[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now


Change LAN subnet and use two routers

Posted on 2011-09-14
Medium Priority
Last Modified: 2012-05-12

at one of my clients I need to join two networks into one, because finally they got 10 Gbps Optical line inbetween. Until now they were using interconnect link via 2 DSL routers. Ok, here we go:

OLD SITUATION (until today)

* LAN 1 ****** 200 IP devices
Subnet mask:
Main Router IP:
DSL router IP:

* LAN 2 ****** 100 IP devices

Subnet mask:
Main Router IP:
DSL router IP:

On both MAIN ROUTERS there is a route added for other network, so traffic destined from LAN1 to LAN2 (or vice versa) is routed on proper DSL ROUTER.

They've got 10 Gbit optical dark fibre and FO-2-ETH adapters between both LANs.

Now, I need some suggestions how to utilize this link best. How should we proceed?
As we think of expanding subnet, for example to (subnet mask, we realize that we won't be able to change all network device settings at once, but it will be a long process (more than 300 IP devices, lot's of them with static IP).

1.) Since by changing subnet to we'll change broadcast address to, what could get broken in the process? I mean, when some of devices will have new subnet, and others old...will they be able to communicate?
2.) Should we start by changing IP/SUBNET on router/firewalls first, then servers, then clients.....or vice versa? I tested changing subnet on my PC, and from client side it all works from new IP and new subnet mask. But I did not try changing subnet on router.

Ok, when above config will be finished, there is one main problem:
We do not want all clients to use 1 gateway, but would like some sort of load-balancing. Each single gateway is on weak WAN connection (ADSL), so it barelly handles existing traffic, which is why we do not want further joint traffic to route via single ADSL.

So how to set this up?
WAN Routers are on one side LINUX machine on CentOS, and on the other side Cisco 800 series.

A simple FAILOVER can be established by configuring DHCP to provide 2 Gateways to clients. But this does not split traffic, neither provides load balancing.

Any idea?
Question by:Andrej Pirman
  • 3
  • 2
LVL 41

Expert Comment

ID: 36541199
First question:

Why the urge to make it one IP network range.
Keep a router between the two compartiments and keep two subnets, then your 2nd problem doesn't exist either
as both compartiments have their own rules for routing...
LVL 18

Accepted Solution

fgasimzade earned 1000 total points
ID: 36541740
1. devices will still be able to communicate with devices, but not with - will be able to communicate with devices

2. It does not matter, if your firewall and servers will have addresses in range. If you change subnet masks on them, they will still be able to communicate with other PCs in range.
LVL 41

Assisted Solution

noci earned 1000 total points
ID: 36542634
Mismatch of netmask can be an issue w.r.t. network stuff that depends on broadcast.... and on route selection.
So changing a netmask may block traffic, or shut parts of the network.

A better strategy if you want to change is to keep those networks saparated, and migrate to a NEW range.
(All equipment needs to be revisited anyway...)

so: + =>

Then everything will continue to work as expected. (It can be done in the same lan, a bottleneck can be the capacity for the routers needed to bridge the temporary gap.

Anyway, why try to create ONE big network...
If you want to connect to the internet at large using multiple gateways you may need to look into getting BGP up & running and obtain a public network range that can be routed to.
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 18

Author Comment

by:Andrej Pirman
ID: 36552648
Hey, thanx for responds!

Well, regarding your first tip...it is a no go with existing equipment :(
In previous config, there were DSL modems as IP devices, which were used as hops from one to another network. Each side was configured to use this DSL modem's IP as gateway to another network.
But in new config, there are only fibre-to-ethernet adapters, which are not IP devices, so they cannot route traffic. This means, we would need to buy some extra routers for old config to be done on new fibre.

Regarding move to another range...
Well, you might be right, but it is PRODUCTION 24/7, with many devices running 24/7, which are integrated into network, so a move to another NEW subnet would be not possible, since it cannot be done in one run. Printers, surveilence devices, timers, gate control devices, telephony equipment, VPN links, etc...too many different devices and too many caretakers involved, that we cannot gather all together and reconfigure all devices at once.

So my plan was to keep larger subnet, and expand, so smaller subnet can fit into.

Regarding to Fgasimzade's explanation:
- if we expand subnet first on SERVERS and FIREWALL, those will be able to communicate with both, existing and newly expanded networks, right?
- after server's DHCP is updated to expanded subnet, clients will be able to communicate bot, with each other and with servers, right?
- the only problematic will be those machines with STATIC IP, which will remain on old subnet - they will not be able to communicate with devices on expanded part of new subnet, right?

So I assume, printers will be most noticeable problem, until we change their subnets.
LVL 41

Assisted Solution

noci earned 1000 total points
ID: 36553352
If you have ONE router that can forward between the (Multiple IP in ONE Ethernet LAN). You can move everything one by one instead of all @ once.

Changing the Broadcast address will mean that all kinds of stuff related to Broadcast stops working.. That is in part implementation defined.

The DHCP update can be seen a one update. Then first move to a ultra short lease time (10 minutes or so) and after all systems are on that short lease you can change the setup. If the normal lease time is one week you need to wait one week in the short lease time to be sure that all addresses change.

LVL 18

Author Closing Comment

by:Andrej Pirman
ID: 36951110
Thanx, guyz!

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question