Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Assigning two seperate IP ranges

Posted on 2009-07-13
Medium Priority
Last Modified: 2012-05-07
Hey all,

We have hit a potential issue - we're running out of IP Addresses in the externally assigned range. We've spoken to Time Warner Cable who provide us with our ethernet connection and they've said they can assign us an additional range, but it will not be sequential from the current range.

All fine with that, we don't really care - we just need more IP's.

Problem being, the Time Warner ethernet connection plugs directly into one of the ethernet ports on our Sonicwall (Sonicwall 3060 - assume latest firmware, if it's not we can update it without issue). From what I can see, there is no way of assigning two external IP ranges to the same port on SonicOS.

My question would be, what would we need to purchase / do to allow the Sonicwall to use the two seperate ranges, even though they're being delivered on the same media - note, that if this involves buying a router or such to sit between the Sonicwall and the provider, then that's fine.

A thought that's just come to me, would it be as simple as hooking the delivered ethernet connection into a hub (taking layer 3 out of the equation) and then two ports from the hub into two interfaces on the Sonicwall and assigning their seperate address ranges?
Question by:skiddy89
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1

Expert Comment

ID: 24842805
Call timewarner and tell them you want a routed block they can assign you /30 and route both of your blocks thru that ip address, or you can ask them to route the new block through your current block using the address of your sonic firewall as the default gateway.

Author Comment

ID: 24842975
I don't think the issue is getting Time Warner to assign the addresses - they've already said that they can assign the addresses without issue at their end.

The problem I'm having a tough time getting my head around is where on the Sonicwall I can assign the additional range details, or at least how I can work around this. At the moment, an external IP is assigned to the Sonicwall and lets say a /29 is set as being the subnet mask. If the ranges aren't consecutive ranges, and I can't set two subnets as being assigned to one interface, how do we get around the "address is not in range" error that will inevitably appear when I try and add address objects based on the new range?

Expert Comment

ID: 24844758
sorry i dont know enough about sonic firewall to answer that part different with ASA's
Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.


Expert Comment

ID: 24846378

I understand that you are having internet from single ISP i.e. TW Cable and using pool of LAN ip address. Now this ip pool is exhausted so you are going for another pool of ips (different range!). How to use this new pool? TW Cable is directly terminated on Sonicwall device.

Advice to go for Standard network design for scalability as below:

      WAN Link > Internet router/L3 Device > Firewall > LAN

As per your budget, you may plan for Cisco Router/L3 Switch for termination of the WAN link (internet).

Any additional ip pool range you get from ISP can be used in LAN by assigning gateway ip address to Router LAN interface.
Additional WAN links also can be terminated on router for failover and high availability without any much network changes.

Does this answer your query!, any more info required?
LVL 16

Expert Comment

by:Aaron Street
ID: 24848123
you just need a simple router like ken suggests.

then you can assign mutiply IP address to the wan interface.

you also may be able to get your ISP to assign your current router inside your fire wall as the next hop for getting to the new IP network.

then you set up the routing your end.

so say you have a current ip range of and your router is

you get a new range 192.168.10/24

your ISP then assigns a route  on there router that borders you of

so all traffic comming on to your site is still going to the origianl ip address range.

your internal router then deals with splitting it off to its own network.

Now I am not sure if they will set this up for you. but if they did you could achive what you want with out any changes to hard ware as long as you ahve some routing cababilities within you network they can direcct the traffic to.

Author Comment

ID: 24850166
So, in this scenario, we'd have a router which would have two seperate ranges assigned to one interface. The internal interface on the router would plug directly into the currently used interface on the Sonicwall.

But we still have no way of assigning the two ranges to the Sonicwall as it only allows one range to be entered per interface, thus when we try to enter a mapping on the Sonicwall for one of the external IP's it'll just tell me that the address is not within the allocated range.

I know what you're both saying above, I appreciate that - what I don't see a solution to is how to get the two ranges to be recognised by the sonicwall.
LVL 16

Expert Comment

by:Aaron Street
ID: 24850315
ahh get you

mmmm that may be more dificult. it will really depend if the fire wall si built to deal with two ranges.

the only other way to get around this would be to "supernet" the two ranges in to one. Now i understand that they will nto be continious, but if they are quie close you could then simple refilter out any of the range that dose not belong to you?


Author Comment

ID: 24850475
Yeah, that's what I'd thought - the range hasn't been assigned yet, so we're not sure what it will be - this "issue" was brought up before we ordered the additional range and we all sat around for a while scratching our heads wondering how we were going to do it.

It's a class C range that we currently have, and we're currently assigned x IP's - I know TWC have already stated that they cannot give us continuous addresses as the next range up and down are both allocated already. Lets say that they're currently assigned range is /29 and they give us the new range on the same scope - I've no problem setting my subnet mask on the Sonicwall to be /24 (!) if needed and setting static routes to the provider gateway to addresses that I've carpet bombed in my subnet allocation.
LVL 16

Accepted Solution

Aaron Street earned 2000 total points
ID: 24850575
yer as long as the isp dosen't route thoses ranges to you there should be no problem.

I would still suggest you in futre get a firwall that can handel mutiply ip ranges, but for not I dont see why this would not work for you.

Author Comment

ID: 24850627
Agreed, that's definately something we'll have to look at.

In terms of a firewall that can handle multiple ranges, any suggestions on one of those? I fear that knowing Murphy's Law pretty intimately, we'll end up getting an additional range which is all kinds of different from our currently.

Expert Comment

ID: 24851564
Two networks is not possible with Sonicall and Cisco firewall device also with single interface.
Supernetting can help you if your ISP can provide contiguous range of ip pool for you.
I feel the below options exist
1. Supernetting of the both ip ranges using existing Sonicwall config.
2. Using PATting to manage with preset ip range.
3. Use additional Interface on your Sonicwall device to terminate your
I see with enhanced SonicOS upto 6 interfaces are availabel for use.
4. Linux firewall with multiple interfaces can also be used for managing economics
5. If the need for more IPs is growing, its time for moving to ARIN/RIPE/APNIC ips whatever applicable to your country.


Featured Post

Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…
Suggested Courses

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question