# Optimizing Pritunl VPN for AWS: Separating Private and Public Networks and Automating Route Addition

**URL:** <https://forum.pritunl.com/t/optimizing-pritunl-vpn-for-aws-separating-private-and-public-networks-and-automating-route-addition/2970>\
**Category:** Pritunl VPN\
**Tags:** pritunl-zero, pritunl-client, pritunl\
**Created:** [January 15, 2025, 3:11am UTC](https://forum.pritunl.com/t/optimizing-pritunl-vpn-for-aws-separating-private-and-public-networks-and-automating-route-addition/2970 "2025-01-15T03:11:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dima](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/d/e47c2d/32.png) [@Dima](https://forum.pritunl.com/u/Dima)\
**Post date:** [January 15, 2025, 3:11am UTC](https://forum.pritunl.com/t/optimizing-pritunl-vpn-for-aws-separating-private-and-public-networks-and-automating-route-addition/2970/1 "2025-01-15T03:11:54Z")

</div>

Hello Pritunl community,

I need assistance in optimizing my VPN structure for AWS using Pritunl. Here’s an overview of the current setup and the issues I’m facing:

### Current Setup:

- **Pritunl VPN** is running on EC2 with Okta SSO integration.
- Several VPCs are connected via **peering** in different AWS regions.
- I’m using specific routes for accessing each VPC, excluding the 0.0.0.0/0 route, and only including subnets like 10.1.0.0/24.
- AWS networks are uploaded to Pritunl using a Python script ([API documentation](https://docs.pritunl.com/docs/api)).

### Issue:

- The number of AWS networks is **overloading the route table** , which affects the performance and management of client connections.

### Questions:

1. **Can Pritunl be used separately for private and public AWS networks?** For example, could a dedicated Pritunl instance in Kubernetes be set up for private networks (e.g., 10.1.0.0/24)?
2. **Can two Pritunl clients be used in parallel** —one for public AWS networks and another for private VPC networks?
3. **Are there automation mechanisms for adding routes** in Pritunl, with the configuration stored in Git?

I’d appreciate your recommendations and advice on how to address these issues efficiently.

Thank you,  
Dmitry  
DevOps at Betterme

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [January 15, 2025, 3:32am UTC](https://forum.pritunl.com/t/optimizing-pritunl-vpn-for-aws-separating-private-and-public-networks-and-automating-route-addition/2970/2 "2025-01-15T03:32:12Z")

</div>

The [**tools/add\_aws\_ranges.py**](https://github.com/pritunl/pritunl/blob/master/tools/add_aws_ranges.py) script in the repository can be used to add routes, there isn’t any example of storing the routes on GitHub. The server is tested with 950 routes if there are issues with fewer routes it may help to upgrade the server. Older versions from several years ago could not handle a lot of routes if it is an older release it should be updated.

The client can connect to multiple servers at the same time with different sets of rotues.
