Recommended Posts

Hey guys,

 

Current setup - 172.16.50.0/24 with a superscope handing out address say 172.16.50.100 to 150 and 172.16.51.100 to 150

I have multiple sites connected via dark-fiber and am looking at moving to 172.16.50.0/21 which will give usable addresses of - 172.16.48.1 - 172.16.55.254.

 

All of my static assigned clients are reservations and I can work with Server 2016 DHCP to reconfigure that or re-make the entire scope if I have to do it manually. My main concern is, my core router and switches, can I set them manually as I move through this process to the new subnet or do I have to do all of this at once to ensure connectivity? All of the clients will reside within 172.16.50.0/24 until I have those devices totally changed. I assume since that range falls within the new subnet as well everything should still be able to talk.

 

Any suggestions or input would be great.

9 minutes ago, xendrome said:

I have multiple sites

That is great and all that your all connected via DWDM... But I really wouldn't suggest 1 flat network.. This gives you way less control if you need to do anything specific, etc.

 

I would plan out your address space so each site can have plenty of space and ability to segment as well for isolation of different classes of devices and or users, etc.

4 minutes ago, BudMan said:

That is great and all that your all connected via DWDM... But I really wouldn't suggest 1 flat network.. This gives you way less control if you need to do anything specific, etc.

 

I would plan out your address space so each site can have plenty of space and ability to segment as well for isolation of different classes of devices and or users, etc.

Well let me rephrase it. These are buildings all on a single campus, next to or across from each other. Each building has just a few computers, some have 4, some have 15. For a total of about 89 systems. We are currently running Unifi APs with a guest network which are isolated and we see a lot of temp connections throughout the day from ipads, cell phones, apple watches, etc taking up a lot of address space.

 

I don't really want to segment the buildings from each other as they do share resources, printers, servers between each other. 

 

My biggest concern is the order at which the resubnetting has to be done.

Yeah so what if they share.. Being on multiple segments has nothing to do with with accessing a printer or a file share.

 

If your to the point that your thinking of using a /21 because of addresses needed..  Buildings, shoot even floors in the same building should be on their own segments..

 

If you have only 89 systems, what is the point of a /21?

 

Your wireless for damn sure should be on its own segment!!!

Just now, BudMan said:

Yeah so what if they share.. Being on multiple segments has nothing to do with with accessing a printer or a file share.

 

If your to the point that your thinking of using a /21 because of addresses needed..  Buildings, shoot even floors in the same building should be on their own segments..

 

If you have only 89 systems, what is the point of a /21?

Well if you have a better suggestion on the subnet I should use I am all ears, with the static devices, wireless clients, etc, our DHCP range is running out of IPs and everything I've read Superscopes are not really recommended. I don't really want to get down into VLANs or separating buildings/floors. I can give you more details on the setup as well if necessary.

If you need more addresses, you need more address - I would prob look to just using a lower lease time if you have a bunch of devices temp jumping on some guest network..

 

First thing I would do is isolate your wifi to its own segment..   You could give it a /16 if you have so many devices jumping on and off, etc.  What it does for its address space doesn't effect your actual network once you segment it off.

 

Why do you not want control of your devices either at a logical level or a security level..  Types of devices for sure should be on their own segment.. Lets say your printer was compromised.

https://arstechnica.com/information-technology/2019/08/microsoft-catches-russian-state-hackers-using-iot-devices-to-breach-networks/

 

Why should your printers be able to talk to anything on your network?  The communication from users/servers to printers should be 1 way..  You accomplish this via putting your printers (and any other iot devices) on their own segments.. And then via your firewall not allowing them to create unsolicated traffic to anything else on your network - unless its actually required.. say dns, or some server to check for files it printers - maybe a log server, etc.

 

Are you running private vlans?  If your just on 1 big L2 - then any device can talk to any other device on any port.. So idiot user #1 gets his box infected - how do you stop it from taking to everything else on your network?  There are many different methods of segmenting out your network best depending on a companies needs and use cases, etc.  But segmentation gives you ability to control connectivity outside user permissions and host firewalls.  Allows you to contain any sort of outbreak of the next wanna cry worm - or whatever the next ransomware thing might be.. There is one thing to limit a users account to only what it needs access to... But there are many devices that have zero reason to even talk to say a server, or other user devices.  Be it they have a valid account or not - if they can talk to the service, it could be exploited via some zero day or unpatched issue, etc..

 

I personally would take the opportunity of needing more address space to rethink your whole network layout and provide for isolation..  The very act of segmenting your different devices will give you way more flexibility in growing address space for a specific segment..

  • Like 2
This topic is now closed to further replies.
  • Posts

    • How to Do More with Less: Future-Proofing Yourself in an AI-driven Economy —was $28 now FREE by Steven Parker Claim your complimentary copy (worth $28) of "How to Do More with Less: Future-Proofing Yourself in an AI-driven Economy" for free, before the offer ends on June 30. Description In today’s workplace, headlines about artificial intelligence can feel overwhelming. With headlines swinging between promises of utopia and warnings of mass unemployment, for most knowledge workers, the truth feels unclear. In this book, Sharon Gai cuts through the noise. Drawing from real-world examples and global insights, she explains how AI is reshaping the way we work—without hype or fearmongering. Instead of choosing between blind optimism or outright pessimism, she offers a practical, balanced perspective that helps readers make sense of the rapidly evolving AI landscape. You’ll learn how to: Reskill and future-proof your career in the face of AI disruption Identify which parts of your role can be automated, and which require human creativity and judgment Use proven frameworks to evaluate AI’s impact on your work and your organization Apply actionable tips and tools to boost productivity, make smarter decisions, and do more with less Gain clarity as a parent, leader, or professional navigating what this means for the next generation Whether you’re an employee anxious about your future, a parent concerned about your children’s opportunities, or a leader managing a lean team with tight budgets, this book provides the strategies and mindset you need to adapt so you can stop worrying and start preparing. How to download for free Please ensure you read the terms and conditions to claim this offer. Complete and verifiable information is required in order to receive this free offer. If you have previously made use of these offers, you will not need to re-register. Was $28, but is now FREE | Below free offer link expires on June 30. How to Do More with Less: Future-Proofing Yourself in an AI-driven Economy The below offers are also available for free in exchange for your (work) email: The Vibe Coding Playbook: Building Your Tech Business with AI ($35 Value) FREE - Expires 6/23 The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing to Understand and Win Customers ($28 Value) FREE - Expires 6/24 How to Do More with Less: Future-Proofing Yourself in an AI-driven Economy ($28 Value) FREE - Expires 6/30 Cloud Security Fundamentals: Building the Foundations for Secure Cloud Platforms ($131.95 Value) FREE - Expires 7/1 The Complete Free AI Learning: Master ChatGPT, Claude, Gemini & More ($21 Value) FREE How to Build an AI Design Workflow with Gamma ($21 Value) FREE The Ultimate Linux Newbie Guide – Featured Free content Python Notes for Professionals – Featured Free content Learn Linux in 5 Days – Featured Free content Quick Reference Guide for Cybersecurity – Featured Free content We post these because we earn commission on each lead so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. Other ways to support Neowin The above deal not doing it for you, but still want to help? Check out the links below. Check out our partner software in the Neowin Store Buy a T-shirt at Neowin's Threadsquad Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: An account at Neowin Deals is required to participate in any deals powered by our affiliate, StackCommerce. For a full description of StackCommerce's privacy guidelines, go here. Neowin benefits from shared revenue of each sale made through the branded deals site.
    • Microsoft admits one of the most crucial Outlook features is currently broken by Sayan Sen Microsoft is making some decent progress when it comes to Windows 11. Recently we have confirmed reports of some rather useful improvements landing in the next version of the OS, 26H2, wherein GPU driver TDR crashes may finally be fixed, plus the company is also allowing users to disable web content on the Search. On the Outlook front though things have not been so rosy. Last month in May we reported several problems affecting basic functionalities on the app. These included a problem where documents would open blank or corrupt themselves. Following that, Quick Steps, a very useful feature, would no longer work correctly, and finally, Microsoft acknowledged a problem wherein images would fail to load up properly inside the email. Microsoft had resolved those bugs later and almost exactly a month after we reported on them, the company has now admitted a new similarly basic issue, this time on Macs. Users recently started noticing that Outlook would no longer display email threads properly as the original message itself was not displayed. An affected user Tsoumpas, C (ngmb) nicely described the problem in a forum post they made on Microsoft's site. They wrote: "Description of the issue: After updating Outlook for Mac [Version 16.110 (26061317)] on 18/6/2026, replying to any email no longer includes the original message in the reply window. Prior to the update, replies correctly contained the original email text below my response. Expected behavior: The original message should be included in the reply, as in previous Outlook versions and according to the configured reply settings. Actual behavior: The reply window contains only a blank composition area (or only my response), with none of the original email text included." Obviously this must be a highly frustrating for users as noted by several in that thread. The post, at the time of writing, has also been upvoted by more than 40 users indicating that is a fairly widespread bug. Thankfully Microsoft seems to have acknowledged the problem right around that time as it opened a new issue on its official website. In the support article, the company recommends switching to Outlook for Mac from the legacy app, where the problem appears to be happening.
    • PotPlayer 260622 by Razvan Serea PotPlayer is an extremely light-weight multimedia player for Windows. It feels like the KMPlayer, but is in active development. Supports almost every available video formats out there. PotPlayer contains internal codecs and there is no need to install codecs manually. Other key features include WebCam/Analog/Digital TV devices support, gapless video playback, DXVA, live broadcasting. Distinctive features of the player is a high quality playback, support for all modern video and audio formats and a built DXVA video codecs. A wide range of subtitles are supported and you are also able to capture audio, video, and screenshots. A comprehensive video and audio player, that also supports TV channels, subtitles and skins. Its been described on the Internet as The KMPlayer redux, and it pretty much is. Daum PotPlayer 260622 (1.7.22963) changelog: Removed Kakao TV Added pause function when navigating via the navigation bar Significantly improved internal stability Fixed an issue where colors appeared strange during RGB24 processing Improved playback for some HTTP streams Improved sync processing for the built-in audio renderer Fixed an issue where certain MP4 files behaved abnormally during playback Download: Daum PotPlayer (64-bit) | 54.7 MB (Freeware) Download: Daum PotPlayer (32-bit) | 61.1 MB View: Daum PotPlayer Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Tixati 3.44 is out.
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      522
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      94
    4. 4
      Michael Scrip
      82
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!