• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Lan IP change

L2/Switching/VLANs
3
8
182
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    froussy
    last edited by 21 days ago

    Good day,

    I actually run multiple sites with PFS, linked through VPN

    I will need to change the ip's on each of those site..

    I always change the ip's at the PFS setup, but not while in production

    What is the easiest way ?

    I was thinking creating a VLAN with then new subnet, create a new IPSEC Phase 2, then change my switch to that new VLAN..

    But one site, I cant do Vlan..

    What do you suggest me.

    Thanks

    Frank

    J 1 Reply Last reply 21 days ago Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @froussy
      last edited by 21 days ago

      @froussy do you have devices on this remote site that are not dhcp? If you do, can you change their IP - be it via ssh or rdp or something?

      If all dhcp - just lower the lease to something really low, like 10 minutes. Wait til all the devices would be using new short lease.

      Then connect to different IP on pfsense, create a vip if you need to that you can get through the vpn.

      Once your connected to that IP, change your pfsense lan IP to your new scheme. This should remind you to change your dhcp, etc.

      Now things should should switch over to your new IP range. Worse case create a vip now with the old IP for things that haven't gotten new lease with new info, or for stuff you need to change manually, etc.

      You would of course updated your vpn settings for your new network range.

      There you go - other than say changes to dns entries to reflect new IPs, and routing for your other sites to this new network you should be good to go.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      J F 2 Replies Last reply 21 days ago Reply Quote 0
      • J
        JKnott @johnpoz
        last edited by 21 days ago

        @johnpoz said in Lan IP change:

        If all dhcp - just lower the lease to something really low, like 10 minutes. Wait til all the devices would be using new short lease.

        Or just do it over a weekend, if there are no users then, assuming you haven't set a very long lease time. Default is 7200 seconds. You might also send an email before hand, explaining it might be necessary to reboot, if the computers are left running. If there are static devices, change them before you change the DHCP range.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        J 1 Reply Last reply 21 days ago Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator @JKnott
          last edited by 21 days ago

          @JKnott sure if you can wait out the lease - sure 2 hours is default, but mine has been set to 8 days.. Why have clients ask for dhcp ever hour if unless your making changes all the time.

          I would do it over a weekend or after hours still sure, but a few days before your going to do it - I would lower the lease so you know right away that all your devices will or should have moved..

          If you have a short lease - vs having to wait a hour or so to know your clients have moved, you should know in like 10 minutes tops if clients are going to move or not. Then you can go back to enjoying your weekend or off hours. ;)

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          J 1 Reply Last reply 20 days ago Reply Quote 0
          • J
            JKnott @johnpoz
            last edited by 20 days ago

            @johnpoz Another trick is to just reboot the switch. That will trigger the clients to request an address.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            J 1 Reply Last reply 20 days ago Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator @JKnott
              last edited by johnpoz 20 days ago 20 days ago

              @JKnott that could work too - but then you for sure creating an outage ;)

              And depending on your switch - some of them can take a while.. Cisco for example, depending on the image, are you using vss, can have some pretty extended boot times.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • F
                froussy @johnpoz
                last edited by 20 days ago

                @johnpoz
                Hi,

                forgot to mention i will be local.. dont want to do that remotely :)

                so, changing the router ip, DONT APPLY, then DHCP, and then apply, in a simple word, right?

                So that way will be simpler than creating a vlan, moving everything and come back right?

                Yes, for the IPSEC, i know to adjust.. that's a detail:)

                J 1 Reply Last reply 20 days ago Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator @froussy
                  last edited by johnpoz 20 days ago 20 days ago

                  @froussy if you're local.. Sure just change the ip on the lan and your good to go.. Since you would be able to touch anything that is not dhcp, etc.

                  And you can always console into pfsense, etc

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  5 out of 8
                  • First post
                    5/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.