Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Best practice for setup of a /27 network

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      torontob
      last edited by

      Hi everyone,

      Let's say I have a network like 33.44.55.0/27. Which usable IP should be set to WAN interface? Is there a best practice or required rule that asks for either one of those IPs to be main and rest virtual IPs?

      Thanks,

      1 Reply Last reply Reply Quote 0
      • W
        wisowebs
        last edited by

        Are you getting your IP's via transit network?

        1 Reply Last reply Reply Quote 0
        • T
          torontob
          last edited by

          Not sure what transit network is. I am told its static routing and server is in datacentre.

          1 Reply Last reply Reply Quote 0
          • dotdashD
            dotdash
            last edited by

            You often get a separate subnet where the gateway lies so you can use the whole subnet.
            I use the first usable next to the gateway. Convention is to use the first or the last usable- on 0/27 that's either 1 or 30. I tend to go with the first.

            1 Reply Last reply Reply Quote 0
            • R
              relmes
              last edited by

              Using the first usable for the router allows you to subdived the IP block later if required without having to change the router IP.

              As an example, say you had.

              192.168.1.0/27

              Network  =  192.168.1.0
              Broadcast =  192.168.1.31
              Usable = 192.168.1.1 to 192.168.1.30 (30 Hosts).

              If you make 192.168.1.1 the router and allocate hosts from that IP upwards, you can always decide later to split that IP allocation between two /28s. (assuming you've not gone past 14 hosts)

              192.168.1.0/28 & 192.168.1.16/28

              If you'd placed the router at 192.168.1.30 and then wanted to split the subnets, you'd have to re-ip the router and all the host config that used it  This may not be so much of an issue for a /27 but scale that up to a /24 or /23 and it soon becomes a right royal pain in the ….

              It is for this reason that I would always set the router/Firewall/HSRP etc IPs at the start of the subnet block rather than then end.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.