Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Subnet mask rules

Status
Not open for further replies.

critcho

Technical User
Oct 2, 2008
2
US
Hi all,

We have a VPN from various remote devices to our server, I am trying to clean up the firewall rules. I want to tell our providor to give us a continuous block that is easier to program into the firewall (I beleive our PIX only allows 10 rules?).

Subnet masks are completely bambooziling me at the moment. Using a mask generator ( I can generate my range with either 7 rules or 4. Obviously 4 is much better. Either way, when I put the base and mask back into SolarWinds subnet generator, there are jumps in the generated IPs.

Does anyone have a tool that will generate continous IP ranges with simple masks, and generate simple masks if I give it the range to allow?

I'm trying to allow xxx.xxx.xxx.177 to xxx.xxx.xxx.204:

Base/Mask CIDR From To
xxx.xxx.xxx.177/255.255.255.255 xxx.xxx.xxx.177/32 xxx.xxx.xxx.177 xxx.xxx.xxx.177 1
xxx.xxx.xxx.178/255.255.255.254 xxx.xxx.xxx.178/31 xxx.xxx.xxx.178 xxx.xxx.xxx.179 2
xxx.xxx.xxx.180/255.255.255.252 xxx.xxx.xxx.180/30 xxx.xxx.xxx.180 xxx.xxx.xxx.181 2
xxx.xxx.xxx.184/255.255.255.248 xxx.xxx.xxx.184/29 xxx.xxx.xxx.185 xxx.xxx.xxx.190 6
xxx.xxx.xxx.192/255.255.255.248 xxx.xxx.xxx.192/29 xxx.xxx.xxx.193 xxx.xxx.xxx.198 6
xxx.xxx.xxx.200/255.255.255.252 xxx.xxx.xxx.200/30 xxx.xxx.xxx.201 xxx.xxx.xxx.202 2
xxx.xxx.xxx.204/255.255.255.255 xxx.xxx.xxx.204/32 xxx.xxx.xxx.204 xxx.xxx.xxx.204 1


Base/Mask CIDR From To
xxx.xxx.xxx.176/255.255.255.240 xxx.xxx.xxx.176/28 xxx.xxx.xxx.177 xxx.xxx.xxx.190 14
xxx.xxx.xxx.192/255.255.255.248 xxx.xxx.xxx.192/29 xxx.xxx.xxx.193 xxx.xxx.xxx.198 6
xxx.xxx.xxx.200/255.255.255.252 xxx.xxx.xxx.200/30 xxx.xxx.xxx.201 xxx.xxx.xxx.202 2
xxx.xxx.xxx.204/255.255.255.255 xxx.xxx.xxx.204/32 xxx.xxx.xxx.204 xxx.xxx.xxx.204 1
 
What class? I am guessing that you're trying to summarize to create less statements for acls?
.177 (class C) can be separated from .204 with any mask lower than /26, but to get them in the same subnet, a /26 is needed (255.255.255.128). So, 192.168.1.128/26=192.168.1.129 through 192.168.1.254, with 192.168.1.255 as the broadcast. What you want with allowing .177 to .204 needs separate subnets, but it looks like you need them in the same subnet for some reason, which is not explained. Please explain which you need...

Burt
 
I am trying to allow all IPs in the range xxx.xxx.xxx.177 to xxx.xxx.xxx.204 inclusive.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top