# How to block client-to-client traffic on the same VPN server (Virtual Network)?

**URL:** <https://forum.pritunl.com/t/how-to-block-client-to-client-traffic-on-the-same-vpn-server-virtual-network/3658>\
**Category:** Pritunl VPN\
**Tags:** pritunl, pritunl-client\
**Created:** [December 17, 2025, 2:03am UTC](https://forum.pritunl.com/t/how-to-block-client-to-client-traffic-on-the-same-vpn-server-virtual-network/3658 "2025-12-17T02:03:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jay](https://forum.pritunl.com/user_avatar/forum.pritunl.com/jay/32/1319_2.png) [@jay](https://forum.pritunl.com/u/jay)\
**Post date:** [December 17, 2025, 2:03am UTC](https://forum.pritunl.com/t/how-to-block-client-to-client-traffic-on-the-same-vpn-server-virtual-network/3658/1 "2025-12-17T02:03:15Z")

</div>

Hello,

I am running into a security concern related to **client-to-client communication** on a Pritunl VPN server and would appreciate guidance on the correct or recommended approach.

**Scenario:**

- Office machines are connected to a Pritunl VPN server.

- A user connects to the **same VPN server from home**.

- Because both clients are on the same **Virtual Network** , the home client can directly access office machines via their VPN IP addresses.

- This behavior violates our internal security policy, as VPN users should only access internal services, **not other client endpoints**.

**Current understanding:**

- This seems to be caused by routing within the Virtual Network (client-to-client traffic being allowed).

- Disabling **Multiple Devices** partially mitigates this, but it is not ideal, as the feature is still useful for other legitimate cases.

**Questions:**

1. Is there an official or recommended way in Pritunl to **block client-to-client traffic** on the same VPN server?

2. Can this be enforced via:

3. Is there a way to allow access only to specific internal subnets while explicitly **preventing traffic between VPN clients**?

---

<div class="post-metadata">

**Author:** ![Moor](https://forum.pritunl.com/user_avatar/forum.pritunl.com/moor/32/1002_2.png) [@Moor](https://forum.pritunl.com/u/Moor)\
**Post date:** [December 17, 2025, 9:05am UTC](https://forum.pritunl.com/t/how-to-block-client-to-client-traffic-on-the-same-vpn-server-virtual-network/3658/2 "2025-12-17T09:05:11Z")

</div>

Hi,

> [@jay](#):
>
> Is there an official or recommended way in Pritunl to **block client-to-client traffic** on the same VPN server?

You can disable connections between clients by turning off the **“Inter-Client Routing”** option in the VPN server settings. I would also recommend enabling **“Restrict Routing”** for better isolation.

> [@jay](#):
>
> Is there a way to allow access only to specific internal subnets while explicitly **preventing traffic between VPN clients**?

You simply need to add the specific networks you want clients to access under the server’s **Routes** tab. [Routes | Pritunl VPN | Pritunl Documentation](https://docs.pritunl.com/kb/vpn/servers/routing)

I highly recommend avoiding the default route `0.0.0.0/0` if the VPN is used strictly for private network access - especially if your Pritunl instance is hosted in the cloud.

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [December 17, 2025, 11:46am UTC](https://forum.pritunl.com/t/how-to-block-client-to-client-traffic-on-the-same-vpn-server-virtual-network/3658/3 "2025-12-17T11:46:49Z")

</div>

There isn’t any option to disable client-to-client routing. It is difficult to do without breaking other functionality. The Inter-Client Routing option is specifically for disabling the client routes created for replicated servers. This allows client traffic to move between hosts running a replicated server.

---

<div class="post-metadata">

**Author:** ![Moor](https://forum.pritunl.com/user_avatar/forum.pritunl.com/moor/32/1002_2.png) [@Moor](https://forum.pritunl.com/u/Moor)\
**Post date:** [December 17, 2025, 11:52am UTC](https://forum.pritunl.com/t/how-to-block-client-to-client-traffic-on-the-same-vpn-server-virtual-network/3658/4 "2025-12-17T11:52:11Z")

</div>

Understood. In that scenario, another workaround would be to enforce firewall rules on the client side.
