<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Quick question about multiple public subnets on SG-5100]]></title><description><![CDATA[<p dir="auto">Hey all:</p>
<p dir="auto">I just inherited a company that was using a Router Guard appliance (yuck), that I have just replaced with a SG-5100. I have a routed /29 subnet from their ISP working on the WAN interface and all of the public IP's are working fine through the 'Virtual IP' function.  I just found out that there is also a different /28 public subnet assigned to this company as well which I need to integrate into the 5100.<br />
My question is, how do I add the additional /28?  Do I just enter them as more Virtual IP's or do I need to do it differently? Any advice would be gratefully received.</p>
<p dir="auto">Rick</p>
]]></description><link>https://forum.netgate.com/topic/137355/quick-question-about-multiple-public-subnets-on-sg-5100</link><generator>RSS for Node</generator><lastBuildDate>Wed, 12 Aug 2026 02:27:57 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/137355.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 01 Nov 2018 16:13:42 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Fri, 02 Nov 2018 19:19:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> I like to NAT, so I will use VIP.</p>
]]></description><link>https://forum.netgate.com/post/801998</link><guid isPermaLink="true">https://forum.netgate.com/post/801998</guid><dc:creator><![CDATA[myriad]]></dc:creator><pubDate>Fri, 02 Nov 2018 19:19:53 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Fri, 02 Nov 2018 19:18:34 GMT]]></title><description><![CDATA[<p dir="auto">So you going to actually put the network behind pfsense or you going to just use vip?</p>
]]></description><link>https://forum.netgate.com/post/801997</link><guid isPermaLink="true">https://forum.netgate.com/post/801997</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Fri, 02 Nov 2018 19:18:34 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Fri, 02 Nov 2018 19:13:48 GMT]]></title><description><![CDATA[<p dir="auto">All good now! ISP had second subnet incorrectly routed.</p>
]]></description><link>https://forum.netgate.com/post/801994</link><guid isPermaLink="true">https://forum.netgate.com/post/801994</guid><dc:creator><![CDATA[myriad]]></dc:creator><pubDate>Fri, 02 Nov 2018 19:13:48 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Fri, 02 Nov 2018 13:49:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> I agree. I have reached out to the ISP to get the routing information for the /28 subnet. I am waiting for that info before I move on.</p>
]]></description><link>https://forum.netgate.com/post/801908</link><guid isPermaLink="true">https://forum.netgate.com/post/801908</guid><dc:creator><![CDATA[myriad]]></dc:creator><pubDate>Fri, 02 Nov 2018 13:49:53 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Fri, 02 Nov 2018 13:40:09 GMT]]></title><description><![CDATA[<p dir="auto">If the /28 is routed to you - it should be routed to you over the same transit as your other network that is routed to you.  You sure they are actually "routed" we get this a lot around here where they say routed be really the isp just gave them IPs that directly attached.</p>
]]></description><link>https://forum.netgate.com/post/801898</link><guid isPermaLink="true">https://forum.netgate.com/post/801898</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Fri, 02 Nov 2018 13:40:09 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Fri, 02 Nov 2018 13:19:27 GMT]]></title><description><![CDATA[<p dir="auto">No you only need the one gateway.  What are you trying to accomplish with the /28?  Some port forwards??  Show your NAT rules.</p>
]]></description><link>https://forum.netgate.com/post/801893</link><guid isPermaLink="true">https://forum.netgate.com/post/801893</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Fri, 02 Nov 2018 13:19:27 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Thu, 01 Nov 2018 22:50:18 GMT]]></title><description><![CDATA[<p dir="auto">I spoke too soon.  I can ping the new IP from the 5100 when I add a VIP but I can't reach it from outside the FW. I have modified the NAT rules to point to the new VIP but no action.  Do I have to add another gateway on the wan address with the network address of the new subnet (206.248.147.128/28)?</p>
]]></description><link>https://forum.netgate.com/post/801829</link><guid isPermaLink="true">https://forum.netgate.com/post/801829</guid><dc:creator><![CDATA[myriad]]></dc:creator><pubDate>Thu, 01 Nov 2018 22:50:18 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Thu, 01 Nov 2018 21:45:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kom">@<bdi>kom</bdi></a> Worked perfectly!  Man, I am falling in love with Pfsense!</p>
]]></description><link>https://forum.netgate.com/post/801825</link><guid isPermaLink="true">https://forum.netgate.com/post/801825</guid><dc:creator><![CDATA[myriad]]></dc:creator><pubDate>Thu, 01 Nov 2018 21:45:55 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Thu, 01 Nov 2018 17:24:30 GMT]]></title><description><![CDATA[<p dir="auto">If these are routed to you - you can actually place the IPs on devices behind pfsense if you wanted too.. There is no need to use vips - unless you actually want to do it that way.</p>
]]></description><link>https://forum.netgate.com/post/801786</link><guid isPermaLink="true">https://forum.netgate.com/post/801786</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 01 Nov 2018 17:24:30 GMT</pubDate></item><item><title><![CDATA[Reply to Quick question about multiple public subnets on SG-5100 on Thu, 01 Nov 2018 17:22:45 GMT]]></title><description><![CDATA[<p dir="auto">I don't have a similar config but that is what I would try first.  Create a VIP for one of the IPs in that /28 and then play with it to see if it works.</p>
]]></description><link>https://forum.netgate.com/post/801785</link><guid isPermaLink="true">https://forum.netgate.com/post/801785</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Thu, 01 Nov 2018 17:22:45 GMT</pubDate></item></channel></rss>