Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN upgrade from /29 to /28

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 4 Posters 991 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kenttec
      last edited by

      Hi Guys

      This is my first post as I'm new to pfSense, I really love the software, brilliant stuff!!!!

      Probably a really stupid question but here goes:

      I have a pfSense sitting on my ESXi box in a data center, when I first installed it for testing I was given a /29 IP block, I told the ISP that I will be needing to increase this to a /28 so they reserved the rest of the IP block for me. The time has now come to increase my IP block, do I simply just edit the WAN subnet from /29 to /28 or do I have to run the initial setup again.

      Cheers

      NollipfSenseN 1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @kenttec
        last edited by

        @kenttec said in WAN upgrade from /29 to /28:

        do I simply just edit the WAN subnet from /29 to /28

        I believe you answered your question...you can also try editing and see what happens!

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • K
          kenttec
          last edited by

          Cheers for the response.

          I want to do this work remotely, If it wasn't hosted in a data center and was a home lab, I'd happily give it a go and see what happens. Only problem is, if it doesn't work, I'll have to get remote hands or make my 1 hour journey.

          Was hoping someone has done something similar to this, like editing the existing WAN

          NollipfSenseN 1 Reply Last reply Reply Quote 0
          • NollipfSenseN
            NollipfSense @kenttec
            last edited by

            @kenttec Hopefully, others will chime in...I understand your situation.

            pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
            pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

            K 1 Reply Last reply Reply Quote 1
            • K
              kenttec @NollipfSense
              last edited by

              @NollipfSense I know its a bit of an odd one as usually you'd get a fresh bunch of IP's/subnet/gateway when going from /29 to /28. 😎

              1 Reply Last reply Reply Quote 0
              • kiokomanK
                kiokoman LAYER 8
                last edited by kiokoman

                the only thing that change from /29 to /28 is the max host available from 6 to 14, if the block of addresses remains the same
                you just need to change netmask from /29 to /28

                ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                Please do not use chat/PM to ask for help
                we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                K 1 Reply Last reply Reply Quote 1
                • K
                  kenttec @kiokoman
                  last edited by

                  @kiokoman Thats good news, so I can do this remotley in GUI and then ask ISP to initiate changes

                  1 Reply Last reply Reply Quote 0
                  • kiokomanK
                    kiokoman LAYER 8
                    last edited by kiokoman

                    you can do it before or after it doesn't really matter,your connection will not disrupt, the gateway remain the same

                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                    Please do not use chat/PM to ask for help
                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                    K 1 Reply Last reply Reply Quote 0
                    • K
                      kenttec @kiokoman
                      last edited by

                      @kiokoman Oh OK, I thought you needed the correct subnet for connectivity to work, so I could change it now and still have connectivity? Then contact ISP Monday

                      1 Reply Last reply Reply Quote 0
                      • kiokomanK
                        kiokoman LAYER 8
                        last edited by

                        buh, i tried it on my config and i didn't lost connectivity , i have a /29 where i have my ip added as virtual ips, i changed my wan interface to /28 and nothing happened 😂

                        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                        Please do not use chat/PM to ask for help
                        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                        K 1 Reply Last reply Reply Quote 1
                        • K
                          kenttec @kiokoman
                          last edited by

                          @kiokoman thank you for testing it and confirming. That’s great news.

                          1 Reply Last reply Reply Quote 0
                          • jimpJ
                            jimp Rebel Alliance Developer Netgate
                            last edited by

                            It may also depend on where your block is allocated. a /29 could start in the middle of a /28. But if the network address of both is the same, then you're probably OK.

                            For example:

                            • 198.51.100.32/28 goes from 198.51.100.33 - 198.51.100.46 (with 32 being the network address and 47 being the broadcast)
                            • 198.51.100.32/29 is contained within 198.51.100.32/28 and goes from 198.51.100.33 - 198.51.100.38 (same network ID, but 39 as broadcast)

                            However:

                            • 198.51.100.40/29 is also contained within 198.51.100.32/28 but goes from 198.51.100.41 - 198.51.100.46 (with 40 being network ID, 47 as broadcast)

                            So if your /29 and /28 use the same network ID then you probably only need to adjust the subnet mask. But if the /29 started halfway into a /28, then you may want to make other adjustments as well. Like if your firewall is using the first usable IP address, you might want to shift that down to match the new subnet.

                            Run the old and new subnet through a subnet calculator to be certain.

                            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                            Need help fast? Netgate Global Support!

                            Do not Chat/PM for help!

                            K 1 Reply Last reply Reply Quote 1
                            • K
                              kenttec @jimp
                              last edited by

                              @jimp Thanks for the heads up, Im not aware of my /28 addresses yet so I will hold fire on adjusting anything.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.