Solved

Need to add an additional subnet

Posted on 2009-05-12
11
249 Views
Last Modified: 2012-05-06
We are currently using subnet 192.168.0.X and will soon be adding more devices.  At that point we will run out of IP addresses.  I want to add subnet 192.168.1.X.  We are using a Cisco ASA5510 (as our firewall/default gateway, ip address 192.168.0.1) and a Cisco switch stack.  I have added another scope to our DHCP server (192.168.1.X) and created a Superscope with both the existing scope and the new scope.  I configured an additional interface on the ASA5510 and connected it to our switch stack, although I'm not sure if that was necessary.  I also created another subnet in Active Directory Sites and Services (the orignal subnet wasn't listed, so I added that as well).  I can create a reservation on the new scope and use an ip address from it, but that computer cannot see any network resources or access the internet.  I know I am missing something (maybe at the switch?), but I'm not sure what.  Help!
0
Comment
Question by:NBTexas
  • 5
  • 5
11 Comments
 
LVL 2

Expert Comment

by:CBalderson
ID: 24366386
Sounds like a routing problem...

You have a single switch stack with more than 254 ports ( All located at the same site)?  

For the second subnet you added 192.168.1.x.
Can the client who gets the reservation ping the gateway on the ASA5510 (192.168.1.1)?
0
 

Author Comment

by:NBTexas
ID: 24366470
We have three 48 port switches in the stack and one site.  We are running out of IP addresses because we use NetMotion to connect our mobile clients and it assigns two IP addresses from the scope - one is a virtual IP and the other is a Point of Presence IP.  We have close to 100 mobile clients, so we are using almost 200 IP addresses just for them.  I can ping the 192.168.1.1 gateway from the client with the reservation.
0
 
LVL 2

Expert Comment

by:CBalderson
ID: 24366851
Ok, can you add a second client to the 192.168.1.x subnet to be sure intra subnet traffic works?

I think we need to check and be sure there is a rule on the ASA allowing the traffic between the two subnets after we ensure that local is working first.

0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 

Author Comment

by:NBTexas
ID: 24367657
I added a second client on the 192.168.1.x subnet and both clients can ping each other.
0
 
LVL 2

Expert Comment

by:CBalderson
ID: 24367935
Good, can you see if you have any policies that allow traffic between the two...
Example
access-list 101 permit ip 192.168.0.0 255.255.255.0 192.168.1.0 255.255.255.0
0
 
LVL 7

Expert Comment

by:MariusSunchaser
ID: 24374978
Hi there.
Clients in the 192.168.1 network get the ip correctly from the DHCP server and can't talk with the computers in the 192.168.0 network, or do they have problems with getting a correct IP?
For troubleshooting, perform these steps:
1. Assign manually an IP in the 192.168.1 network, and see if things work. If they don't, tell us how far the connectivity goes. (Can it ping the ASA interface in the 192.168.0 network?)
2. Connect 2 hosts in the 192.168.1 network. Let them get IP through DHCP. Can they ping each other? Can they ping ASA's interface in their network? Can they ping ASA's interface in the other network?

Please update us with these information, to see if it's a routing problem, a DHCP problem, or maybe a problem with the DHCP relay client.
0
 

Author Comment

by:NBTexas
ID: 24376526
I have spoken to Cisco about this problem.  Apparently, it is a switch stack problem.  According to Cisco, I need to create an additional VLAN and enable IP routing on my switch stack.  Currently, all ports are in one VLAN.  They tell me that I have to create a second VLAN and include the ports that are to be on the new subnet.  This will be problematic, since I am not sure what is connected to each port.  I thought this would be a much easier task than it has turned out to be.  I should know better!
0
 
LVL 2

Expert Comment

by:CBalderson
ID: 24376845
That is ok, you can get it sorted if you want.
show mac-address-table
sh arp
Between the two you can map who is connected to what switchport.

I'd suggest you put all of your ports in the same VLAN and then begin splitting the VLAN if you want to implement the VLAN.

Have you considered using a Class B subnet mask 255.255.0.0?
0
 

Author Comment

by:NBTexas
ID: 24377470
I have considered changing the subnet mask.  Are there any issues with doing that?
0
 
LVL 2

Expert Comment

by:CBalderson
ID: 24377505
Not really.  Until all existing clients update they will think the old mask is still valid and will not be able to talk to new client in the extended range.  Depending on your DHCP lease and how many Static systems you have to update it could be a very quick shift.
0
 

Accepted Solution

by:
NBTexas earned 0 total points
ID: 24425413
I guess there are two possible solutions to this problem.  1. Create an additional VLAN on the switch stack and enable IP routing, or 2. Try another subnet mask.  We are going to try solution #2 and see what happens.  Thanks to everyone who responded to my question.
0

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Automated backups of ASA's and Nexus (5k and 7K) 24 93
Home wifi - Does it matter what router? 9 55
Setting up static routes to  sonicwll 4 74
Sonicwall one way trust 2 42
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question