Extending the subnet
I have a FortiGate and I am running out of IP addresses in the subnet. I have set the DHCP lease for an hour to allow for the leases to expire more quickly but I still need more.
The way I have it setup now is the network is on a 10.20.1.x network. There are no VLANs on the network (even though there are layer 2 switches). I would like to just create networks for each VLAN but it requires me to set up the VLANs on all the switches (which I would have to reset the config on the cisco switches with a known password (not my network)).
I got to thinking wouldn't it be easier to just change the FortiGate interface to add another subnet? Couldn't I just add a secondary IP say 10.20.2.x and add that 10.20.2.2-10.20.2.254 to the pool? When 1 pool is out does it just pick up the next pool in the subnet?
Another thought that I had was can I just change the pool subnet network to be a 255.255.0.0 and then set the pool to be 10.20.1.20-10.20.2.254? Would that give me more IP addresses and still allow me to filter everything out of the same policy?
If that fixes it then I could go in setup the VLANs afterwards and really segment the network out (which I am going to do). There is a definite need for IP addresses that I am trying to address first.
Any thoughts would be appreciated.
