Link to home
Start Free TrialLog in
Avatar of Joe Grosskopf
Joe Grosskopf

asked on

Fail to understand Comcast public IP

So Comcast gave us a fiber line with a block of IP's, I really do not understand how to route the public IP internally. I need to assign a public IP to a VPN server. What the gave us was. Customer Link IP 50.203.X.X, Gatwate 50.203.X.X and subnet of 255.255.255.252. Then the block of public IPs is 50.205.X.X /28 with a subnet of 255.255.255.240. If I assign the 50.205.X.X to a device it, has no way of communicating with 50.203.X.X I called comcast twice and both times they told me this was all correct. IN the past I would have been given 50.203.X.X and the gateway and public IPs would also be 50.203.X.X
Avatar of John
John
Flag of Canada image

I think they are correct.   If you connect to 50.203.x.x   you cannot connect from there to 175.275.a.b .  They are different external IP addresses.  

You could connect from one to the other with a VPN connection.  We do this to test VPN connections at any given client.
Avatar of David Johnson, CD
I don't understand your problem.. you set your network to 50.205.X.X /28 and set the gateway to 50.203.X.X

This is like your router is 192.168.0.1 but your LAN is 10.0.10.0/32 so you get an ip address from dhcp for
10.0.10.1 and a gateway of 192.168.0.1
I don't think you want/need your two blocks of public IPs to communicate with each other.  Comcast should have already programmed your router with both blocks. If you have two different /28 IP blocks, then you have 28 usable public IPs (14 usable IPs per /28 block). Doesn't matter that they are from 2 different blocks. You can use NAT to translate any of the 28 IPs to a private IP. You'll also have one gateway out of your network to the Internet (as David Johnson mentioned) that everything can use.
Avatar of Joe Grosskopf
Joe Grosskopf

ASKER

I've been on the phone with Comcast no less than 6 times over this. This is the way they do their fiber and the customer service policy is "that's in your infrastructure, you have configure it and I'm not an IP specialist so I can't do much more". I don't know how to do this and it's waaaay too complicated for a small business. I'm going to change numbers for security but my customer link ip is 50.203.180.70 and gateway is 50.203.180.69 with subnet mask 255.255.255.252. My public IP is 50.205.110.22 with subnet mask 255.255.255.240. I need got assign a public IP address to a server but do not know how to get that server on the 50.205 to work with the 50.203....and at the same time allow my internal clients on the 192.168 to still access the internet. I can setup wan for 50.203 and land for 192.168 but I don't know how to get the 50.205 to work on a server.
You cannot connect outside at the modem level. You cannot connect your IP to my IP and that is what you are asking

You need to connect internally at the router level by VPN or other like secure connection.
ASKER CERTIFIED SOLUTION
Avatar of atlas_shuddered
atlas_shuddered
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Your last message made things clearer. The IP Address range having the subnet mask 255.255.255.252 is ONLY used as the point-to-point connection between your network and Comcast. This is by design and it's not usable by you. The other block of 14 (possibly 13) IPs is yours to map to your network devices.

This page probably sums it all up:
https://business.comcast.com/help-and-support/ethernet/comcast-business-ethernet-equipment-configuration/
Thanks all, I had to configure the router and setup NAT to route from one network to the other. Never had to do this before. Thanks again