Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Best practice for subnet/prefix length for VIPs?

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 4 Posters 132 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      ChrisJenk
      last edited by

      I have several VIPs, both IPv4 and IPv6, defined on various interfaces. I have tended to add them as /32 (for IPv4) or /128 (for IPv6) but I am wondering if there is any rule or best practice for this as the underlying interface primary addresses are /24 and /64. Does the choice of subnet/prefix size for the VIPs make any actual difference?

      Everything seems to be working just fine but I'm always keen to know if I'm doing things the best way.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        If they are additional IPs in a subnet that's already defined then they can be either a single IP or the full subnet. If they are in a different subnet than the parent then it must be defined as the full subnet.

        1 Reply Last reply Reply Quote 0
        • JKnottJ Offline
          JKnott
          last edited by

          I provide a /24 subnet on IPv4 and /64 on IPv6. I also have the 3rd IPv4 octet match the IPv6 prefix ID. However, this is more for convenience than technical reasons. I also use the same number for the VLAN for my guest WiFi.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          J 1 Reply Last reply Reply Quote 0
          • J Offline
            JacintoChamplin @JKnott
            last edited by

            @JKnott Geometry Dash Lite said in Best practice for subnet/prefix length for VIPs?:

            I provide a /24 subnet on IPv4 and /64 on IPv6. I also have the 3rd IPv4 octet match the IPv6 prefix ID. However, this is more for convenience than technical reasons. I also use the same number for the VLAN for my guest WiFi.

            The information you shared is very useful, thanks.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.