DHCP Almost Full - Superscope?

We have a headquarters and two branch offices. The branch officers are connected to the main officer with MPLS. Here's the configuration:
1. main office: 10.0.0.0/24
2. branch office 1: 10.0.1.0/24
3. branch office 2: 10.0.2.0/24

In the main office, the DHCP is almost full. What's the better way to add more IP addresses in the main office? 10.0.3.0 with Superscope?
stillsyraAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Tom CieslikIT EngineerCommented:
Yes, good idea but you going to need dedicate and configure separate port on your firewall as a gateway.
I have same setup and is working perfectly

You need to setup superscope, and add another scope

10.0.3.0
255.255.255.0
10.0.3.1
For DNS you can use same address you have in first scope 10.0.0.x

Then you need co connect second assigned port on your firewall with IP 10.0.3.1 to your LAN network. I'm using SonicWall and it's working perfectly.
stillsyraAuthor Commented:
Thank you Tom. We have a cloud firewall with our ISP provider.
Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
Sorry having to say that, but your setup is already messed up. You should have used e.g. the second octett for branch/office, or at least leave enough room between each.

Without reassigning networks, you can only add new ones, and that means routing is involved. If you set up 10.0.3.0/24 (or similar), traffic between 10.0.0.0/24 and 10.0.3.0/24 needs to flow thru the default gateway.
I usually would use at least a /22 for the main office. That would mean you need to move the branch offices, e,g, to 10.0.32.0/24 and 10.0.48.0/24, and have at least 10.0.0.x to 10.0.3.x available for the main office.
Active Protection takes the fight to cryptojacking

While there were several headline-grabbing ransomware attacks during in 2017, another big threat started appearing at the same time that didn’t get the same coverage – illicit cryptomining.

stillsyraAuthor Commented:
Thank you Qlemo. This is the reason I posted the question here. I'm trying to find a better way to solve this issue.
Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
Do you think my recommendation to change existing subnets are feasible and acceptable for you? Or are you waiting for other recommendations?
stillsyraAuthor Commented:
Qlemo, your solution would work. But i'm hoping to find a solution that will require minimum change for the existing configuration.
Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
The mininum is that you expand 10.0.0.0/24 to 10.0.0.0/23, and move branch office 1 to a different subnet.
stillsyraAuthor Commented:
Thank you! So the superscope with adding 10.0.3.0/24 to the main office wouldn't work, correct?
Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
It would, but then you'll force your cloud router to be used for communicating between 10.0.0.0/24 and 10.0.3.0/24 - it is just like another branch office.
stillsyraAuthor Commented:
Does it mean that the superscope will work better if we had a physical firewall in house, instead of a cloud based firewall?
Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
Yes, as traffic stays within your site, instead of going to the cloud.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
stillsyraAuthor Commented:
Thank you very much Qlemo!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
DHCP

From novice to tech pro — start learning today.