Jump to content

Recommended Posts

Posted

We are running out of admin IP addresses and require a solution to free up addresses.

 

Our best idea at the minute would be to create a proxy server which will translate a DHCP address from an Admin Workstation into a single Admin IP Address - so all requests for the Admin server will appear to come from the same source. Think that makes sense!

 

We have had the idea of trying to source a Linux based solution for this, but we are not advanced users of Linux.

 

Does anyone have any websites they could point me to that will help, or any other suggestions to resolve the problem?

Posted

In what way are you running out? If you can let us know your IP Address ranges for all networks and also the associated subnet masks, we should be able to help. :)

 

Regards,

 

Rob Cowan.

Guest Guest
Posted

Im confused. Do you mean NATing/PATing?

 

So you want to have;

 

CurrentNetwork --- Proxy/Router --- New range of IPs

 

???

 

 

Why are you running out of IP address's?

Posted

Im going to try and clear up exactly what I need!

 

All our Admin machines use static IP addresses. Our curriculum machines use DHCP, and we have loads of IP addresses in this range.

 

We are now running out of static IP addresses on our Admin IP range. We want to be able to make all the Admin machines DHCP. Any requests from an Admin workstation to the Admin server will pass through a server which will sit in the middle that will point the request to the Admin server.

 

The proxy server that sits in the middle will have two network cards. One will have a DHCP Address, and the other will have a static Admin IP address that will allow the server to communicate with the Admin server.

 

I hope this helps ... still not sure if it makes sense!

Posted
Ahh I see, was going to say we had a similar problem with our curriculum IPs recently, we adjusted the scope from 10.200.1.x to include 10.200.2.x giving ourselves a wodge more IPs. But thats no use to you if someone else is nicking the IPs :D
Posted

OK, just to clarify and see if I'm understanding this...

 

You currently have two networks - admin and curriculum. Admin machines have static IP addresses while curriculum machines receive through DHCP. Are we talking completely different address ranges (ie, admin 192.168.1.x subnet 255.255.255.0, curr. 192.168.2.x subnet 255.255.255.0), or two ends of a single range (ie, 192.168.1.1-200 for curriculum, 192.168.1.201-254 for admin)?

 

From what I can tell, you are looking at adding an intermediate machine as a DHCP server. This server will talk to DHCP-assigned admin machines on one NIC, and the static assigned admin server on the other.

 

If this is the case, you don't need to do it like this. The Admin server (I'm assuming it's running either server 2000 or 2003) can become the DHCP server for the admin range, and still have a static assigned address for itself (in fact, it has to have a static address for itself).

 

If I've got the wrong end of the stick, let me know. Otherwise, I hope it helps point you in the right direction.

 

Rob.

Posted

Ah, just saw your reply after I posted...!

 

Is it possible to get a different range with enough addresses from the relevant authorities?

 

Rob.

Posted

Or put a machine in between you and the lea thus enabling you to run whatever internal network scope you desire?

 

All outbound connections natting through it?

 

Ben

Posted

I wish it was that simple! The rest of the range is (according to .ict) in use by another school on the embc network.

 

Are you saying all your schools are connected to a single network using the same Ip ranges or part thereof??

 

This does not sound right to me, all our school do indeed sit on a connected community network but have a 10.x.x.x gateway address while all internal IPs inc Admin have a 192.168.x.x address this way you do not clash with other schools.

 

I agree with RobC that you could just make your admin server a dhcp server but you say that your curric pc's are dhcp assigned so I have to assume that you have a dhcp server on your network already if that is the case adding another dhcp server will introduce problems.

 

Can you not use the exisitng dhcp server to assign the dhcp to the admin pc's or can they not see it, hence the static assignment.

 

Also you say you are running out of IP's this must mean that you have more than 253 ip's assigned on your admin network???

Posted
Are you saying all your schools are connected to a single network using the same Ip ranges or part thereof??

 

This does not sound right to me,

 

That's how it works here in Lancs.

 

I have to assume that you have a dhcp server on your network already if that is the case adding another dhcp server will introduce problems

 

implementing VLANs can get round this problem.

 

Also you say you are running out of IP's this must mean that you have more than 253 ip's assigned on your admin network

 

Err...CIDR? He might not have a complete class C.

Posted
Well, as the IP address ranges are given to you by your supplier, I would contact them and ask for a bigger subnet - they should have systems in place to deal with this - if not then they are failing at a key part of their job.
Posted

Effectively we are a WAN, not a LAN so IP addresses are limited. We do not have 253 admin machines - the subnet we use limits the addresses availabe to 124.

 

If we use others in this range, we will be pinching them from another school!

Posted

Your provider should be able to change which subnet you have been assigned. Try giving them a call. If they can't then they aren't doing their job.

 

However, that then doesn't help you. You could simply choose your own subnet for the admin machines, stick an ISA box with DHCP on it in between the 2 and get it to NAT requests between the 2. But again, your provider should tell you this.

Posted

@Geoff, Craig_W: This makes sense now, effectively the LEA is merely an ISP type of affair.

 

In that case I agree with localzuk contact the provider and ask them to increase what you have, there is also the possibility that if you try to do something smart within the school to fool (NAT) to a single IP your provider may take a dim view on this especially if they are logging IP usage and such.

Posted
there is also the possibility that if you try to do something smart within the school to fool (NAT) to a single IP your provider may take a dim view on this especially if they are logging IP usage and such.

 

I don't think they are that bothered. However I am. I don't like it when windows worms run rampant through the LEA WAN and take out entire schools. As such, I'll keep my firewall (it's not NAT'ing though, just a layer 2 bridge). :)

Guest Guest
Posted

Im still confused as to what the problem is?

What range have you been assigned? Whats the subnet?

 

 

I find it strange as we have been given a /20 subnet mask thus giving us *unlimited ip address'. I cant see why they've give you such a small range.

 

*obviously not unlimited but for a school its enough.

Posted
j17sparky - here's an example. We have been given an /22 subnet, giving us 1016 usable addresses. This is plenty for us. But some schools will have been given a smaller subnet - in this case a total of 124. This is simply down to the way the supplier has doled out the subnets, and as such is their responsibility to fix it...
Guest Guest
Posted

124? 8O I read that as theres 124 in the admin.

 

 

Well id be onto your provider and get them to sort it out as the problem will only get worse.

 

If they wont sort it id just set up my own private class B behind the single current router and get it NAT/PATing. Otherwise your going to have 2 routers and there simply isnt any need for that with that many clients.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...