• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Subnetting my home network

jardows

2[H]4U
2FA
Joined
Jun 10, 2015
Messages
2,475
I am going to try to setup some VLANS and subnetting for my home network this weekend. I would like input and recommendations for my initial plan, or any corrections to my subnetting math! My current networking equipment is an OpnSense router/firewall, a Cisco Catalyst 2960 24-port switch, and a couple of older entry-level Wi-Fi routers set in AP only mode. While I don't have a whole lot of end point devices, I want to leave some room for additions and expansion.
Here is what I have planned out so far:

Vlan 1 - 192.168.0.0/29 (usable .1-.6) “DMZ” – Gateway, potentially public servers. Not wide-open, but maybe an SSH jump box, media server, and minecraft servers that might be opened for selected access
Vlan2 - 192.168.0.8/29 (usable .9-.14) Internal Servers, things that won't be public facing and may need more restrictions, primarily file serving.
Vlan3 -192.168.0.16/28 (usable .17-.30) Ethernet connected workstations. Will be statically assigned IP addresses. Should have access to Vlan1, 2, 6, 7
Vlan4 - 192.168.0.32/28 (usable .33-46) Main Wi-Fi computers/phones/tablets. DHCP Enabled. Should have access to Vlan1, 2, 6
Vlan5 - 192.168.0.48/27 (usable .43-79) Guest Wi-Fi access. Should only have access to Internet and "public" servers
Vlan6 - 192.168.0.192/28 (usable .193-207) Network connected printers - accessible from Vlan3 and 4. Should not access the Internet
Vlan7 - 192.168.0.240/28 (usable .241-254) Switch/AP Management - may need Internet access to pull firmware updates, should only be accessible by vlan3

Much of this scheme is done in an attempt to preserve existing IP addressing assignments, but if I need to change IP addressing I can. I have plenty of Ip addresses left to use here for future IP security cameras and IoT devices, but I don't have any of those currently.

Recommendations for a beter scheme or any corrections to my setup are welcome!
 
1769114033378.png
 
Vlan4 - 192.168.0.32/28 (usable .33-46) Main Wi-Fi computers/phones/tablets. DHCP Enabled. Should have access to Vlan1, 2, 6
Vlan5 - 192.168.0.48/27 (usable .43-79) Guest Wi-Fi access. Should only have access to Internet and "public" servers
Total noob but does the upperbound .46 being higher than the next lower bound .43 something wanted by design ? seem to have enough room to avoid this if not.
 
Total noob but does the upperbound .46 being higher than the next lower bound .43 something wanted by design ? seem to have enough room to avoid this if not.
In a routed subnet, the first and last IP addresses of the range are reserved. This is why in a normal home network, you are unable to use .0 and .255 for endpoint devices.
 
In a routed subnet, the first and last IP addresses of the range are reserved. This is why in a normal home network, you are unable to use .0 and .255 for endpoint devices.
I am not sure to understand where the adress 192.168.0.44 would fall on or maybve it is a typo ? and usable were .49 up to .79 for vlan5 ? and not .43-.79 ?
 
I am not sure to understand where the adress 192.168.0.44 would fall on or maybve it is a typo ? and usable were .49 up to .79 for vlan5 ? and not .43-.79 ?
I see now. Yes, a typo. Vlan 5 should be 49 -79 available
 
Eww, your subnetting plan looks horrible and limiting. There's no reason you have to stick to such small ranges contained within 192.168.0.0-255. You can use multiple /24 subnets.

FWIW, this is basically what I do:

VLANSubnetNotes
Wired LAN10192.168.10.0/24Most anything ethernet.
WiFi20192.168.20.0/24Most laptops, phones, etc.
Guest WiFi25192.168.25.0/24Internet access only.
WiFi IOT26192.168.26.0/24Lock that crap down.
VPN50192.168.50.0/24Incoming from the outside.
Management99192.168.99.0/24Router, switch, Proxmox, etc. management.

Note that I correlate the third octet with the VLAN number. Most major categories (e.g. WiFi) are denoted by a VLAN # divisible by 10, any subcategories shortly thereafter. Don't use VLAN 1, it's usually reserved.
 
Eww, your subnetting plan looks horrible and limiting. There's no reason you have to stick to such small ranges contained within 192.168.0.0-255. You can use multiple /24 subnets.

FWIW, this is basically what I do:

VLANSubnetNotes
Wired LAN10192.168.10.0/24Most anything ethernet.
WiFi20192.168.20.0/24Most laptops, phones, etc.
Guest WiFi25192.168.25.0/24Internet access only.
WiFi IOT26192.168.26.0/24Lock that crap down.
VPN50192.168.50.0/24Incoming from the outside.
Management99192.168.99.0/24Router, switch, Proxmox, etc. management.

Note that I correlate the third octet with the VLAN number. Most major categories (e.g. WiFi) are denoted by a VLAN # divisible by 10, any subcategories shortly thereafter. Don't use VLAN 1, it's usually reserved.
That's what I was thinking. I'd just use /24s and renumber. Deal with the pain once so it doesn't bite you in the ass in the future.

I have 6 VLANs but I just made all of mine /24s. I could go bigger if I wanted, but nah. I don't see much chance of needing 250 addresses on one subnet. Actually, I have 2^64 addresses per subnet... but that's IPv6. Comcast will let you hint for up to a /60, so they're real Internet IP addresses and not NATed. IIRC that's actually spec for IPv6 home internet.

My setup also has multiple WiFi SSIDs. I'm using access points, and they can have up to 8 SSIDs per band. I've got 6 VLANs and 5 SSIDs. One of the VLANs is basically caused by a router bug. My MikroTik RB5009 router provides lousy performance to devices slower than my internet connection over the 10Gb port. Internet has crept up to 2Gb down, so it's a problem for WiFi and gigabit devices. So basically my VLANs are 2.5Gb & 10Gb computers, 1Gb and WiFi computers, a couple for phones and gizmos, one for my work stuff, and of course a guest network. All of them have their own WiFi SSID except for the 2.5 & 10Gb computers network. Only the guest network and one of the gizmo networks are WiFi only. Well, sort of. My APs are wired, but those VLANs only run over cables to the APs. The other gizmos network has a couple wired devices on it - my TV and my Tablo network over-the-air TV tuner/DVR.

Almost everything on my network uses DHCP. I just set static addresses in my router based on MAC address & add DNS entries. My server machine uses static IPs, but that's about it. Router is .1 on all subnets, server is .2 on both computer subnets and has it's default route set to the 2.5+10Gb network.
 
Eww, your subnetting plan looks horrible and limiting. There's no reason you have to stick to such small ranges contained within 192.168.0.0-255. You can use multiple /24 subnets.

FWIW, this is basically what I do:

VLANSubnetNotes
Wired LAN10192.168.10.0/24Most anything ethernet.
WiFi20192.168.20.0/24Most laptops, phones, etc.
Guest WiFi25192.168.25.0/24Internet access only.
WiFi IOT26192.168.26.0/24Lock that crap down.
VPN50192.168.50.0/24Incoming from the outside.
Management99192.168.99.0/24Router, switch, Proxmox, etc. management.

Note that I correlate the third octet with the VLAN number. Most major categories (e.g. WiFi) are denoted by a VLAN # divisible by 10, any subcategories shortly thereafter. Don't use VLAN 1, it's usually reserved.
So many reasons this is easier, just look at keeping track of the gateways for instance, when you use whole /24's.
Vlan 666 is the guest/IOT isolated wasteland on most of our stuff. ;)
 
Ya, and any modern hardware can handle larger subnets with out issues anyways..

Pix 505 ~22 years ago would have handled that. :)

Given that CIDR has been the standard since the 90s, which based the some the things I see in this forum is longer than many here have been alive, I'm not sure why this even needs to be said. Failure to handle any length netmask is just a fail. I've literally got a Cisco 2511, used for serial console access, from 1998 that will handle any length mask. You'd have a hard time finding a weaker box built in the last 20 years.

termserv#sh ver
Cisco Internetwork Operating System Software
IOS (tm) 2500 Software (C2500-I-L), Version 11.2(15a), RELEASE SOFTWARE (fc1)
Copyright (c) 1986-1998 by cisco Systems, Inc.
Compiled Mon 24-Aug-98 00:22 by tmullins
Image text-base: 0x03022F80, data-base: 0x00001000

ROM: System Bootstrap, Version 11.0(10c), SOFTWARE
BOOTFLASH: 3000 Bootstrap Software (IGS-BOOT-R), Version 11.0(10c), RELEASE SOFTWARE (fc1)

termserv uptime is 11 weeks, 3 days, 51 minutes
System restarted by power-on at 18:46:24 UTC Sat Nov 8 2025
System image file is "flash:c2500-i-l.112-15a", booted via flash

cisco 2511 (68030) processor (revision M) with 2048K/2048K bytes of memory.
Processor board ID 11995003, with hardware revision 00000000
Bridging software.
X.25 software, Version 2.0, NET2, BFE and GOSIP compliant.
1 Ethernet/IEEE 802.3 interface(s)
2 Serial network interface(s)
16 terminal line(s)
32K bytes of non-volatile configuration memory.
16384K bytes of processor board System flash (Read ONLY)
 
It was just something decades ago you would have someone mention "you can't use a /20, the broadcast traffic will kill any network! break it up into smaller /24s"

I heard it as recently as....4 years ago with a client I worked with who had so many dam VLANs, all were /24's and they had about 800 vms. They had 4 Server VLANS, all wide open to each other. So I asked their Senior Networking engineer why, and he said because they don't want to flood the network so they did separate VLANs....

Meanwhile they have the dam expensive high end Cisco networking gear $50k each switches, top of rack, feeder switches, all redundant, you name it!
 
It was just something decades ago you would have someone mention "you can't use a /20, the broadcast traffic will kill any network! break it up into smaller /24s"

I heard it as recently as....4 years ago with a client I worked with who had so many dam VLANs, all were /24's and they had about 800 vms. They had 4 Server VLANS, all wide open to each other. So I asked their Senior Networking engineer why, and he said because they don't want to flood the network so they did separate VLANs....

Meanwhile they have the dam expensive high end Cisco networking gear $50k each switches, top of rack, feeder switches, all redundant, you name it!
On a shared media, read hub not switch, 10Mbps ethernet network sure a /20 with 4096 host would generate enough broadcast and more to point collisions to impact a network. Not so much since the world moved to switched network at 100+ Mbps. That was a matter concerning number of actual devices on the network. It had nothing to do with the number usable IPs.
 
On a shared media, read hub not switch, 10Mbps ethernet network sure a /20 with 4096 host would generate enough broadcast and more to point collisions to impact a network. Not so much since the world moved to switched network at 100+ Mbps. That was a matter concerning number of actual devices on the network. It had nothing to do with the number usable IPs.
IPv6 more or less codifies this. The minimum subnet size is 2^64 addresses. Pile on enough devices and the multicast traffic (IPv6 doesn't have broadcast, but local multicast does basically the same thing) will eventually start to degrade things, but the number of addresses available doesn't matter for performance. You could use an IPv4 /8 if you wanted to.
 
Alright, you guys convinced me! All /24's it is. Now just have to fiddle with the firewall rules to block/grant access as desired.
ya, it does make life easier. I do have some /28's for my Wifi SSIDs, as i wont ever use a /24, but also is easily manageable.
 
ya, it does make life easier. I do have some /28's for my Wifi SSIDs, as i wont ever use a /24, but also is easily manageable.
I'd be too lazy to do that even if I knew I'd never use all those IPs on that subnet. Easier to just do /24s for everything IMHO. My WiFi 6 APs cap me at 8-16. They support 8 SSIDs per band, so any SSID that uses both 2.4 & 5GHz counts as one of each. I have a dedicated VLAN and SSID for one device that I consider a security risk, and that's a /24. I have this older Ambient Weather weather station that'll let you upgrade its firmware without a password over WiFi, so it's on a VLAN & SSID that only allows outbound tcp connections to the Internet and doesn't allow any traffic at all to other VLANs inside the house. So it can upload weather data, but nothing is allowed to connect to it. If I want to upgrade its firmware I have to put my phone on it's SSID.
 
Back
Top