'Default gateway does not belong to the same subnet...................." message while configuring static IPV4 on the NIC

amanzoor
amanzoor used Ask the Experts™
on
Hi there,
I am running server 2008/2012 windows domain, win 8.1/10 clients.  I am in the process of making my Sophos firewall SG310 (10.10.10.6) being the default gateway for my users.
I am running three subnets:
10.10.10.0/24
10.10.2.0/23
10.10.10.0/23
On my DHCP server I am publishing 10.10.10.254 as my router address till now so my clients IPV4 config looks like:
IP address: 10.10.10.5
subnet mask: 255.255.255.0
default gateway: 10.10.10.254
DNS: .........
Whenever I make put into a test client the static IPv4 config as:
IP add: 10.10.10.5
subnet mask: 255.255.255.0
default gateway: 10.10.10.6  .......<<<<<<<<Sophos firewall SG310
It gives me 'DG does not belong to the same subnet............................................"

Purpose:
1)  I want each and every client's traffic on my domain to go through my Sophos firewall SG310 for fileting purposes
2) If any user purposely changes the IPV4 on a client to my previous settings with my router address as DG will not get the internet.

Physical:
My Sophos firewall sites behind my router and till now things work great as a firewall but for filtering I need to make this sophos firewall as a gateway.  
What should I do so that the subject warning is not generated and my Sophos firewall becomes the DG of my domain?

Need help
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Commented:
You have 2 overlapping subnets, 10.10.10.0/24 & 10.10.10.0/23 - i assume you're router is configured with the /23 subnet mask and the workstations are in the /24 - so they don't match and are prompting with the error - change one of the ranges and see how you go..
nociSoftware Engineer
Distinguished Expert 2018

Commented:
indeed, for a network you need to have all netmasks the same for the same (sub)net.
Use filters on a router to prevent other uses.
amanzoorNetwork infrastructure Admin

Author

Commented:
AndyS:
Thanks for the reply.  I will user /23 and let you know.

noci:
****Use filters on a router to prevent other uses****  if I can understand it well.  It means if a user changes to static IP with the default gateway of the router IP will not go on the internet.  If this is what it means, what is the command to enable this.   Need help
nociSoftware Engineer
Distinguished Expert 2018
Commented:
If you want some systems (ip addresses) not reaching the internet you need filters on the gateway to the internet that block traffic for those systems.
You should have all systems use the same netmask, default gateway.

Changing the default gateway *SHOULD* break things, not get you more access.
amanzoorNetwork infrastructure Admin

Author

Commented:
Thanks guys.  Appreciate it.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial