I noticed that the clients are being assigned IPs out of RFC6598 space (“Carrier-grade NAT” – There is a reasonable chance that this will cause breakage for people using the VPN on their phones or otherwise directly connected to ISPs using CGNAT. Should it be a private range like Private-Use Networks RFC 1918 ?

