asked on
IP scheme advise for a new large network
Hello Experts,
I am in a project and we have a contractor as we are building a new IP scheme for a building - large enough but I do not think we will need as 30K IPs . We are going to use OSPF with area 0. What one of the groups suggested is to use the 10 network but to change the 2nd octet with each floor of the building example they want to use for ground floor 10.0.1.x/24 , 1st floor 10.1.1.x/24 and so on. I just want to know with this type of IP scheme will this cause discontinuous networks and will area 0 have issues in the future.
My suggestion was to use 10.10.x.H , the 2nd octet is for the site code and X is the vlan that will change per floor. I though this was wise to do but I need to check with you all.
From what you've explained, you're going to use maybe 10.1.0.0/16 at site 1, 10.2.0.0/16 at site 2, 10.3.0.0/16 at site 3, etc. then at site 1 use 10.1.0.0/24 for ground floor, 10.1.1.0/24 for first floor. 10.1.2.0/24 for second floor, etc. That's quite common.
ASKER
This is common as you mentioned for different sites, but this client want to use this concept for one building only. instead of sites they want to do it per floor, the issue is this building will be area 0 and have one core switch.
ASKER
ASKER
Thanks,
When the time comes, one site will run OSPF area 0 and others that connect to that site will run OSPF area x, y, z, whatever. The fact that you have split a 10.0.0.0/8 network into smaller subnets is not an issue for OSPF whatsoever. It's when you want to start summarising the subnets that you may have issues, but again, not a problem for OSPF itself - it's more how you summarise the networks nicely.
When it comes to the VPN, again, don't worry. Just advertise networks to the firewall using OSPF. Add the networks you want to enable through the VPN tunnel at the firewall (by setting ACL or encryption domain depending on terminology) and it's all good.
ASKER
ASKER
I know from what I read that ospf area 0 should not have discontiguous networks. That is the issue with use 10 network and changing the 2 octet but they are using /24 mask everywhere. just want to make sure I am not going against the design principal.
My site code suggesting for area 0 is to keep the network the same through out using 10.X.Y. H , X remains for the site and Y changes with different floors.
if we have 2nd site, the X changes ofcourse but that site will be in different area.
let me know