ASUS ROG Rapture GT-BE98 Pro Subnet Settings

Configure subnet and VLAN settings on the ASUS ROG Rapture GT-BE98 Pro gaming router. Default LAN IP, DHCP pool, and steps to use gaming QoS features with custom subnets.

ZERO UPLOAD · ALL LOCAL
  1. Enter an IP address (IPv4 like 192.168.1.0 or IPv6 like 2001:db8::) into the input box.
  2. Set the CIDR prefix using the number input. The tool auto-detects IPv4 or IPv6.
  3. Results appear instantly: network address, usable IP range, host count, and more.
  4. Use the Copy buttons next to each field to grab individual values.
  5. Toggle between IPv4 and IPv6 by simply changing the IP address format.

Default LAN subnet for this router

192.168.50.0/24 is this router's default LAN subnet. ASUS uses .50 to reduce conflicts with ISP modem-routers. The IP and CIDR fields below are pre-filled to it.

Matches ASUS ROG Rapture GT-BE98 Pro spec
/

SUBNET CALCULATION RESULTS

IP Version
Network Address
Broadcast Address
First Usable IP
Last Usable IP
Total Addresses
Usable Hosts
Wildcard Mask
CIDR Notation
IP Class
IP Type
Binary (IP)
Binary (Mask)
Hex Range Start
Hex Range End
Usable Host Count

ASUS ROG Rapture GT-BE98 Pro Subnet Settings Guide

The ASUS ROG Rapture GT-BE98 Pro is ASUS's flagship Wi-Fi 7 gaming router, offering 24 Gbps aggregate throughput across 2.4 GHz, 5 GHz low, 5 GHz high, and 6 GHz bands. Its default LAN subnet is 192.168.50.0/24. ASUS uses .50 to reduce conflicts with ISP modem-routers that default to 192.168.0.x or 192.168.1.x. For gamers who connect consoles and gaming PCs alongside streaming devices and smart-home sensors, subnet segmentation reduces inter-device interference and allows QoS rules to target entire subnets rather than individual IPs.

Specifications1

Default LAN IP192.168.50.1
Default subnet mask255.255.255.0
CIDR notation192.168.50.0/24
Default DHCP pool192.168.50.2 – 192.168.50.254
Max DHCP leases253 (full /24 pool)
IPv6 supportYes — DHCPv6, SLAAC, 6in4, 6to4
Wi-Fi standardWi-Fi 7 (802.11be), quad-band
Management interfacehttp://router.asus.com or http://192.168.50.1

Default subnet configuration

The ROG Rapture GT-BE98 Pro defaults to 192.168.50.0/24,2 placing 253 DHCP addresses in a flat network. ASUS chose the .50.x range to minimize conflicts with ISP-provided gateways at .0.1 and .1.1. The full DHCP pool covers .2 through .254, leaving no reserved static range by default. For gaming households with consoles needing consistent IPs for port forwarding, configuring DHCP reservations under LAN > DHCP Server > Manually Assigned IP is essential. Building on this, the GT-BE98 Pro's adaptive QoS feature classifies traffic by device, which works more reliably when gaming devices use static assignments rather than dynamic leases that could change after a router restart.

Changing subnet settings on the GT-BE98 Pro

Navigate to http://192.168.50.1 or http://router.asus.com and log in. Go to LAN > LAN IP. The LAN IP address and Subnet Mask fields control the subnet. Change the IP to 10.0.0.1 and the mask to 255.255.255.0 for a /24 at 10.0.0.x, or 255.255.0.0 for a /16. Click Apply. The DHCP Server section under LAN > DHCP Server automatically updates its pool boundaries and verify the pool start and end are within the new subnet range. Building on this, the router reboots network services and connected devices must renew leases. Static DHCP bindings are also under LAN > DHCP Server as the Manually Assigned IP table.

Choosing a subnet mask for gaming households

For most gaming households, the default /24 subnet mask (255.255.255.0) provides 253 usable addresses, which suits a typical mix of consoles, PCs, streaming devices, and smart-home sensors without requiring VLAN segmentation. If you plan to isolate IoT devices or run a guest network with separate addressing, switching to a /23 mask (255.255.254.0) and partitioning the resulting 510 address space with VLANs gives each trust zone enough headroom. CapyToolkit's subnet calculator shows the usable address range for any mask you consider so you can verify the pool covers all planned devices before applying settings in the ASUS admin panel.

Multi-subnet and VLAN patterns for gaming

The GT-BE98 Pro includes a guest Wi-Fi network that isolates guest devices from the primary LAN.3 This is useful for separating streaming devices and smart-home sensors from gaming hardware. For full VLAN segmentation, the router's LAN ports support 802.1Q VLAN tagging when used with a managed switch. A common gaming setup: gaming VLAN (192.168.50.0/24 with low latency QoS priority), IoT VLAN (192.168.51.0/24, isolated), streaming VLAN (192.168.52.0/24, medium QoS). Consequently, ASUS's Traffic Analyzer applies separate QoS profiles to each VLAN. Planning each CIDR block with the subnet calculator before configuring the switch ensures non-overlapping allocations and correct gateway assignments for each segment.

Isolating gaming traffic with VLAN tags

Assign the gaming VLAN an 802.1Q tag matching the QoS priority level in the ASUS admin panel so the router applies low-latency queuing to frames tagged with the VLAN identifier from the managed switch. This ensures that upstream internet traffic from consoles and gaming PCs receives priority processing during congestion without competing against streaming or IoT bursts on the physical LAN segment. CapyToolkit's subnet calculator validates each CIDR allocation before you assign VLAN subinterfaces so the gaming CIDR never overlaps with the streaming or management ranges.

The GT-BE98 Pro also exposes a dedicated Gaming Port among its seven LAN ports, a low-latency Ethernet port that ASUS's own specifications call out separately from the standard 10Gbps, 2.5Gbps, and 1Gbps LAN ports. Wiring a gaming PC or console directly into the Gaming Port gives it a hardware-level fast path that complements VLAN-based QoS tagging, so latency-sensitive traffic gets priority treatment even before it reaches the switch where 802.1Q tags are applied.

AiProtection and subnet-aware firewall rules

ASUS AiProtection powered by Trend Micro inspects traffic at the network edge, blocking known-malicious IPs and scanning outbound connections for command-and-control signatures. AiProtection works at the router level, so it covers every device on the LAN without installing agents. Yet its effectiveness depends on correct subnet configuration: if the router's LAN subnet does not match the actual address range of connected devices, AiProtection may fail to inspect traffic from devices on unrecognized segments.

For multi-VLAN setups, AiProtection inspects traffic that passes through the router's inter-VLAN routing engine. Building on this, placing gaming devices on a dedicated VLAN with a known CIDR (for example, 192.168.50.0/24) lets you create AiProtection rules that apply only to that segment. IoT devices on a separate VLAN can receive stricter inspection profiles while gaming traffic passes through with minimal latency overhead. Consequently, the combination of VLAN segmentation and AiProtection creates a layered defense: the VLAN contains lateral movement, and AiProtection filters outbound threats per segment.

Configuring VPN subnets alongside gaming VLANs

The GT-BE98 Pro supports both ASUSWRT VPN server (OpenVPN and WireGuard) and VPN client modes. When you run a VPN server on the router, remote clients need their own subnet that does not overlap with any existing VLAN. Assign the VPN pool to 192.168.51.0/24, separate from the gaming VLAN at 192.168.50.0/24 and the IoT VLAN at 192.168.52.0/24. Building on this, the router's firewall rules control whether VPN clients can reach the gaming VLAN, the IoT VLAN, or only the internet. For competitive gaming, allowing VPN clients access to the gaming VLAN while blocking them from IoT segments prevents compromised remote devices from probing smart-home sensors.

Port forwarding and DMZ with custom subnets

The GT-BE98 Pro's port forwarding feature maps external ports to internal IP addresses, which requires the target device to have a consistent IP. When you change the router's subnet (for example, from 192.168.50.0/24 to 10.0.0.0/24), every existing port forwarding rule breaks because the internal IPs it references no longer exist. Before changing the subnet, document all port forwarding rules and DHCP reservations, then recreate them using addresses in the new range.

The DMZ host feature exposes one internal IP entirely to the internet, bypassing the router's firewall for that single address. Building on this, placing the DMZ host on its own small subnet (a /30 or /29) rather than the main LAN limits the blast radius if the DMZ host is compromised. For a game server that needs direct internet exposure, assign it 10.0.0.2/29 on the DMZ segment while the main gaming VLAN sits at 10.0.1.0/24. Consequently, an attacker who compromises the game server gains access to only the /29 DMZ segment, not the 253-host gaming VLAN behind it. carve a DMZ subnet for a game server on the ASUS GT-BE98 before opening any inbound ports.

Sources
  1. 1.

    ASUS, "ROG Rapture GT-BE98 Pro Specifications," rog.asus.com, accessed June 2026. https://rog.asus.com/networking/rog-rapture-gt-be98-pro/spec/

  2. 2.

    ASUS, "ROG Rapture GT-BE98 Pro Support," asus.com, accessed June 2026. https://www.asus.com/us/supportonly/gt-be98%20pro/helpdesk_bios/

  3. 3.

    ASUS, "GT-BE98 Pro User Manual," asus.com, accessed June 2026. https://dlcdnets.asus.com/pub/ASUS/wireless/GT-BE98/GT-BE98_UM_WEB.pdf

FAQ