# Mac users report unexpected 2000::/3 route injection

**URL:** https://forum.pritunl.com/t/mac-users-report-unexpected-2000-3-route-injection/2579
**Category:** Pritunl VPN
**Tags:** pritunl-client
**Created:** [November 4, 2024, 8:35am UTC](https://forum.pritunl.com/t/mac-users-report-unexpected-2000-3-route-injection/2579 "2024-11-04T08:35:01Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![tmshlvck](https://forum.pritunl.com/user_avatar/forum.pritunl.com/tmshlvck/32/48_2.png) [@tmshlvck](https://forum.pritunl.com/u/tmshlvck)
#### Post date: [November 4, 2024, 8:35am UTC](https://forum.pritunl.com/t/mac-users-report-unexpected-2000-3-route-injection/2579/1 "2024-11-04T08:35:01Z")

</div>

Hi!

Mac users are reporting that the newest client is injecting `2000::/3` route even when the disable default route is ticked. It happens with a recently deployed server (`v1.32.3805.95`) that is sending both IPv4 and IPv6 default routes (`0.0.0.0/0` + `::/0` are in config).

Interestingly, it happens only with OpenVPN and not in WG mode.

OpenVPN:

```auto
ip -6 route 15:29:30
default via fe80::46fe:3bff:fe73:584d%en0 dev en0
::1 via ::1 dev lo0
2000::/3 via utun8 dev utun8
2001:4c08:2003:b09::/64 via utun8 dev utun8
2600:c00:2:100::/56 via utun8 dev utun8
2602:fb2b:100::/48 via utun8 dev utun8
2602:fb2b:110::/49 via utun8 dev utun8
2602:fb2b:110:1000::/64 via fe80::34f8:5142:2259:8921%utun8 dev utun8
2602:fb2b:110:1000:a0e8:0:a0e8:3 dev lo0 scope link
2602:fb2b:110:1001:a0e8::/96 via utun8 dev utun8
2602:fb2b:110:ff00::a001 via fe80::46fe:3bff:fe73:584d%en0 dev en0
2602:fb2b:120::/48 via utun8 dev utun8
2604:6800:258::/63 via utun8 dev utun8
2a00:fb01:400::/56 via utun8 dev utun8
2a00:fb01:400:200::/64 via utun8 dev utun8
2a04:ee41:3:f403::/64 dev en0 scope link
2a0b:21c0:4003::/62 via utun8 dev utun8
2a0b:21c0:4006:100::/56 via utun8 dev utun8
2a0b:21c0:b002:2::/64 via utun8 dev utun8

```

WG:

```auto
ip -6 route 15:30:09
default via fe80::46fe:3bff:fe73:584d%en0 dev en0
::1 via ::1 dev lo0
2001:4c08:2003:b09::/64 via utun8 dev utun8
2600:c00:2:100::/56 via utun8 dev utun8
2602:fb2b:100::/48 via utun8 dev utun8
2602:fb2b:110::/49 via utun8 dev utun8
2602:fb2b:110:1000:a0e8::/96 via utun8 dev utun8
2602:fb2b:110:1001::/64 via fe80::34f8:5142:2259:8921%utun8 dev utun8
2602:fb2b:110:1001:a0e8::/96 via utun8 dev utun8
2602:fb2b:110:1001:a0e8:0:a0e8:7fa dev lo0 scope link
2602:fb2b:120::/48 via utun8 dev utun8
2604:6800:258::/63 via utun8 dev utun8
2a00:fb01:400::/56 via utun8 dev utun8
2a00:fb01:400:200::/64 via utun8 dev utun8
2a04:ee41:3:f403::/64 dev en0 scope link
2a04:ee41:3:f403:a8:82f8:ea7d:dd80 via e2:72:1e:c8:d1:ac dev lo0
2a04:ee41:3:f403:b8f2:571b:5277:4157 via e2:72:1e:c8:d1:ac dev lo0
2a0b:21c0:4003::/62 via utun8 dev utun8
2a0b:21c0:4006:100::/56 via utun8 dev utun8
2a0b:21c0:b002:2::/64 via utun8 dev utun8

```

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [November 4, 2024, 9:37am UTC](https://forum.pritunl.com/t/mac-users-report-unexpected-2000-3-route-injection/2579/2 "2024-11-04T09:37:34Z")

</div>

This is similar to routing `0.0.0.0/1` and `128.0.0.0/1` in IPv4 to avoid effecting the default gateway. The range `2000::/3` covers all public (global unicast) IPv6 addresses. It’s done in [**pritunl/clients/clients.py**](https://github.com/pritunl/pritunl/blob/master/pritunl/clients/clients.py#L195). This has been done for a while now.

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [November 4, 2024, 9:41am UTC](https://forum.pritunl.com/t/mac-users-report-unexpected-2000-3-route-injection/2579/3 "2024-11-04T09:41:16Z")

</div>

The issue has been fixed in the client repository to ignore this route when disable gateway is enabled. This will be included in the next release this week.
