this range works normally.

Other Reasons an Address Is Not Reachable

These situations are not reserved addresses, but they cause the same symptom.

Two of your plants use the same subnet

Your tunnel can route one subnet to only one plant at a time. If two plants you can reach both use, for example, 192.168.1.0/24, the route overview marks the conflict and you choose which plant wins — you can switch at any time. See Resolve a Conflicting Subnet.

Your own local network overlaps the plant

If the network your computer is on — office, home or mobile hotspot — uses the same range as the plant, your computer sends that traffic to your local network instead of into the tunnel. This happens on your own device, so the platform cannot change it.

Workaround: connect from a different network, or ask your IT department to use a different local range.

The plant network uses public addresses

Only traffic for private address ranges enters the tunnel; everything else stays on your normal internet connection. A plant network that is numbered with public (non-private) addresses is therefore not reachable over the VPN.

Workaround: open the device's web interface through the Proxy, or have the plant network re-addressed into a private range.

Related Features

  • VPN
  • Personal VPN guide
  • Direct VPN
  • Organization VPN Services
  • Proxy
Prev
VPN
Next
Proxy (Web Access to Plant Devices)
© 2026 Mirox Verwaltungs GmbH. All rights reserved. | Privacy Policy