Change the LAN Subnet and DHCP Range on Your Router
Most people change a router's LAN subnet for one of three reasons: it clashes with the ISP modem in front of it, a VPN or second site uses the same range, or the network needs room to split into VLANs. The change itself takes a minute. What takes planning is everything that depends on the old addresses, because DHCP reservations, port forwarding rules and any device with a static IP all point at the old range and stop working once the router moves.
Router makers do not agree on defaults, which is the first thing to check. ASUS ships 192.168.50.0/24, TP-Link's Archer routers ship 192.168.0.0/24 and its Deco mesh ships 192.168.68.0/24, Netgear and the Ubiquiti UDM-Pro ship 192.168.1.0/24, and eero uses a wider 192.168.4.0/22 with 1,022 usable addresses. Each section gives that router's default subnet and DHCP pool, the menu path to change it, its guest, IoT and VLAN options, and what to update afterwards. Before you save a new range, run it through the subnet calculator to confirm the gateway address, usable host range and broadcast address.
Default LAN subnets on these routers
- ASUS ROG Rapture GT-BE98 Pro 192.168.50.0/24
- Netgear Nighthawk RS700S 192.168.1.0/24
- TP-Link Archer BE900 192.168.0.0/24
- TP-Link Deco BE63 192.168.68.0/24
- eero Pro 7 192.168.4.0/22
- Ubiquiti UDM-Pro 192.168.1.0/24
Enter the new range in the calculator before you save it on the router, and check that it does not overlap your modem, VPN or other sites.
Opens the Subnet Calculator with this page's reference values shown at the top of the tool.
Open in the tool →ASUS ROG Rapture GT-BE98 Pro Subnet Settings
The ASUS ROG Rapture GT-BE98 Pro is ASUS's flagship Wi-Fi 7 gaming router, offering 24 Gbps aggregate throughput across 2.4 GHz, 5 GHz low, 5 GHz high, and 6 GHz bands. Its default LAN subnet is 192.168.50.0/24. ASUS uses .50 to reduce conflicts with ISP modem-routers that default to 192.168.0.x or 192.168.1.x. For gamers who connect consoles and gaming PCs alongside streaming devices and smart-home sensors, subnet segmentation reduces inter-device interference and allows QoS rules to target entire subnets rather than individual IPs.
Run this check yourself in the Subnet Calculator.
Open in the tool →Specifications1
| Default LAN IP | 192.168.50.1 |
|---|---|
| Default subnet mask | 255.255.255.0 |
| CIDR notation | 192.168.50.0/24 |
| Default DHCP pool | 192.168.50.2 – 192.168.50.254 |
| Max DHCP leases | 253 (full /24 pool) |
| IPv6 support | Yes — DHCPv6, SLAAC, 6in4, 6to4 |
| Wi-Fi standard | Wi-Fi 7 (802.11be), quad-band |
| Management interface | http://router.asus.com or http://192.168.50.1 |
Why ASUS ships 192.168.50.0/24 with no static range
The ROG Rapture GT-BE98 Pro defaults to 192.168.50.0/24,2 placing 253 DHCP addresses in a flat network. ASUS chose the .50.x range to minimize conflicts with ISP-provided gateways at .0.1 and .1.1. The full DHCP pool covers .2 through .254, leaving no reserved static range by default. For gaming households with consoles needing consistent IPs for port forwarding, configuring DHCP reservations under LAN > DHCP Server > Manually Assigned IP is essential. Building on this, the GT-BE98 Pro's adaptive QoS feature classifies traffic by device, which works more reliably when gaming devices use static assignments rather than dynamic leases that could change after a router restart.
Changing subnet settings on the GT-BE98 Pro
Navigate to http://192.168.50.1 or http://router.asus.com and log in. Go to LAN > LAN IP. The LAN IP address and Subnet Mask fields control the subnet. Change the IP to 10.0.0.1 and the mask to 255.255.255.0 for a /24 at 10.0.0.x, or 255.255.0.0 for a /16. Click Apply. The DHCP Server section under LAN > DHCP Server automatically updates its pool boundaries and verify the pool start and end are within the new subnet range. Building on this, the router reboots network services and connected devices must renew leases. Static DHCP bindings are also under LAN > DHCP Server as the Manually Assigned IP table.
Choosing a subnet mask for gaming households
For most gaming households, the default /24 subnet mask (255.255.255.0) provides 253 usable addresses, which suits a typical mix of consoles, PCs, streaming devices, and smart-home sensors without requiring VLAN segmentation. If you plan to isolate IoT devices or run a guest network with separate addressing, switching to a /23 mask (255.255.254.0) and partitioning the resulting 510 address space with VLANs gives each trust zone enough headroom. CapyToolkit's subnet calculator shows the usable address range for any mask you consider so you can verify the pool covers all planned devices before applying settings in the ASUS admin panel.
Gaming, IoT and streaming VLANs with separate QoS
The GT-BE98 Pro includes Guest Network Pro, whose networks carry an Access Intranet setting meant to keep guest devices off the primary LAN. One owner on firmware 3006.102.2 reported that turning Access Intranet off still left every LAN device reachable, so test isolation from a guest device before you rely on it.3 Separating guests this way is useful for separating streaming devices and smart-home sensors from gaming hardware. For full VLAN segmentation, the router's LAN ports support 802.1Q VLAN tagging when used with a managed switch. A common gaming setup: gaming VLAN (192.168.50.0/24 with low latency QoS priority), IoT VLAN (192.168.51.0/24, isolated), streaming VLAN (192.168.52.0/24, medium QoS). Consequently, ASUS's Traffic Analyzer applies separate QoS profiles to each VLAN. Planning each CIDR block with the subnet calculator before configuring the switch ensures non-overlapping allocations and correct gateway assignments for each segment.4
Isolating gaming traffic with VLAN tags
Assign the gaming VLAN an 802.1Q tag matching the QoS priority level in the ASUS admin panel so the router applies low-latency queuing to frames tagged with the VLAN identifier from the managed switch. This ensures that upstream internet traffic from consoles and gaming PCs receives priority processing during congestion without competing against streaming or IoT bursts on the physical LAN segment. CapyToolkit's subnet calculator validates each CIDR allocation before you assign VLAN subinterfaces so the gaming CIDR never overlaps with the streaming or management ranges.
The GT-BE98 Pro also exposes a dedicated Gaming Port among its seven LAN ports, a low-latency Ethernet port that ASUS's own specifications call out separately from the standard 10Gbps, 2.5Gbps, and 1Gbps LAN ports. Wiring a gaming PC or console directly into the Gaming Port gives it a hardware-level fast path that complements VLAN-based QoS tagging, so latency-sensitive traffic gets priority treatment even before it reaches the switch where 802.1Q tags are applied.
AiProtection and subnet-aware firewall rules
ASUS AiProtection powered by Trend Micro inspects traffic at the network edge, blocking known-malicious IPs and scanning outbound connections for command-and-control signatures. AiProtection works at the router level, so it covers every device on the LAN without installing agents. Yet its effectiveness depends on correct subnet configuration: if the router's LAN subnet does not match the actual address range of connected devices, AiProtection may fail to inspect traffic from devices on unrecognized segments.
For multi-VLAN setups, AiProtection inspects traffic that passes through the router's inter-VLAN routing engine. Building on this, placing gaming devices on a dedicated VLAN with a known CIDR (for example, 192.168.50.0/24) lets you create AiProtection rules that apply only to that segment. IoT devices on a separate VLAN can receive stricter inspection profiles while gaming traffic passes through with minimal latency overhead. Consequently, the combination of VLAN segmentation and AiProtection creates a layered defense: the VLAN contains lateral movement, and AiProtection filters outbound threats per segment.
Configuring VPN subnets alongside gaming VLANs
The GT-BE98 Pro supports both ASUSWRT VPN server (OpenVPN and WireGuard) and VPN client modes. When you run a VPN server on the router, remote clients need their own subnet that does not overlap with any existing VLAN. Assign the VPN pool to 192.168.51.0/24, separate from the gaming VLAN at 192.168.50.0/24 and the IoT VLAN at 192.168.52.0/24. Building on this, the router's firewall rules control whether VPN clients can reach the gaming VLAN, the IoT VLAN, or only the internet. For competitive gaming, allowing VPN clients access to the gaming VLAN while blocking them from IoT segments prevents compromised remote devices from probing smart-home sensors.
Port forwarding and DMZ with custom subnets
The GT-BE98 Pro's port forwarding feature maps external ports to internal IP addresses, which requires the target device to have a consistent IP. When you change the router's subnet (for example, from 192.168.50.0/24 to 10.0.0.0/24), every existing port forwarding rule breaks because the internal IPs it references no longer exist. Before changing the subnet, document all port forwarding rules and DHCP reservations, then recreate them using addresses in the new range.
The DMZ host feature exposes one internal IP entirely to the internet, bypassing the router's firewall for that single address. Building on this, placing the DMZ host on its own small subnet (a /30 or /29) rather than the main LAN limits the blast radius if the DMZ host is compromised. For a game server that needs direct internet exposure, assign it 10.0.0.2/29 on the DMZ segment while the main gaming VLAN sits at 10.0.1.0/24. Consequently, an attacker who compromises the game server gains access to only the /29 DMZ segment, not the 253-host gaming VLAN behind it.5 carve a DMZ subnet for a game server on the ASUS GT-BE98 before opening any inbound ports.
- 1.
ASUS, "ROG Rapture GT-BE98 Pro Specifications," rog.asus.com, accessed June 2026. https://rog.asus.com/networking/rog-rapture-gt-be98-pro/spec/
- 2.
ASUS, "ROG Rapture GT-BE98 Pro Support," asus.com, accessed June 2026. https://www.asus.com/us/supportonly/gt-be98%20pro/helpdesk_bios/
- 3.
SNBForums, "GT BE98 Pro Guest Network Cannot Disable Intranet Access," snbforums.com, November 2024. https://www.snbforums.com/threads/gt-be98-pro-guest-network-cannot-disable-intranet-access.92790/
- 4.
V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632
- 5.
R. Baker, "Address Allocation for Private Internets," RFC 1918, IETF, February 1996. https://www.rfc-editor.org/rfc/rfc1918.html
192.168.50.1. ASUS uses 192.168.50.x to avoid conflicting with ISP router defaults at 192.168.0.1 and 192.168.1.1. Access the admin interface at http://192.168.50.1 or http://router.asus.com.
Go to LAN > LAN IP in the admin interface. Edit the LAN IP and Subnet Mask fields. Click Apply. Verify the DHCP pool under LAN > DHCP Server is updated to match the new subnet range. CapyToolkit's subnet calculator shows you the new pool boundaries before you apply changes so you can confirm the DHCP range covers your gaming devices.
The GT-BE98 Pro supports guest network isolation natively. For multi-VLAN homelab or gaming setups, connect a managed 802.1Q switch to the LAN port. The router handles inter-VLAN routing if configured with VLAN subinterfaces.
ASUS Adaptive QoS and Traffic Analyzer operate at the device level, classifying traffic by MAC or IP. When using custom subnets, static DHCP reservations ensure gaming devices keep consistent IPs that QoS rules target reliably. Dynamic IPs can cause QoS priority rules to miss the device after a lease renewal.
Yes. Configure IPv6 under Advanced Settings > IPv6. The router supports DHCPv6-PD, SLAAC, 6in4 tunnels, and 6to4. Delegated IPv6 prefixes are distributed to LAN devices as /64 blocks.
Netgear Nighthawk RS700S Subnet Settings
The Netgear Nighthawk RS700S is a flagship Wi-Fi 7 router with a 2.5 Gbps WAN port and 19 Gbps aggregate wireless throughput. Its default LAN subnet is 192.168.1.0/24, the most common home router default. For homelab users who connect the RS700S to a managed switch or NAS, changing the subnet to 10.0.0.0/24 or similar private range distinguishes it from ISP modem networks at a glance, which is useful when managing multiple VLANs or running split-DNS for internal hostnames.
Run this check yourself in the Subnet Calculator.
Open in the tool →Specifications1
| Default LAN IP | 192.168.1.1 |
|---|---|
| Default subnet mask | 255.255.255.0 |
| CIDR notation | 192.168.1.0/24 |
| Default DHCP pool | 192.168.1.2 – 192.168.1.254 |
| Max DHCP leases | 253 (full /24 pool) |
| IPv6 support | Yes — DHCPv6, SLAAC, 6to4 |
| Wi-Fi standard | Wi-Fi 7 (802.11be), tri-band |
| Management interface | http://routerlogin.net or http://192.168.1.1 |
Shrinking the 192.168.1.0/24 pool to free static addresses
The RS700S defaults to 192.168.1.0/242, a /24 block providing 253 usable DHCP addresses. Most household networks never fill a /24, but the router's WAN 2.5G port and LAN 2.5G ports make it attractive for homelab setups where servers, NAS units, and workstations need separate VLANs for storage traffic isolation. Building on this, the standard DHCP pool 192.168.1.2 through 192.168.1.254 leaves .1 for the router and does not reserve a static range for servers, so adjusting the pool to 192.168.1.100 through 192.168.1.254 frees 192.168.1.2 through 192.168.1.99 for static server assignments without DHCP conflicts.
Planning a static versus dynamic split
Reserving the bottom of the subnet for static assignments is a common convention because it keeps infrastructure addresses clustered and easy to document. A NAS at 192.168.1.10, a Proxmox host at 192.168.1.20, and a TrueNAS instance at 192.168.1.30 all sit below the DHCP range and never collide with dynamic leases. This convention also simplifies firewall rules on the router, since you can write rules that reference the entire static range rather than individual addresses.
Netgear's own configuration guide labels these as the Starting IP Address and Ending IP Address fields under Advanced > Setup > LAN Setup, and both values must fall within the same subnet as the router itself. This constraint is why the static-versus-dynamic split has to happen inside the /24 rather than by carving out a separate subnet for infrastructure devices: the DHCP pool boundaries can only be moved within 192.168.1.2 through 192.168.1.254, not redirected to an entirely different address range.
Changing subnet settings on the RS700S
Open a browser and navigate to http://routerlogin.net or http://192.168.1.1. Log in with your admin credentials. Go to Advanced > Setup > LAN Setup. The IP Address field shows the router's current LAN IP and the Subnet Mask field shows 255.255.255.0. Change these to your desired values, for example 10.0.0.1 with 255.255.0.0 for a /16, and then scroll down to the DHCP pool section to update the start and end IPs to match the new subnet range. Click Apply and the router reboots the DHCP service so devices must renew their leases.
Locking devices to a fixed address with DHCP reservations
Static DHCP reservations are configured on the same LAN Setup page by binding a device's MAC address to a fixed IP. This is preferable to configuring a static IP on the device itself because the reservation stays consistent even if you replace the device's network card or reinstall its operating system, and it keeps all address management in one place on the router.
Management, storage and IoT VLANs behind a managed switch
The RS700S provides a guest wireless network that runs in an isolated segment, restricting guest clients from accessing the main LAN. For multi-VLAN homelab setups, the RS700S connects to a managed switch that tags traffic with IEEE 802.1Q VLAN IDs. Each VLAN maps to a subnet: management VLAN at 10.0.0.0/24, storage VLAN at 10.0.1.0/24, IoT VLAN at 10.0.2.0/24.
Deciding where inter-VLAN routing happens
The RS700S performs inter-VLAN routing if configured with VLAN subinterfaces, or a dedicated firewall handles routing if the RS700S is used only as a wireless access point in this topology. CapyToolkit's subnet calculator helps pre-plan CIDR allocations for each VLAN before configuring the managed switch, ensuring non-overlapping ranges and a clean per-VLAN DHCP setup. Deciding up front whether the RS700S or an upstream firewall routes between VLANs determines how you configure the trunk port on the managed switch.
Static IP planning for homelab servers and NAS devices
Homelab setups with the RS700S benefit from a clean split between dynamic and static address ranges. Reserving 192.168.1.2 through 192.168.1.99 for static assignments and 192.168.1.100 through 192.168.1.254 for DHCP prevents address conflicts when adding new servers. A NAS at 192.168.1.10, a Proxmox host at 192.168.1.20, and a TrueNAS instance at 192.168.1.30 keep infrastructure addresses clustered at the bottom of the subnet for easy documentation. Building on this, the RS700S DHCP pool configuration at Advanced > Setup > LAN Setup lets you set the start address to 192.168.1.100, automatically skipping the static range. Changing this pool boundary after initial setup requires only one configuration change rather than individual device reconfiguration.
IPv6 prefix delegation and LAN configuration on the RS700S
The RS700S supports DHCPv6-PD (Prefix Delegation) on the WAN side.3 When the ISP delegates a /56 or /60 prefix, the router assigns a /64 from that delegation to the LAN. Enabling IPv6 at Advanced > Advanced Setup > IPv6 assigns LAN hosts their addresses through SLAAC, DHCPv6, or both simultaneously. Building on this, the RS700S displays the current WAN IPv6 prefix and LAN IPv6 prefix in the same IPv6 settings page. If your ISP delegates a /56 (for example 2001:db8:abcd::/56), the router assigns 2001:db8:abcd:0001::/64 to the LAN, leaving 254 additional /64s available for VLANs.4 Without VLAN support on the RS700S LAN, the single /64 serves all devices, which is sufficient for most home deployments. CapyToolkit shows the /64 boundaries when you enter the delegated prefix, helping you plan multi-VLAN IPv6 if you add a managed switch.
Using the RS700S in AP mode behind a dedicated gateway
Switching the RS700S to AP mode (Advanced > Advanced Setup > Router/AP Mode > AP Mode) disables its NAT and DHCP server, turning the device into a pure wireless access point. Your upstream gateway : pfSense, OPNsense, or a UDM Pro : handles all routing, subnet assignment, and firewall rules. Building on this, AP mode is the correct deployment choice when you run a multi-VLAN setup: the upstream gateway assigns VLAN-backed subnets with 802.1Q trunking to a managed switch, and the RS700S provides Wi-Fi on whichever VLAN the switch port is configured for.
The routerlogin.net admin interface remains accessible at the static IP you assign in AP mode (typically a management VLAN address). All Wi-Fi settings, band steering, and mesh features continue to work; only routing functions are disabled. Before flipping the RS700S to AP mode, map each VLAN to a subnet on the Nighthawk RS700S so the upstream gateway inherits clean CIDR boundaries.5
- 1.
Netgear, "Nighthawk RS700S Support," netgear.com, accessed June 2026. https://www.netgear.com/support/product/rs700/
- 2.
Netgear, "How do I change the LAN TCP/IP settings on my Nighthawk router," kb.netgear.com, accessed June 2026. https://kb.netgear.com/24088/How-do-I-change-the-LAN-TCP-IP-settings-on-my-Nighthawk-router
- 3.
Netgear, "How do I specify the pool of IP addresses assigned by my Nighthawk router," kb.netgear.com, accessed June 2026. https://kb.netgear.com/24089/How-do-I-specify-the-pool-of-IP-addresses-assigned-by-my-Nighthawk-router
- 4.
O. Troan and R. Droms, "IPv6 Prefix Options for Dynamic Host Configuration Protocol (DHCP) version 6," RFC 3633, IETF, December 2003. https://www.rfc-editor.org/rfc/rfc3633.html
- 5.
V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632
192.168.1.1. The admin interface is at http://routerlogin.net or http://192.168.1.1. Default admin credentials are admin/password unless changed during setup.
Go to Advanced > Setup > LAN Setup in the admin UI. Edit the IP Address and Subnet Mask fields. Update the DHCP pool start and end to match the new subnet. Click Apply and allow the router to restart its DHCP service.
The RS700S supports guest network isolation natively. For full multi-VLAN configuration, connect it to a managed 802.1Q switch. CapyToolkit's subnet calculator helps you pre-plan the CIDR for each VLAN before configuring the switch. Check the RS700S firmware release notes for current VLAN tagging capabilities on LAN ports.
The default DHCP lease time is 1440 minutes (24 hours). Adjust this under Advanced > Setup > LAN Setup. Shorter leases suit high-turnover environments; longer leases reduce DHCP traffic on stable home networks.
Not natively in the standard firmware. The RS700S provides one DHCP server for its primary LAN subnet. To serve DHCP across multiple VLANs, add a DHCP relay or use pfSense/OPNsense as the DHCP server while the RS700S handles wireless access.
TP-Link Archer BE900 Subnet Settings
The TP-Link Archer BE900 is TP-Link's flagship Wi-Fi 7 router, operating on 2.4 GHz, 5 GHz, and 6 GHz bands simultaneously. Its default LAN subnet is 192.168.0.0/24, placing all connected devices in a single flat network of 254 usable addresses. For households with many IoT devices, smart home hubs, and work computers, reconfiguring the subnet into VLANs prevents IoT devices from reaching personal computers on the same switch, which is a common security improvement the BE900's admin UI supports through VLAN tagging.
Run this check yourself in the Subnet Calculator.
Open in the tool →Specifications1
| Default LAN IP | 192.168.0.1 |
|---|---|
| Default subnet mask | 255.255.255.0 |
| CIDR notation | 192.168.0.0/24 |
| Default DHCP pool | 192.168.0.100 – 192.168.0.249 |
| Max DHCP leases | 150 (default pool size) |
| IPv6 support | Yes — DHCPv6, SLAAC, 6rd, DS-Lite |
| Wi-Fi standard | Wi-Fi 7 (802.11be), quad-band |
| Management interface | http://192.168.0.1 or tplinkwifi.net |
A 150-lease pool inside a 254-address subnet
The BE900 ships with 192.168.0.0/24 as the LAN subnet.2 A /24 block holds 254 usable host addresses, which is enough for households with dozens of connected devices, but at 150 DHCP leases the default pool is more limiting than the subnet itself. Out of the box, the router hands out addresses from a narrow band in the middle of the range, leaving the lower and upper addresses available for static assignment.
Why the default DHCP pool is smaller than the subnet
Expanding the pool in the admin UI to cover the full /24 (192.168.0.2 through 192.168.0.254) gives all 253 addresses to DHCP. Yet 254 addresses in a flat network means every device can reach every other device directly, including IoT sensors, smart TVs, and work laptops. Consequently, users with mixed-trust devices benefit from splitting the /24 into VLANs backed by separate subnets, one for each trust level.
Changing subnet settings on the BE900
Open a browser and navigate to 192.168.0.1 or tplinkwifi.net. Log in with your admin credentials. Go to Advanced > Network > DHCP Server. The LAN IP section shows the current gateway IP (192.168.0.1) and subnet mask (255.255.255.0). To change the subnet, modify the IP address and subnet mask fields (for example, changing to 10.0.0.1 with mask 255.255.0.0 moves the router to a /16). Click Save after each change. The router reboots the DHCP service and devices must renew leases. Building on this, under Advanced > Network > LAN you can configure VLAN IDs for guest networks, which create separate subnets behind the same router.
Guest network and 802.1Q VLANs with the BE900 as router
The BE900 supports a guest Wi-Fi network that runs in an isolated segment, preventing guest clients from reaching the main LAN. Enabling the guest network under Wireless > Guest Network creates a virtual interface with its own DHCP pool. For more advanced VLAN segmentation, such as a separate IoT VLAN, home office VLAN, and gaming VLAN, connect the BE900's LAN port to a managed switch that supports IEEE 802.1Q VLAN tagging. Configure the switch ports with the appropriate VLAN IDs and set the BE900 as the inter-VLAN router.
Planning VLAN subnets with the calculator
Consequently, each VLAN gets its own subnet allocation planned with the subnet calculator, and the firewall rules between VLANs prevent cross-segment access for untrusted device categories. Planning the CIDRs before configuring the switch ensures that the IoT VLAN at 192.168.1.0/24 cannot route to the home office VLAN at 192.168.2.0/24 without an explicit firewall rule, which is the core benefit of subnet-based isolation.
Beyond the switch-based VLAN approach, the BE900's built-in Private IoT Network feature offers a lighter-weight alternative: it creates a separate wireless network specifically for IoT devices with HomeShield and WPA3 protections layered on top, without requiring an external managed switch. The router also exposes four independent guest networks, one per radio band (6 GHz, the two 5 GHz bands, and 2.4 GHz), each of which can be assigned its own subnet for band-specific isolation.
IPv6 prefix delegation on the BE900
The BE900 supports DHCPv6 Prefix Delegation, which requests a prefix from your ISP and distributes /64 blocks to LAN segments automatically. When your ISP delegates a /56, the BE900 can assign one /64 to the main LAN and additional /64s to guest or IoT VLANs. This gives every segment its own globally routable IPv6 range without manual configuration.
3
How prefix delegation assigns a /64 to each VLAN
For the main LAN, the BE900 assigns a /64 from the delegated prefix using SLAAC, allowing every device to self-configure a global IPv6 address.4 Building on this, the guest network receives a separate /64, which isolates guest devices at the IPv6 level even if the IPv4 firewall rules are misconfigured. Verifying the delegated prefix length in the BE900's admin UI (under Advanced > IPv6) confirms whether your ISP provides a /56, /48, or only a single /64. If the ISP delegates only a /64, you cannot assign unique /64s to multiple VLANs; in that case, use NAT66 or ULA (fc00::/7) for internal segments.
OneMesh and subnet considerations for TP-Link extenders
TP-Link OneMesh lets you add compatible TP-Link range extenders to the BE900's network, creating a mesh-like experience without replacing the router. OneMesh extenders connect to the BE900 over Wi-Fi and extend the same SSID, meaning all devices (whether connected to the router or an extender) share the same subnet and broadcast domain. This simplifies client roaming but means the extender does not create a separate segment.
For households that need both extended coverage and subnet isolation, connect a managed switch to the BE900's LAN port and run Ethernet to access points that support VLAN tagging. Building on this, the access points assign VLAN IDs per SSID (main SSID on VLAN 10, IoT SSID on VLAN 20), and the managed switch enforces inter-VLAN routing through the BE900. The subnet calculator plans the CIDR for each VLAN before configuring the access points, ensuring the main LAN at 192.168.0.0/24 and the IoT VLAN at 192.168.1.0/24 do not overlap.5 Consequently, the subnet calculator helps you separate IoT devices from your main LAN, giving you both extended Wi-Fi coverage and proper subnet segmentation that OneMesh alone cannot provide.
- 1.
TP-Link, "Archer BE900 User Guide," tp-link.com, 2023. https://static.tp-link.com/upload/manual/2023/202306/20230626/1910013368_Archer%20BE900_UG_REV1.0.0.pdf
- 2.
TP-Link, "Archer BE900," tp-link.com, accessed June 2026. https://www.tp-link.com/us/home-networking/wifi-router/archer-be900/
- 3.
TechSpot, "TP-Link Archer BE900," techspot.com, accessed June 2026. https://www.techspot.com/review/2601-tp-link-archer-be900/
- 4.
O. Troan and R. Droms, "IPv6 Prefix Options for Dynamic Host Configuration Protocol (DHCP) version 6," RFC 3633, IETF, December 2003. https://www.rfc-editor.org/rfc/rfc3633.html
- 5.
V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632
192.168.0.1. The admin interface is accessible at http://192.168.0.1 or tplinkwifi.net from any device connected to the LAN.
Go to Advanced > Network > DHCP Server in the admin UI at 192.168.0.1. Modify the subnet mask field to the new mask (for example 255.255.0.0 for a /16) and save. Connected devices need to renew their DHCP leases after the change.
The BE900 supports a guest network as a built-in isolated segment. For multiple VLANs with separate subnets, connect a managed 802.1Q-capable switch to the LAN port and configure VLAN tagging on the switch.
The default DHCP pool covers 150 addresses (192.168.0.100 to 192.168.0.249). Expanding the pool to 192.168.0.2 through 192.168.0.254 supports up to 253 DHCP-assigned devices on the /24 subnet, and CapyToolkit's calculator confirms the full usable range for any prefix so you can verify that an expanded pool does not collide with statically assigned addresses.
Yes. The BE900 supports DHCPv6 and SLAAC for IPv6 address assignment. Configure the WAN IPv6 type under Advanced > IPv6. The router assigns /64 prefixes to LAN segments from the ISP-delegated prefix.
TP-Link Deco BE63 Subnet Settings
The TP-Link Deco BE63 is a Wi-Fi 7 mesh system rated among the best mesh routers in 2026. Managed through the Deco app rather than a browser-based admin UI, its subnet settings follow the 192.168.68.0/24 default found across the Deco lineup. Mesh systems extend a single subnet across multiple access points, and all units in a Deco network share one DHCP server and one broadcast domain, meaning all devices regardless of which access point they connect through share the same /24 subnet.
Run this check yourself in the Subnet Calculator.
Open in the tool →Specifications1
| Default LAN IP | 192.168.68.1 |
|---|---|
| Default subnet mask | 255.255.255.0 |
| CIDR notation | 192.168.68.0/24 |
| Default DHCP pool | 192.168.68.2 – 192.168.68.254 |
| Max DHCP leases | 253 (full /24 pool) |
| IPv6 support | Yes — DHCPv6 and SLAAC |
| Wi-Fi standard | Wi-Fi 7 (802.11be), tri-band |
| Management interface | Deco app (iOS/Android); no browser UI |
One flat 192.168.68.0/24 network across every node
The Deco BE63 uses 192.168.68.0/24 as its default LAN subnet, with the main unit at 192.168.68.1,2 which keeps it clear of the 192.168.0.x and 192.168.1.x ranges used by most ISP modem-routers. With the default DHCP pool spanning 192.168.68.2 to 192.168.68.254, the system assigns up to 253 addresses dynamically. In a typical home, 10 to 60 devices connect across all Deco nodes, leaving most of the /24 unused. Yet the flat network means a compromised smart TV on one node can still communicate with a work laptop connected to another, which is exactly why the Deco app includes an IoT Network feature that creates a second subnet for untrusted devices.
Why 192.168.68.0/24 avoids ISP conflicts
TP-Link picked 192.168.68.1 as the default gateway because the 192.168.0.x and 192.168.1.x ranges are overwhelmingly common on ISP-supplied modem-routers, and picking a rare subnet prevents the silent failures that occur when two routers on the same network hand out addresses from overlapping ranges. Placing the Deco on 192.168.68.0/24 means you can plug an ISP gateway into the Deco WAN port without an IP overlap breaking DHCP or DNS forwarding.
This matters more than most users realize. An overlapping range causes devices to receive addresses from the wrong gateway and lose internet access without any obvious error message, and tracking down that misconfiguration across a mesh of several nodes takes far longer than picking a clean subnet up front. CapyToolkit's subnet calculator lets you verify that your chosen subnet does not overlap with the ISP gateway range before you connect the Deco.
Changing subnet settings via the Deco app
Open the Deco app, tap the More menu (bottom right), then Advanced > DHCP Server. Here you can view and edit the router IP and subnet mask. Change the IP address and mask to move the entire mesh to a different subnet, for example 10.0.1.1 with 255.255.255.0 for a /24 at 10.0.1.x, and keep in mind that every Deco node in the mesh adopts the new subnet at once because there is only one DHCP server running on the main unit. Tap Save and the Deco reboots its network stack so all connected devices must renew DHCP leases.
Editing the DHCP pool boundaries
Building on this, the DHCP reservation feature lets you assign specific IPs to devices by MAC address, which is useful for servers and smart home hubs that need consistent addresses for firewall rules and port forwards. You can also shrink the pool to reserve a block of addresses for static assignments, preventing the router from handing out an IP that you intended to reserve for a server.
Multi-subnet and IoT isolation patterns
The Deco app's IoT Network feature (More > IoT Network) creates a dedicated Wi-Fi network for smart home devices, which TP-Link says improves both connection success and security.3 Before you count on it as isolation, check from a device on the IoT network whether it can still reach devices on the primary SSID. For more granular VLAN segmentation beyond what the Deco app offers, connect a managed switch to the BE63's LAN port with 802.1Q VLAN tagging configured.
Planning VLAN subnets before adding a switch
The Deco functions as the WAN edge while the managed switch enforces inter-VLAN routing rules between the segments you define. Planning each VLAN's subnet CIDR with the subnet calculator before purchasing the managed switch ensures you allocate correctly sized blocks for each trust zone without overlap. A common split is a /24 for primary devices, a /24 for IoT, and a /26 for guest traffic, each with its own DHCP scope.
Mesh topology and its impact on subnet design
In a Deco mesh, every node extends the same Layer 2 broadcast domain. Unlike a traditional multi-AP setup where each access point can connect to a different VLAN through a trunk port, all Deco nodes share one subnet managed by the main unit's DHCP server. Building on this, adding more Deco nodes increases Wi-Fi coverage without changing the subnet: a three-node BE63 mesh still serves one 192.168.68.0/24 subnet. The mesh backhaul (wired or wireless) carries traffic between nodes at Layer 2, so a device connected to the farthest node can communicate with a device connected to the main node without routing.4 This simplicity is a strength for home users but a limitation for anyone who needs per-segment isolation without adding a managed switch.
DHCP management and device naming in the Deco ecosystem
The Deco app displays every connected device with its hostname, IP address, and connection node. Renaming devices in the app (for example, "Living Room TV" instead of "android-abc123") makes it easier to identify which device holds a given IP when troubleshooting. Building on this, DHCP reservations under each device's settings let you pin a specific MAC address to a fixed IP. A home server at 192.168.68.50 that hosts a Plex media library or a Home Assistant instance benefits from a reservation: the address survives mesh node reboots and firmware updates. The Deco app also shows per-device bandwidth usage, which helps identify which device is consuming bandwidth during slowdowns : information that correlates with the IP address in your subnet plan.
Using the Deco BE63 with a managed switch for VLAN segmentation
Connecting a managed switch to the Deco BE63's LAN port opens up VLAN segmentation that the Deco app cannot provide on its own. Configure the switch port connected to the Deco as a trunk carrying VLAN 10 (primary LAN) and VLAN 20 (IoT). The Deco handles VLAN 10 devices normally, while VLAN 20 devices route through the managed switch's inter-VLAN routing rules.
Building on this, the managed switch's DHCP server (or a separate DHCP relay to a router) assigns addresses from a different subnet to VLAN 20 devices: 192.168.69.0/24 for IoT, while the Deco continues serving 192.168.68.0/24 for the primary LAN. A firewall rule on the managed switch blocking VLAN 20 to VLAN 10 traffic isolates IoT devices at the switch level. The subnet calculator keeps Deco VLANs on separate subnets before you configure the switch, ensuring non-overlapping allocations that the Deco and managed switch can coexist without routing conflicts.5
- 1.
TP-Link, "Deco BE63 User Guide," tp-link.com, 2025. https://static.tp-link.com/upload/manual/2025/202501/20250102/1910013639_Deco%20BE63(US)2.6_User%20Guide_REV2.6.0%20(1).pdf
- 2.
TP-Link, "How to Log In to Your TP-Link Deco Web Management Page," tp-link.com, accessed October 2026. https://www.tp-link.com/us/support/faq/2641/
- 3.
TP-Link, "Deco Smart Home Setup: Settings to Prevent and Fix Connection Issues," tp-link.com, accessed October 2026. https://www.tp-link.com/us/support/faq/4420/
- 4.
R. Braden, "Requirements for Internet Hosts' Communication Layers," RFC 1122, IETF, September 1989. https://www.rfc-editor.org/rfc/rfc1122.html
- 5.
V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632
192.168.68.1. The Deco uses this address to avoid conflicting with common ISP gateway addresses like 192.168.0.1 and 192.168.1.1. Manage the network through the Deco app rather than a browser interface.
Open the Deco app > More > Advanced > DHCP Server. Edit the router IP and subnet mask. After saving, the mesh reboots the DHCP service and all devices must renew leases, though some may require manual reconnection before they pick up the new address range.
No. The Deco BE63 is managed exclusively through the TP-Link Deco app (iOS or Android). There is no browser-based admin page, so all settings including subnet configuration require the app. CapyToolkit's subnet calculator works independently of the Deco app, so you can plan the new CIDR on a laptop and then apply it in the app when ready.
Yes. The Deco app includes an IoT Network option that creates a separate SSID with its own subnet. IoT devices on this network can access the internet but are isolated from devices on the main LAN.
Yes. In a Deco mesh system, all nodes are part of one unified network managed by a single DHCP server on the main node. Every device connected to any Deco node is on the same subnet, because the mesh extends Layer 2 coverage rather than creating separate subnets for each node.
eero Pro 7 Subnet Settings
The Amazon eero Pro 7 is a Wi-Fi 7 mesh router designed for zero-configuration setup. Its default subnet is 192.168.4.0/22. Unusually, eero uses a /22 rather than the /24 common on competing routers, giving the system 1,022 usable addresses across its DHCP pool. This larger subnet accommodates smart homes with many devices without pool exhaustion.
Run this check yourself in the Subnet Calculator.
Open in the tool →Specifications1
| Default LAN IP | 192.168.4.1 |
|---|---|
| Default subnet mask | 255.255.252.0 |
| CIDR notation | 192.168.4.0/22 |
| Default DHCP pool | 192.168.4.2 – 192.168.7.254 |
| Max DHCP leases | 1022 (full /22 pool) |
| IPv6 support | Yes — DHCPv6 and SLAAC via eero app |
| Wi-Fi standard | Wi-Fi 7 (802.11be), tri-band |
| Management interface | eero app (iOS/Android only); no browser UI |
What a /22 flat network allows and risks
eero's /22 default (192.168.4.0/22, as eero owners report it)2 spans four /24 blocks: 192.168.4.x through 192.168.7.x. This provides 1,022 usable addresses, far more than the 254 of a standard /24. The larger pool prevents DHCP exhaustion in dense smart-home environments where dozens of IoT sensors, speakers, and appliances each claim a lease. Yet a /22 flat network means every connected device can reach every other. A compromised smart device has access to all 1,021 other addresses in the pool. Building on this, eero's Network+ feature (paid subscription) adds profile-based device segmentation, but true VLAN isolation requires a managed switch behind the eero.
When a /22 flat network makes sense
A flat /22 suits households with a single trusted zone where every device can freely communicate with every other. Smart-home ecosystems benefit from this openness during initial setup because mDNS and discovery protocols reach across the entire subnet without routing configuration. The tradeoff is that a compromised device can probe all 1,021 other leases, so /22 deployments work best when every connected device is trusted and firmware is kept up to date.
Changing subnet settings via the eero app
Open the eero app, tap Settings (gear icon) > Advanced Settings > DHCP & NAT. The current subnet and gateway IP are displayed. To change the subnet, tap the IP address and enter a new gateway IP and subnet mask. For example, setting 10.0.0.1 with 255.255.0.0 moves the network to 10.0.0.0/16 with 65,534 available addresses. Tap Save; the eero network restarts its DHCP service and clients must renew leases. Furthermore, DHCP reservations are available under the individual device settings. Tap a device in the app, then Reserve IP to bind a static address to that device's MAC so the device keeps the same lease even after it disconnects from the mesh for several days.
Choosing a non-default subnet on the eero Pro 7
Changing the subnet mask is uncommon on eero but useful when you want fewer addresses and a smaller broadcast domain for tighter device isolation. For example, switching the mask to 255.255.255.0 on a 192.168.4.0 configuration gives you a /24 with 254 usable addresses and a smaller flood scope. CapyToolkit's subnet calculator shows you the available address count for any gateway-and-mask combination before you apply changes in the eero app.
The same DHCP & NAT screen also exposes a NAT type toggle with three modes: automatic (eero manages NAT itself), custom (you define the NAT behavior manually), and bridged (NAT is disabled entirely so an upstream router handles it). Switching to custom NAT is the setting to use alongside a non-default subnet, since automatic mode assumes eero's own addressing scheme and can conflict with a manually chosen gateway and mask.
Guest network and trust-zone VLANs behind the eero
eero supports a guest network through the app. This creates a second SSID with its own isolated segment. Guest devices cannot reach the primary network but can access the internet. For full VLAN segmentation (IoT isolation, homelab servers, cameras), connect a managed switch to the eero's LAN port with IEEE 802.1Q VLAN tagging. Configure the switch with VLAN IDs matching intended trust zones and set the eero as the upstream gateway.
Planning CIDR blocks for each trust zone
Each VLAN receives its own CIDR block planned with the subnet calculator. IoT zones work well as /24 networks with 254 usable addresses, guest zones as /25 networks with 126 usable addresses, and management zones as /26 networks that limit exposure to 62 devices. Consequently, IoT sensors sit in a /24 that the switch blocks from reaching the personal device VLAN, while the main eero still routes internet-bound traffic for all VLANs.
Why eero chose /22 instead of /24 and what it means for you
Most home routers default to a /24 subnet (254 usable addresses).3 eero quadrupled that to a /22 (1,022 usable addresses) because modern smart homes routinely have 30 to 80 connected devices: phones, laptops, tablets, smart speakers, thermostats, cameras, smart plugs, TVs, and streaming sticks. A /24 exhausts in large households or multi-unit dwellings where neighbors' networks contribute devices that briefly roam onto the mesh. Building on this, the tradeoff is a larger broadcast domain: every ARP request from any device reaches all 1,021 other potential addresses. In practice, this rarely causes performance issues on modern Wi-Fi hardware, but it does mean compromised devices can scan a wider address space. If your household has fewer than 50 devices and you want smaller broadcast domains, switching to a /24 in the eero app reduces the address pool without affecting functionality.
Port forwarding and DHCP reservations on the eero Pro 7
The eero app's Reserve IP feature (under device settings) binds a MAC address to a fixed IP within the DHCP pool. This is critical for devices that need consistent addresses: a home server running Plex, a NAS that network shares reference, or a gaming console that needs inbound ports open. After reserving the address, navigate to Settings > Advanced Settings > Reservations & Port Forwarding to map external ports to that reserved IP. Building on this, eero+ (the paid subscription) adds advanced threat scanning and ad blocking at the DNS level, but port forwarding and DHCP reservation work without a subscription. The eero Pro 7's NAT table supports up to 20 simultaneous port forwarding rules; for server hosting needs beyond that scale, consider a dedicated gateway that gives you full iptables or pfSense control.4
Bridge mode and using the eero behind a dedicated router
Placing the eero Pro 7 in bridge mode (Settings > Advanced Settings > DHCP & NAT > Bridge) disables its routing function and turns the mesh into a pure wireless access point. Your upstream router, whether a pfSense box, a UDM Pro, or an OpenWrt gateway, handles all subnetting, DHCP, firewall rules, and inter-VLAN routing without any configuration changes on the eero itself.
Building on this, bridge mode is the correct choice when you need proper VLAN segmentation, as eero's native firmware does not support VLAN tagging on its LAN ports. In bridge mode, eero's built-in security features (threat scanning, content filtering) still operate at the DNS level, but firewall rules must live on the upstream gateway where they can inspect traffic across all VLANs.
The eero app continues to manage Wi-Fi settings, firmware updates, and device profiles even when routing is disabled, which means you can adjust channel widths, pause client access, and push firmware to mesh nodes without touching the upstream routing stack. CapyToolkit's DHCP pool calculator helps determine the correct addresses to assign to eero nodes as static leases under the upstream router's subnet so each mesh unit keeps a consistent management IP even as wireless clients roam across different access points. Before you flip the eero to bridge mode, reserve a fixed IP for every eero Pro 7 node under the upstream router's subnet so each unit keeps that address as clients roam.5
- 1.
eero, "Advanced Networking Settings," eero.com, accessed June 2026. https://support.eero.com/hc/en-us/articles/360036385311-What-are-the-Advanced-networking-settings
- 2.
Roon Community, "Several problems with Nucleus+ after recent router upgrade to Eero," community.roonlabs.com, accessed October 2026. https://community.roonlabs.com/t/several-problems-with-nucleus-after-recent-router-upgrade-to-eero/299247
- 3.
Tom's Hardware, "Amazon eero 7 Pro Review," tomshardware.com, accessed June 2026. https://www.tomshardware.com/networking/routers/amazon-eero-7-pro-wi-fi-7-mesh-router-review
- 4.
V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632
- 5.
R. Baker, "Address Allocation for Private Internets," RFC 1918, IETF, February 1996. https://www.rfc-editor.org/rfc/rfc1918.html
192.168.4.0/22, which provides 1,022 usable DHCP addresses across the range 192.168.4.2 to 192.168.7.254. eero uses a /22 instead of the more common /24 to accommodate large smart-home device counts.
Open the eero app > Settings > Advanced Settings > DHCP & NAT. Edit the gateway IP and subnet mask. After saving, the eero restarts its network stack and devices must renew DHCP leases. The eero app is required; there is no browser-based admin page.
No. eero devices are managed exclusively through the eero iOS or Android app. All settings including subnet, DHCP, and port forwarding are configured in the app. No browser admin interface is available.
The eero app provides a guest network for basic isolation. eero+ (paid) offers profile-based access controls per device. For true subnet isolation, add a managed switch behind the eero with VLAN tagging. CapyToolkit's subnet calculator helps you pre-plan each VLAN's CIDR before assigning them to the eero's trust zones.
A /22 provides 1,022 DHCP addresses versus 254 for a /24. eero targets customers with many smart-home devices, including speakers, sensors, cameras, and appliances, so the larger pool prevents DHCP exhaustion without requiring users to change settings.
Ubiquiti UDM-Pro 10G Cloud Gateway Subnet Settings
The Ubiquiti UDM-Pro 10G Cloud Gateway is the leading prosumer and homelab networking gateway in 2026. Unlike consumer routers, the UDM Pro is designed from the start for multi-VLAN deployments. Creating separate networks with different subnets is a first-class feature in the UniFi OS console. Each network gets its own CIDR block, DHCP range, firewall zone, and optional VPN policy.
Run this check yourself in the Subnet Calculator.
Open in the tool →Specifications1
| Default LAN IP | 192.168.1.1 |
|---|---|
| Default subnet mask | 255.255.255.0 |
| CIDR notation | 192.168.1.0/24 |
| Default DHCP pool | 192.168.1.6 – 192.168.1.254 |
| Max DHCP leases | 249 (default pool) |
| IPv6 support | Yes — DHCPv6-PD, SLAAC, static prefix |
| Wi-Fi standard | Requires separate UniFi APs (not built-in) |
| Management interface | https://unifi.ui.com or local https://192.168.1.1 |
The default LAN as one of many networks
The UDM Pro ships with a 192.168.1.0/24 LAN,2 placing the router at .1 and allocating DHCP from .6 to .254. Five addresses (.1 through .5) are reserved for static assignments to the gateway and management services. In contrast to consumer routers, the UDM Pro treats the default network as just one of many possible networks. Adding a second network takes three clicks in the UniFi console and immediately provisions a new DHCP server and firewall zone. Building on this, the default network typically serves management devices (switches, APs) while additional networks serve user segments, IoT devices, and cameras in well-designed UniFi deployments.
Adding networks in UniFi OS
Log into the UniFi console at https://unifi.ui.com or https://192.168.1.1. Navigate to Settings > Networks > Create New Network. Enter a name, choose the purpose (Corporate, Guest, VLAN Only), and set the CIDR subnet. For example, 10.0.10.0/24 is a solid choice for an IoT VLAN. The VLAN ID field assigns an 802.1Q tag (e.g., VLAN 10). Enable DHCP and set the pool range. UniFi OS automatically creates inter-VLAN routing rules and firewall zones. Consequently, restricting IoT devices from reaching the main LAN requires one firewall rule: Block IoT Zone to LAN Zone in Settings > Firewall Policies. The UDM Pro enforces these rules at hardware speed for throughput above 1 Gbps.
Seven VLANs carved from one 10.0.0.0/20 block
UniFi lets you create a separate virtual network for each VLAN, and a UDM Pro homelab might use seven of them: Management (10.0.0.0/24), Trusted LAN (10.0.1.0/24), IoT (10.0.2.0/24), Guest (10.0.3.0/24), Cameras (10.0.4.0/24), Servers (10.0.5.0/24), VPN clients (10.0.6.0/24).3 Planning these from a parent /20 block (10.0.0.0/20) keeps all subnets within one summarizable prefix that simplifies firewall summarization and route tables across the UDM Pro routing engine. Building on this, UniFi OS supports site-to-site VPN between UDM Pro units and requires that each site publish a unique non-overlapping prefix so tunnel traffic routes without ambiguity during failover or mesh reconvergence. CapyToolkit's subnet calculator verifies each CIDR allocation before you commit values to the UniFi console and prevents overlapping ranges from breaking pooled address plans.
Allocating CIDR blocks across trust zones
When you segment the available address block into flat /24 networks, you can leave headroom for future expansion by reserving CIDR prefixes on tier boundaries. The UDM Pro itself supports route summarization across six to eight contiguous networks at once, which means that a single advertising entry for 10.0.0.0/21 covers your IoT, Guest, Cameras, and Servers VLANs in one route table line rather than four individual entries that complicate leaks during topology changes.4 This summarization behavior is essential to keep the UniFi OS routing engine from bloating dynamic rules across multiple SD-WAN tunnels during multi-site failover events. CapyToolkit's subnet calculator enumerates each CIDR prefix in the recommended order so the entire plan fits inside one summarizable block before you enter the first CIDR value into the console.
DHCP configuration per VLAN on the UDM Pro
Each network on the UDM Pro runs its own DHCP server with an independently configurable pool. After creating a VLAN network at 10.0.10.0/24, the DHCP pool defaults to the full subnet range. Narrowing the pool (for example, 10.0.10.100 through 10.0.10.200) reserves addresses below .100 for static assignments to servers, printers, and access points. Building on this, DHCP reservations under Settings > Networks > [Network Name] > DHCP Name Server let you bind specific MAC addresses to fixed IPs within the pool. A UniFi access point that always receives 10.0.10.2 retains that address even after firmware updates or replacement hardware; simply update the MAC address in the reservation to match the new device.
Firewall rule design for multi-VLAN deployments
UniFi OS creates automatic firewall zones for each network: default, guest, VPN, and any custom VLAN networks you add. Inter-VLAN routing is enabled by default, which means devices on any network can reach devices on any other network unless you block it. A single firewall rule blocking IoT Zone to LAN Zone at Settings > Firewall Policies restricts IoT devices to internet-only access while allowing LAN devices to initiate connections to IoT endpoints for management. Building on this, placing blocking rules above allowing rules in the policy list matters: UniFi OS processes rules top-to-bottom, and the first matching rule wins. Adding an allow rule for a specific port above a blanket block gives granular exceptions without opening the entire zone.
DNS configuration across VLANs
The UDM Pro's built-in DNS forwarder serves all VLANs by default. Conditional DNS forwarding under Settings > Networks > [Network] > DHCP Name Server lets you specify which DNS server handles each VLAN. Directing IoT VLAN DNS queries to a Pi-hole or AdGuard instance at 10.0.2.10, while keeping the primary LAN on Cloudflare's 1.1.1.1, gives you per-zone DNS filtering without separate physical hardware. Clients within each VLAN inherit the DNS server automatically through DHCP option 6.
VPN integration with VLAN-backed subnets
The UDM Pro supports L2TP, OpenVPN (via Teleport), and WireGuard (since UniFi OS 3.x). Remote access VPN clients receive an IP from a dedicated VPN subnet configured under Settings > Teleport & VPN. Building on this, adding a firewall rule that permits VPN Zone traffic to specific VLAN subnets (for example, allowing VPN clients to reach 10.0.5.0/24 for the Servers VLAN but not 10.0.2.0/24 for the IoT VLAN) provides secure remote access to management interfaces without exposing the entire network. Site-to-site WireGuard tunnels between two UDM Pro units require non-overlapping CIDR allocations at each site; planning these from separate /20 blocks (10.0.0.0/20 for site A, 10.16.0.0/20 for site B) ensures no routing conflicts when the tunnel comes up. split a /20 across VPN sites on the Dream Machine Pro so each tunnel gets a unique prefix before the link comes up.5
Monitoring traffic between VLANs
UniFi OS traffic identification classifies packets by application type and displays per-client statistics in the UDM Pro dashboard. Under Insights > Traffic, you can filter by VLAN to see bandwidth consumption per zone. Setting traffic rules with bandwidth profiles (for example, limiting the Guest VLAN to 50 Mbps aggregate) prevents one segment from saturating the uplink. CapyToolkit's subnet calculator helps plan the CIDR allocations that feed into this entire workflow: each VLAN's subnet size determines the DHCP pool, which determines the address range your firewall rules target.
This traffic identification runs through the UDM Pro's Deep Packet Inspection engine, which the official tech specs rate at 3.5 Gbps of combined IDS/IPS throughput. Because that inspection capacity is shared across every VLAN, a Guest network saturating its bandwidth cap still leaves headroom for the DPI engine to keep classifying traffic on the Servers and Management VLANs without dropping visibility into either segment.
- 1.
Ubiquiti, "UDM-Pro Quick Start Guide," ui.com, accessed June 2026. https://dl-origin.ubnt.com/qsg/UDM-Pro/UDM-Pro_EN.html
- 2.
Ubiquiti, "UniFi Dream Machine Pro Tech Specs," ui.com, accessed June 2026. https://techspecs.ui.com/unifi/cloud-gateways/udm-pro
- 3.
Ubiquiti, "Creating Virtual Networks (VLANs)," help.ui.com, accessed October 2026. https://help.ui.com/hc/en-us/articles/9761080275607-Creating-Virtual-Networks-VLANs
- 4.
V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632
- 5.
R. Baker, "Address Allocation for Private Internets," RFC 1918, IETF, February 1996. https://www.rfc-editor.org/rfc/rfc1918.html
Go to Settings > Networks > Create New Network in UniFi OS. Set the subnet CIDR, VLAN ID, enable DHCP, and configure the pool range. UniFi automatically creates firewall zones for the new network and enables inter-VLAN routing.
192.168.1.1 on the default LAN. For each additional network you create, the gateway is the first usable address in that subnet. For a 10.0.10.0/24 network, UniFi OS sets the gateway automatically to 10.0.10.1.
Yes. Create the IoT network on a separate VLAN. Then in Settings > Firewall Policies, add a rule blocking traffic from the IoT zone to the LAN zone. UniFi OS applies this rule in the firewall engine so IoT devices can still reach the internet but not the main network. CapyToolkit's subnet calculator helps you pre-allocate the CIDR for the IoT zone and the LAN zone before you create the corresponding firewall rules.
Yes. Configure IPv6 PD under Settings > Internet > IPv6 Connection. The UDM Pro requests a prefix from your ISP and distributes /64 blocks to each network automatically.
UniFi OS supports up to 4094 VLANs (the 802.1Q maximum). Practical deployments rarely exceed 20 active networks. Each network runs its own DHCP server process, and the UDM Pro handles 15 to 20 active DHCP scopes without performance issues.