network/mikrotik-tool/subnets.md
2026-05-08 17:47:42 -05:00

231 lines
9.5 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# CGNAT /20 alignment plan
## Goal
Make every router's CGNAT /20 base match its mgmt /20 base on the third
octet, so `10.10.X.0/20` is paired with `100.64.X.0/20` everywhere.
The **mgmt** subnets are already correctly aligned at /20. Only the
**CGNAT** ranges need to move (and in three cases, widen).
## Target state
| Router | Mgmt /20 | CGNAT today | CGNAT target | New gateway |
|----------|------------------|--------------------|--------------------|-----------------|
| verona | 10.10.0.0/20 | 100.64.0.0/22 | 100.64.0.0/20 | 100.64.3.254 (no change \*) |
| altoga\* | 10.10.80.0/20 | 100.64.12.0/22 | 100.64.80.0/20 | 100.64.95.254 |
| climax | 10.10.16.0/20 | 100.64.4.0/22 | 100.64.16.0/20 | 100.64.31.254 |
| culleoka | 10.10.96.0/20 | 100.64.24.0/22 | 100.64.96.0/20 | 100.64.111.254 |
| newhope | 10.10.128.0/20 | 100.64.16.0/22 | 100.64.128.0/20 | 100.64.143.254 |
| core | 10.10.64.0/20 | 100.64.8.0/22 | 100.64.64.0/20 | 100.64.79.254 |
| lowry | 10.10.144.0/20 | 100.64.144.0/20 | (already aligned) | 100.64.159.254 |
| 982 | 10.10.48.0/20 | 100.64.48.0/20 | (already aligned) | 100.64.63.254 |
| 494 | 10.10.160.0/20 | 100.64.160.0/20 | (already aligned) | 100.64.175.254 |
\* Verona keeps its existing gateway because `100.64.3.254` is inside the
new /20; the change is just the netmask. Altoga sits on the verona
router (`ether6-switch` interface) and is treated as its own renumber.
## Access point IPs: no changes
APs live in the top /24 of each mgmt /20. Mgmt /20s are not moving, so
**no AP IPs change**. The existing values in `radios.yaml` stay correct.
## Why the order matters
Three /20s currently overlap with someone else's planned target:
- **`100.64.0.0/20`** (verona's target) currently also contains
climax's `100.64.4.0/22`, core's `100.64.8.0/22`, and altoga's
`100.64.12.0/22`. Climax, core, and altoga must all leave before
verona widens.
- **`100.64.16.0/20`** (climax's target) currently contains newhope's
`100.64.16.0/22`. Newhope must leave before climax claims it.
- **`100.64.96.0/20`** and **`100.64.128.0/20`** and **`100.64.64.0/20`**
and **`100.64.80.0/20`** are all empty today — those moves are clean.
That gives this order:
1. **culleoka**`100.64.96.0/20` (clean)
2. **newhope**`100.64.128.0/20` (clean; frees `100.64.16.0/20`)
3. **core**`100.64.64.0/20` (clean; partly clears `100.64.0.0/20`)
4. **climax**`100.64.16.0/20` (target free after step 2; clears more of `100.64.0.0/20`)
5. **altoga**`100.64.80.0/20` (clean; clears the last subset of `100.64.0.0/20`)
6. **verona** widen `100.64.0.0/22``100.64.0.0/20` (no overlap left)
Steps 15 are independent in pairs; the only hard precedences are
2-before-4 and 3+4+5-before-6.
## The pattern (applies to every step except verona widening)
1. Add the new pool, address, and dhcp-server-network on the existing
interface.
2. Point the PPP profile at the new pool and update its `local-address`.
3. Disconnect existing PPPoE sessions (`/ppp active remove [find]`) so
they reconnect into the new range.
4. After confirming clients are on the new range, remove the old pool,
old `/ip address`, and old `/ip dhcp-server network`.
5. Audit the config for any lingering references to the old gateway IP
(hotspot profiles, scripts, firewall rules, NAT) and update them.
> Pool/profile/interface names below come from the actual `.rsc` exports.
> Substitute if your live config has drifted.
---
## Step 1 — culleoka: 100.64.24.0/22 → 100.64.96.0/20
```rsc
# add new ----------------------------------------------------
/ip pool add name=culleoka-cgnat-new ranges=100.64.96.1-100.64.111.253
/ip address add address=100.64.111.254/20 interface=ether2-netonix \
comment="cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.96.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.111.254 ntp-server=204.110.191.19
# cut over ---------------------------------------------------
/ppp profile set [find name=pppoe] \
local-address=100.64.111.253 remote-address=culleoka-cgnat-new
/ppp active remove [find]
# verify, then clean up old ----------------------------------
/ip dhcp-server network remove [find address=100.64.24.0/22]
/ip address remove [find address=100.64.27.254/22]
/ip pool remove [find name=culleoka-cgnat]
/ip pool set [find name=culleoka-cgnat-new] name=culleoka-cgnat
```
## Step 2 — newhope: 100.64.16.0/22 → 100.64.128.0/20
newhope already has two pools (`cgnat` and `cgnat-full`); both must go.
```rsc
/ip pool add name=newhope-cgnat-new ranges=100.64.128.1-100.64.143.253
/ip address add address=100.64.143.254/20 interface=sfp-sfpplus1-edgepoint \
comment="cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.128.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.143.254 ntp-server=204.110.191.19
/ppp profile set [find name=newhope] \
local-address=100.64.143.253 remote-address=newhope-cgnat-new
/ppp active remove [find]
/ip dhcp-server network remove [find address=100.64.16.0/22]
/ip address remove [find address=100.64.19.254/22]
/ip pool remove [find name=cgnat]
/ip pool remove [find name=cgnat-full]
/ip pool set [find name=newhope-cgnat-new] name=newhope-cgnat
```
## Step 3 — core: 100.64.8.0/22 → 100.64.64.0/20
```rsc
/ip pool add name=core-cgnat-new ranges=100.64.64.1-100.64.79.253
/ip address add address=100.64.79.254/20 interface=combo1-380 \
comment="cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.64.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.79.254 ntp-server=204.110.191.19
/ppp profile set [find name=380] \
local-address=100.64.79.253 remote-address=core-cgnat-new
/ppp active remove [find]
/ip dhcp-server network remove [find address=100.64.8.0/22]
/ip address remove [find address=100.64.11.254/22]
# (core had no named cgnat pool in the export — confirm and remove if present)
/ip pool set [find name=core-cgnat-new] name=core-cgnat
```
## Step 4 — climax: 100.64.4.0/22 → 100.64.16.0/20
> This step depends on step 2 having completed.
```rsc
/ip pool add name=climax-cgnat-new ranges=100.64.16.1-100.64.31.253
/ip address add address=100.64.31.254/20 interface=climax-bridge \
comment="cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.16.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.31.254 ntp-server=204.110.191.19
/ppp profile set [find name=pppoe] \
local-address=100.64.31.253 remote-address=climax-cgnat-new
/ppp active remove [find]
/ip dhcp-server network remove [find address=100.64.4.0/22]
/ip address remove [find address=100.64.7.254/22]
/ip pool remove [find name=cgnat]
/ip pool set [find name=climax-cgnat-new] name=climax-cgnat
```
## Step 5 — altoga (on the verona router): 100.64.12.0/22 → 100.64.80.0/20
> Run this on the **verona** router, against the `ether6-switch` interface
> and the `pppoe-altoga` profile. Do **not** touch verona-cgnat in this
> step.
```rsc
/ip pool add name=altoga-cgnat-new ranges=100.64.80.1-100.64.95.253
/ip address add address=100.64.95.254/20 interface=ether6-switch \
comment="altoga cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.80.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.95.254 ntp-server=204.110.191.19
/ppp profile set [find name=pppoe-altoga] \
local-address=100.64.95.253 remote-address=altoga-cgnat-new
/ppp active remove [find name~"altoga"] # narrow to altoga sessions only
/ip dhcp-server network remove [find address=100.64.12.0/22]
/ip address remove [find address=100.64.15.254/22]
/ip pool remove [find name=altoga-cgnat]
/ip pool set [find name=altoga-cgnat-new] name=altoga-cgnat
```
## Step 6 — verona widen: 100.64.0.0/22 → 100.64.0.0/20
> All of steps 3, 4, 5 must be complete first. After this, verona is the
> sole occupant of `100.64.0.0/20` and the netmask widening is just a
> bookkeeping change — the existing gateway IP `100.64.3.254` stays.
```rsc
# widen the pool first so new sessions can actually use the extra space
/ip pool set [find name=verona-cgnat] ranges=100.64.0.1-100.64.15.253
# widen the address (RouterOS won't change the mask in place; replace it)
/ip address remove [find address=100.64.3.254/22]
/ip address add address=100.64.3.254/20 interface=verona network=100.64.0.0 \
comment="cgnat /20 (widened from /22)"
# widen the dhcp-server network
/ip dhcp-server network remove [find address=100.64.0.0/22]
/ip dhcp-server network add address=100.64.0.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.3.254 ntp-server=204.110.191.19
# (PPP profile pppoe-verona already references verona-cgnat — no change.)
# Cycle sessions if you want them on the wider range immediately:
/ppp active remove [find name~"verona"]
```
---
## Post-migration audit checklist
Run on every renumbered router:
```rsc
# any stale /22 references?
:put [/ip address find where address~"/22"]
:put [/ip dhcp-server network find where address~"/22"]
# any references to old gateways in scripts / firewall / nat?
/log print where message~"100.64."
/ip firewall nat print where dst-address~"100.64." or src-address~"100.64."
/ip firewall filter print where dst-address~"100.64." or src-address~"100.64."
```
Also re-pull the exports and re-run `mikrotik-tool radios` so
`radios.yaml` and `subnets.yaml` reflect the new layout.