Skip to main content
dpsguard
New Member
March 7, 2021
Question

Routing a Public /29 block over /30 transport block and use all 8 IPs of /29

  • March 7, 2021
  • 2 replies
  • 4144 views

Hello forum members and experts,

 

I need to use an additional Public IP block of /29 over /30 transport block. Since this /29 block wont be assigned to any interface, but will just be used on VIPs to map to the inside servers, and thus no L2 / ARP on this block, I should be able to use all 8 IPs (not just 5) since there should be no concept of network ID, gateway and broadcast address when routed thru a static route by ISP to the /30 IP on my firewall WAN port?

 

Can someone please confirm this?

 

Thanks

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    March 7, 2021

    The same question pops up time to time in the forum. The answer is "yes".

    dpsguard
    dpsguardAuthor
    New Member
    March 7, 2021

    Thank you so much Toshi Esumi for confirming my logic. I did spend time to search thru this forum as well as did Google search but I did not find specific question and specific response to it. Most will talk that yes this is standard practice to route over the transport block and that you then assign one IP address for gateway to LAN interface of the edge router and then have the firewall WAN attached to that interface of the router. Those used to be the traditional method years ago and what I wanted was to terminate the /30 and /29 directly on the firewall.

     

    Appreciate again for your quick response and confirmation.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!