LAN routing after subnet change

  • I recently changed the subnet on our LAN to /16 from /20 all seems to be working as expected. DHCP get given out by with the new /16 range instead of /20 but there is an issue with ipsec where its advertising the routes on the client end as /20 still.

    I have tried changing the config for the phase 2 tunnel, restarting ipsec and even changing the local subnet to be instead of using "LAN subnet" but route print on the client still show /20.

    Any ideas how to get the right route ?

  • Not sure why but the config change was never picked up even after restarting the service.

    Rebooted the firewall and it's now sending the clients the right subnet so probably something is cached and not reloaded on restart.

