9.5 KiB
CGNAT /20 alignment plan
Goal
Make every router's CGNAT /20 base match its mgmt /20 base on the third
octet, so 10.10.X.0/20 is paired with 100.64.X.0/20 everywhere.
The mgmt subnets are already correctly aligned at /20. Only the CGNAT ranges need to move (and in three cases, widen).
Target state
| Router | Mgmt /20 | CGNAT today | CGNAT target | New gateway |
|---|---|---|---|---|
| verona | 10.10.0.0/20 | 100.64.0.0/22 | 100.64.0.0/20 | 100.64.3.254 (no change *) |
| altoga* | 10.10.80.0/20 | 100.64.12.0/22 | 100.64.80.0/20 | 100.64.95.254 |
| climax | 10.10.16.0/20 | 100.64.4.0/22 | 100.64.16.0/20 | 100.64.31.254 |
| culleoka | 10.10.96.0/20 | 100.64.24.0/22 | 100.64.96.0/20 | 100.64.111.254 |
| newhope | 10.10.128.0/20 | 100.64.16.0/22 | 100.64.128.0/20 | 100.64.143.254 |
| core | 10.10.64.0/20 | 100.64.8.0/22 | 100.64.64.0/20 | 100.64.79.254 |
| lowry | 10.10.144.0/20 | 100.64.144.0/20 | (already aligned) | 100.64.159.254 |
| 982 | 10.10.48.0/20 | 100.64.48.0/20 | (already aligned) | 100.64.63.254 |
| 494 | 10.10.160.0/20 | 100.64.160.0/20 | (already aligned) | 100.64.175.254 |
* Verona keeps its existing gateway because 100.64.3.254 is inside the
new /20; the change is just the netmask. Altoga sits on the verona
router (ether6-switch interface) and is treated as its own renumber.
Access point IPs: no changes
APs live in the top /24 of each mgmt /20. Mgmt /20s are not moving, so
no AP IPs change. The existing values in radios.yaml stay correct.
Why the order matters
Three /20s currently overlap with someone else's planned target:
100.64.0.0/20(verona's target) currently also contains climax's100.64.4.0/22, core's100.64.8.0/22, and altoga's100.64.12.0/22. Climax, core, and altoga must all leave before verona widens.100.64.16.0/20(climax's target) currently contains newhope's100.64.16.0/22. Newhope must leave before climax claims it.100.64.96.0/20and100.64.128.0/20and100.64.64.0/20and100.64.80.0/20are all empty today — those moves are clean.
That gives this order:
- culleoka →
100.64.96.0/20(clean) - newhope →
100.64.128.0/20(clean; frees100.64.16.0/20) - core →
100.64.64.0/20(clean; partly clears100.64.0.0/20) - climax →
100.64.16.0/20(target free after step 2; clears more of100.64.0.0/20) - altoga →
100.64.80.0/20(clean; clears the last subset of100.64.0.0/20) - verona widen
100.64.0.0/22→100.64.0.0/20(no overlap left)
Steps 1–5 are independent in pairs; the only hard precedences are 2-before-4 and 3+4+5-before-6.
The pattern (applies to every step except verona widening)
- Add the new pool, address, and dhcp-server-network on the existing interface.
- Point the PPP profile at the new pool and update its
local-address. - Disconnect existing PPPoE sessions (
/ppp active remove [find]) so they reconnect into the new range. - After confirming clients are on the new range, remove the old pool,
old
/ip address, and old/ip dhcp-server network. - Audit the config for any lingering references to the old gateway IP (hotspot profiles, scripts, firewall rules, NAT) and update them.
Pool/profile/interface names below come from the actual
.rscexports. Substitute if your live config has drifted.
Step 1 — culleoka: 100.64.24.0/22 → 100.64.96.0/20
# add new ----------------------------------------------------
/ip pool add name=culleoka-cgnat-new ranges=100.64.96.1-100.64.111.253
/ip address add address=100.64.111.254/20 interface=ether2-netonix \
comment="cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.96.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.111.254 ntp-server=204.110.191.19
# cut over ---------------------------------------------------
/ppp profile set [find name=pppoe] \
local-address=100.64.111.253 remote-address=culleoka-cgnat-new
/ppp active remove [find]
# verify, then clean up old ----------------------------------
/ip dhcp-server network remove [find address=100.64.24.0/22]
/ip address remove [find address=100.64.27.254/22]
/ip pool remove [find name=culleoka-cgnat]
/ip pool set [find name=culleoka-cgnat-new] name=culleoka-cgnat
Step 2 — newhope: 100.64.16.0/22 → 100.64.128.0/20
newhope already has two pools (cgnat and cgnat-full); both must go.
/ip pool add name=newhope-cgnat-new ranges=100.64.128.1-100.64.143.253
/ip address add address=100.64.143.254/20 interface=sfp-sfpplus1-edgepoint \
comment="cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.128.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.143.254 ntp-server=204.110.191.19
/ppp profile set [find name=newhope] \
local-address=100.64.143.253 remote-address=newhope-cgnat-new
/ppp active remove [find]
/ip dhcp-server network remove [find address=100.64.16.0/22]
/ip address remove [find address=100.64.19.254/22]
/ip pool remove [find name=cgnat]
/ip pool remove [find name=cgnat-full]
/ip pool set [find name=newhope-cgnat-new] name=newhope-cgnat
Step 3 — core: 100.64.8.0/22 → 100.64.64.0/20
/ip pool add name=core-cgnat-new ranges=100.64.64.1-100.64.79.253
/ip address add address=100.64.79.254/20 interface=combo1-380 \
comment="cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.64.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.79.254 ntp-server=204.110.191.19
/ppp profile set [find name=380] \
local-address=100.64.79.253 remote-address=core-cgnat-new
/ppp active remove [find]
/ip dhcp-server network remove [find address=100.64.8.0/22]
/ip address remove [find address=100.64.11.254/22]
# (core had no named cgnat pool in the export — confirm and remove if present)
/ip pool set [find name=core-cgnat-new] name=core-cgnat
Step 4 — climax: 100.64.4.0/22 → 100.64.16.0/20
This step depends on step 2 having completed.
/ip pool add name=climax-cgnat-new ranges=100.64.16.1-100.64.31.253
/ip address add address=100.64.31.254/20 interface=climax-bridge \
comment="cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.16.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.31.254 ntp-server=204.110.191.19
/ppp profile set [find name=pppoe] \
local-address=100.64.31.253 remote-address=climax-cgnat-new
/ppp active remove [find]
/ip dhcp-server network remove [find address=100.64.4.0/22]
/ip address remove [find address=100.64.7.254/22]
/ip pool remove [find name=cgnat]
/ip pool set [find name=climax-cgnat-new] name=climax-cgnat
Step 5 — altoga (on the verona router): 100.64.12.0/22 → 100.64.80.0/20
Run this on the verona router, against the
ether6-switchinterface and thepppoe-altogaprofile. Do not touch verona-cgnat in this step.
/ip pool add name=altoga-cgnat-new ranges=100.64.80.1-100.64.95.253
/ip address add address=100.64.95.254/20 interface=ether6-switch \
comment="altoga cgnat /20 (renumber)"
/ip dhcp-server network add address=100.64.80.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.95.254 ntp-server=204.110.191.19
/ppp profile set [find name=pppoe-altoga] \
local-address=100.64.95.253 remote-address=altoga-cgnat-new
/ppp active remove [find name~"altoga"] # narrow to altoga sessions only
/ip dhcp-server network remove [find address=100.64.12.0/22]
/ip address remove [find address=100.64.15.254/22]
/ip pool remove [find name=altoga-cgnat]
/ip pool set [find name=altoga-cgnat-new] name=altoga-cgnat
Step 6 — verona widen: 100.64.0.0/22 → 100.64.0.0/20
All of steps 3, 4, 5 must be complete first. After this, verona is the sole occupant of
100.64.0.0/20and the netmask widening is just a bookkeeping change — the existing gateway IP100.64.3.254stays.
# widen the pool first so new sessions can actually use the extra space
/ip pool set [find name=verona-cgnat] ranges=100.64.0.1-100.64.15.253
# widen the address (RouterOS won't change the mask in place; replace it)
/ip address remove [find address=100.64.3.254/22]
/ip address add address=100.64.3.254/20 interface=verona network=100.64.0.0 \
comment="cgnat /20 (widened from /22)"
# widen the dhcp-server network
/ip dhcp-server network remove [find address=100.64.0.0/22]
/ip dhcp-server network add address=100.64.0.0/20 \
dns-server=204.110.191.240,204.110.191.20 domain=vntx.net \
gateway=100.64.3.254 ntp-server=204.110.191.19
# (PPP profile pppoe-verona already references verona-cgnat — no change.)
# Cycle sessions if you want them on the wider range immediately:
/ppp active remove [find name~"verona"]
Post-migration audit checklist
Run on every renumbered router:
# any stale /22 references?
:put [/ip address find where address~"/22"]
:put [/ip dhcp-server network find where address~"/22"]
# any references to old gateways in scripts / firewall / nat?
/log print where message~"100.64."
/ip firewall nat print where dst-address~"100.64." or src-address~"100.64."
/ip firewall filter print where dst-address~"100.64." or src-address~"100.64."
Also re-pull the exports and re-run mikrotik-tool radios so
radios.yaml and subnets.yaml reflect the new layout.