Change the LAN Subnet and DHCP Range on Your Router

Default LAN subnets, DHCP pools and the exact menus to change them on the ASUS ROG Rapture GT-BE98 Pro, Netgear Nighthawk RS700S, TP-Link Archer BE900 and Deco BE63, eero Pro 7 and Ubiquiti UDM-Pro.

Change the LAN Subnet and DHCP Range on Your Router

Most people change a router's LAN subnet for one of three reasons: it clashes with the ISP modem in front of it, a VPN or second site uses the same range, or the network needs room to split into VLANs. The change itself takes a minute. What takes planning is everything that depends on the old addresses, because DHCP reservations, port forwarding rules and any device with a static IP all point at the old range and stop working once the router moves.

Router makers do not agree on defaults, which is the first thing to check. ASUS ships 192.168.50.0/24, TP-Link's Archer routers ship 192.168.0.0/24 and its Deco mesh ships 192.168.68.0/24, Netgear and the Ubiquiti UDM-Pro ship 192.168.1.0/24, and eero uses a wider 192.168.4.0/22 with 1,022 usable addresses. Each section gives that router's default subnet and DHCP pool, the menu path to change it, its guest, IoT and VLAN options, and what to update afterwards. Before you save a new range, run it through the subnet calculator to confirm the gateway address, usable host range and broadcast address.

Default LAN subnets on these routers

  • 192.168.50.0/24
  • 192.168.1.0/24
  • 192.168.0.0/24
  • 192.168.68.0/24
  • 192.168.4.0/22
  • 192.168.1.0/24

Enter the new range in the calculator before you save it on the router, and check that it does not overlap your modem, VPN or other sites.

Opens the Subnet Calculator with this page's reference values shown at the top of the tool.

Open in the tool →

ASUS ROG Rapture GT-BE98 Pro Subnet Settings

The ASUS ROG Rapture GT-BE98 Pro is ASUS's flagship Wi-Fi 7 gaming router, offering 24 Gbps aggregate throughput across 2.4 GHz, 5 GHz low, 5 GHz high, and 6 GHz bands. Its default LAN subnet is 192.168.50.0/24. ASUS uses .50 to reduce conflicts with ISP modem-routers that default to 192.168.0.x or 192.168.1.x. For gamers who connect consoles and gaming PCs alongside streaming devices and smart-home sensors, subnet segmentation reduces inter-device interference and allows QoS rules to target entire subnets rather than individual IPs.

Run this check yourself in the Subnet Calculator.

Open in the tool →

Specifications1

Default LAN IP192.168.50.1
Default subnet mask255.255.255.0
CIDR notation192.168.50.0/24
Default DHCP pool192.168.50.2 – 192.168.50.254
Max DHCP leases253 (full /24 pool)
IPv6 supportYes — DHCPv6, SLAAC, 6in4, 6to4
Wi-Fi standardWi-Fi 7 (802.11be), quad-band
Management interfacehttp://router.asus.com or http://192.168.50.1

Why ASUS ships 192.168.50.0/24 with no static range

The ROG Rapture GT-BE98 Pro defaults to 192.168.50.0/24,2 placing 253 DHCP addresses in a flat network. ASUS chose the .50.x range to minimize conflicts with ISP-provided gateways at .0.1 and .1.1. The full DHCP pool covers .2 through .254, leaving no reserved static range by default. For gaming households with consoles needing consistent IPs for port forwarding, configuring DHCP reservations under LAN > DHCP Server > Manually Assigned IP is essential. Building on this, the GT-BE98 Pro's adaptive QoS feature classifies traffic by device, which works more reliably when gaming devices use static assignments rather than dynamic leases that could change after a router restart.

Changing subnet settings on the GT-BE98 Pro

Navigate to http://192.168.50.1 or http://router.asus.com and log in. Go to LAN > LAN IP. The LAN IP address and Subnet Mask fields control the subnet. Change the IP to 10.0.0.1 and the mask to 255.255.255.0 for a /24 at 10.0.0.x, or 255.255.0.0 for a /16. Click Apply. The DHCP Server section under LAN > DHCP Server automatically updates its pool boundaries and verify the pool start and end are within the new subnet range. Building on this, the router reboots network services and connected devices must renew leases. Static DHCP bindings are also under LAN > DHCP Server as the Manually Assigned IP table.

Choosing a subnet mask for gaming households

For most gaming households, the default /24 subnet mask (255.255.255.0) provides 253 usable addresses, which suits a typical mix of consoles, PCs, streaming devices, and smart-home sensors without requiring VLAN segmentation. If you plan to isolate IoT devices or run a guest network with separate addressing, switching to a /23 mask (255.255.254.0) and partitioning the resulting 510 address space with VLANs gives each trust zone enough headroom. CapyToolkit's subnet calculator shows the usable address range for any mask you consider so you can verify the pool covers all planned devices before applying settings in the ASUS admin panel.

Gaming, IoT and streaming VLANs with separate QoS

The GT-BE98 Pro includes Guest Network Pro, whose networks carry an Access Intranet setting meant to keep guest devices off the primary LAN. One owner on firmware 3006.102.2 reported that turning Access Intranet off still left every LAN device reachable, so test isolation from a guest device before you rely on it.3 Separating guests this way is useful for separating streaming devices and smart-home sensors from gaming hardware. For full VLAN segmentation, the router's LAN ports support 802.1Q VLAN tagging when used with a managed switch. A common gaming setup: gaming VLAN (192.168.50.0/24 with low latency QoS priority), IoT VLAN (192.168.51.0/24, isolated), streaming VLAN (192.168.52.0/24, medium QoS). Consequently, ASUS's Traffic Analyzer applies separate QoS profiles to each VLAN. Planning each CIDR block with the subnet calculator before configuring the switch ensures non-overlapping allocations and correct gateway assignments for each segment.4

Isolating gaming traffic with VLAN tags

Assign the gaming VLAN an 802.1Q tag matching the QoS priority level in the ASUS admin panel so the router applies low-latency queuing to frames tagged with the VLAN identifier from the managed switch. This ensures that upstream internet traffic from consoles and gaming PCs receives priority processing during congestion without competing against streaming or IoT bursts on the physical LAN segment. CapyToolkit's subnet calculator validates each CIDR allocation before you assign VLAN subinterfaces so the gaming CIDR never overlaps with the streaming or management ranges.

The GT-BE98 Pro also exposes a dedicated Gaming Port among its seven LAN ports, a low-latency Ethernet port that ASUS's own specifications call out separately from the standard 10Gbps, 2.5Gbps, and 1Gbps LAN ports. Wiring a gaming PC or console directly into the Gaming Port gives it a hardware-level fast path that complements VLAN-based QoS tagging, so latency-sensitive traffic gets priority treatment even before it reaches the switch where 802.1Q tags are applied.

AiProtection and subnet-aware firewall rules

ASUS AiProtection powered by Trend Micro inspects traffic at the network edge, blocking known-malicious IPs and scanning outbound connections for command-and-control signatures. AiProtection works at the router level, so it covers every device on the LAN without installing agents. Yet its effectiveness depends on correct subnet configuration: if the router's LAN subnet does not match the actual address range of connected devices, AiProtection may fail to inspect traffic from devices on unrecognized segments.

For multi-VLAN setups, AiProtection inspects traffic that passes through the router's inter-VLAN routing engine. Building on this, placing gaming devices on a dedicated VLAN with a known CIDR (for example, 192.168.50.0/24) lets you create AiProtection rules that apply only to that segment. IoT devices on a separate VLAN can receive stricter inspection profiles while gaming traffic passes through with minimal latency overhead. Consequently, the combination of VLAN segmentation and AiProtection creates a layered defense: the VLAN contains lateral movement, and AiProtection filters outbound threats per segment.

Configuring VPN subnets alongside gaming VLANs

The GT-BE98 Pro supports both ASUSWRT VPN server (OpenVPN and WireGuard) and VPN client modes. When you run a VPN server on the router, remote clients need their own subnet that does not overlap with any existing VLAN. Assign the VPN pool to 192.168.51.0/24, separate from the gaming VLAN at 192.168.50.0/24 and the IoT VLAN at 192.168.52.0/24. Building on this, the router's firewall rules control whether VPN clients can reach the gaming VLAN, the IoT VLAN, or only the internet. For competitive gaming, allowing VPN clients access to the gaming VLAN while blocking them from IoT segments prevents compromised remote devices from probing smart-home sensors.

Port forwarding and DMZ with custom subnets

The GT-BE98 Pro's port forwarding feature maps external ports to internal IP addresses, which requires the target device to have a consistent IP. When you change the router's subnet (for example, from 192.168.50.0/24 to 10.0.0.0/24), every existing port forwarding rule breaks because the internal IPs it references no longer exist. Before changing the subnet, document all port forwarding rules and DHCP reservations, then recreate them using addresses in the new range.

The DMZ host feature exposes one internal IP entirely to the internet, bypassing the router's firewall for that single address. Building on this, placing the DMZ host on its own small subnet (a /30 or /29) rather than the main LAN limits the blast radius if the DMZ host is compromised. For a game server that needs direct internet exposure, assign it 10.0.0.2/29 on the DMZ segment while the main gaming VLAN sits at 10.0.1.0/24. Consequently, an attacker who compromises the game server gains access to only the /29 DMZ segment, not the 253-host gaming VLAN behind it.5 carve a DMZ subnet for a game server on the ASUS GT-BE98 before opening any inbound ports.

Sources
  1. 1.

    ASUS, "ROG Rapture GT-BE98 Pro Specifications," rog.asus.com, accessed June 2026. https://rog.asus.com/networking/rog-rapture-gt-be98-pro/spec/

  2. 2.

    ASUS, "ROG Rapture GT-BE98 Pro Support," asus.com, accessed June 2026. https://www.asus.com/us/supportonly/gt-be98%20pro/helpdesk_bios/

  3. 3.

    SNBForums, "GT BE98 Pro Guest Network Cannot Disable Intranet Access," snbforums.com, November 2024. https://www.snbforums.com/threads/gt-be98-pro-guest-network-cannot-disable-intranet-access.92790/

  4. 4.

    V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632

  5. 5.

    R. Baker, "Address Allocation for Private Internets," RFC 1918, IETF, February 1996. https://www.rfc-editor.org/rfc/rfc1918.html

FAQ

192.168.50.1. ASUS uses 192.168.50.x to avoid conflicting with ISP router defaults at 192.168.0.1 and 192.168.1.1. Access the admin interface at http://192.168.50.1 or http://router.asus.com.

Go to LAN > LAN IP in the admin interface. Edit the LAN IP and Subnet Mask fields. Click Apply. Verify the DHCP pool under LAN > DHCP Server is updated to match the new subnet range. CapyToolkit's subnet calculator shows you the new pool boundaries before you apply changes so you can confirm the DHCP range covers your gaming devices.

The GT-BE98 Pro supports guest network isolation natively. For multi-VLAN homelab or gaming setups, connect a managed 802.1Q switch to the LAN port. The router handles inter-VLAN routing if configured with VLAN subinterfaces.

ASUS Adaptive QoS and Traffic Analyzer operate at the device level, classifying traffic by MAC or IP. When using custom subnets, static DHCP reservations ensure gaming devices keep consistent IPs that QoS rules target reliably. Dynamic IPs can cause QoS priority rules to miss the device after a lease renewal.

Yes. Configure IPv6 under Advanced Settings > IPv6. The router supports DHCPv6-PD, SLAAC, 6in4 tunnels, and 6to4. Delegated IPv6 prefixes are distributed to LAN devices as /64 blocks.

Netgear Nighthawk RS700S Subnet Settings

The Netgear Nighthawk RS700S is a flagship Wi-Fi 7 router with a 2.5 Gbps WAN port and 19 Gbps aggregate wireless throughput. Its default LAN subnet is 192.168.1.0/24, the most common home router default. For homelab users who connect the RS700S to a managed switch or NAS, changing the subnet to 10.0.0.0/24 or similar private range distinguishes it from ISP modem networks at a glance, which is useful when managing multiple VLANs or running split-DNS for internal hostnames.

Run this check yourself in the Subnet Calculator.

Open in the tool →

Specifications1

Default LAN IP192.168.1.1
Default subnet mask255.255.255.0
CIDR notation192.168.1.0/24
Default DHCP pool192.168.1.2 – 192.168.1.254
Max DHCP leases253 (full /24 pool)
IPv6 supportYes — DHCPv6, SLAAC, 6to4
Wi-Fi standardWi-Fi 7 (802.11be), tri-band
Management interfacehttp://routerlogin.net or http://192.168.1.1

Shrinking the 192.168.1.0/24 pool to free static addresses

The RS700S defaults to 192.168.1.0/242, a /24 block providing 253 usable DHCP addresses. Most household networks never fill a /24, but the router's WAN 2.5G port and LAN 2.5G ports make it attractive for homelab setups where servers, NAS units, and workstations need separate VLANs for storage traffic isolation. Building on this, the standard DHCP pool 192.168.1.2 through 192.168.1.254 leaves .1 for the router and does not reserve a static range for servers, so adjusting the pool to 192.168.1.100 through 192.168.1.254 frees 192.168.1.2 through 192.168.1.99 for static server assignments without DHCP conflicts.

Planning a static versus dynamic split

Reserving the bottom of the subnet for static assignments is a common convention because it keeps infrastructure addresses clustered and easy to document. A NAS at 192.168.1.10, a Proxmox host at 192.168.1.20, and a TrueNAS instance at 192.168.1.30 all sit below the DHCP range and never collide with dynamic leases. This convention also simplifies firewall rules on the router, since you can write rules that reference the entire static range rather than individual addresses.

Netgear's own configuration guide labels these as the Starting IP Address and Ending IP Address fields under Advanced > Setup > LAN Setup, and both values must fall within the same subnet as the router itself. This constraint is why the static-versus-dynamic split has to happen inside the /24 rather than by carving out a separate subnet for infrastructure devices: the DHCP pool boundaries can only be moved within 192.168.1.2 through 192.168.1.254, not redirected to an entirely different address range.

Changing subnet settings on the RS700S

Open a browser and navigate to http://routerlogin.net or http://192.168.1.1. Log in with your admin credentials. Go to Advanced > Setup > LAN Setup. The IP Address field shows the router's current LAN IP and the Subnet Mask field shows 255.255.255.0. Change these to your desired values, for example 10.0.0.1 with 255.255.0.0 for a /16, and then scroll down to the DHCP pool section to update the start and end IPs to match the new subnet range. Click Apply and the router reboots the DHCP service so devices must renew their leases.

Locking devices to a fixed address with DHCP reservations

Static DHCP reservations are configured on the same LAN Setup page by binding a device's MAC address to a fixed IP. This is preferable to configuring a static IP on the device itself because the reservation stays consistent even if you replace the device's network card or reinstall its operating system, and it keeps all address management in one place on the router.

Management, storage and IoT VLANs behind a managed switch

The RS700S provides a guest wireless network that runs in an isolated segment, restricting guest clients from accessing the main LAN. For multi-VLAN homelab setups, the RS700S connects to a managed switch that tags traffic with IEEE 802.1Q VLAN IDs. Each VLAN maps to a subnet: management VLAN at 10.0.0.0/24, storage VLAN at 10.0.1.0/24, IoT VLAN at 10.0.2.0/24.

Deciding where inter-VLAN routing happens

The RS700S performs inter-VLAN routing if configured with VLAN subinterfaces, or a dedicated firewall handles routing if the RS700S is used only as a wireless access point in this topology. CapyToolkit's subnet calculator helps pre-plan CIDR allocations for each VLAN before configuring the managed switch, ensuring non-overlapping ranges and a clean per-VLAN DHCP setup. Deciding up front whether the RS700S or an upstream firewall routes between VLANs determines how you configure the trunk port on the managed switch.

Static IP planning for homelab servers and NAS devices

Homelab setups with the RS700S benefit from a clean split between dynamic and static address ranges. Reserving 192.168.1.2 through 192.168.1.99 for static assignments and 192.168.1.100 through 192.168.1.254 for DHCP prevents address conflicts when adding new servers. A NAS at 192.168.1.10, a Proxmox host at 192.168.1.20, and a TrueNAS instance at 192.168.1.30 keep infrastructure addresses clustered at the bottom of the subnet for easy documentation. Building on this, the RS700S DHCP pool configuration at Advanced > Setup > LAN Setup lets you set the start address to 192.168.1.100, automatically skipping the static range. Changing this pool boundary after initial setup requires only one configuration change rather than individual device reconfiguration.

IPv6 prefix delegation and LAN configuration on the RS700S

The RS700S supports DHCPv6-PD (Prefix Delegation) on the WAN side.3 When the ISP delegates a /56 or /60 prefix, the router assigns a /64 from that delegation to the LAN. Enabling IPv6 at Advanced > Advanced Setup > IPv6 assigns LAN hosts their addresses through SLAAC, DHCPv6, or both simultaneously. Building on this, the RS700S displays the current WAN IPv6 prefix and LAN IPv6 prefix in the same IPv6 settings page. If your ISP delegates a /56 (for example 2001:db8:abcd::/56), the router assigns 2001:db8:abcd:0001::/64 to the LAN, leaving 254 additional /64s available for VLANs.4 Without VLAN support on the RS700S LAN, the single /64 serves all devices, which is sufficient for most home deployments. CapyToolkit shows the /64 boundaries when you enter the delegated prefix, helping you plan multi-VLAN IPv6 if you add a managed switch.

Using the RS700S in AP mode behind a dedicated gateway

Switching the RS700S to AP mode (Advanced > Advanced Setup > Router/AP Mode > AP Mode) disables its NAT and DHCP server, turning the device into a pure wireless access point. Your upstream gateway : pfSense, OPNsense, or a UDM Pro : handles all routing, subnet assignment, and firewall rules. Building on this, AP mode is the correct deployment choice when you run a multi-VLAN setup: the upstream gateway assigns VLAN-backed subnets with 802.1Q trunking to a managed switch, and the RS700S provides Wi-Fi on whichever VLAN the switch port is configured for.

The routerlogin.net admin interface remains accessible at the static IP you assign in AP mode (typically a management VLAN address). All Wi-Fi settings, band steering, and mesh features continue to work; only routing functions are disabled. Before flipping the RS700S to AP mode, map each VLAN to a subnet on the Nighthawk RS700S so the upstream gateway inherits clean CIDR boundaries.5

Sources
  1. 1.

    Netgear, "Nighthawk RS700S Support," netgear.com, accessed June 2026. https://www.netgear.com/support/product/rs700/

  2. 2.

    Netgear, "How do I change the LAN TCP/IP settings on my Nighthawk router," kb.netgear.com, accessed June 2026. https://kb.netgear.com/24088/How-do-I-change-the-LAN-TCP-IP-settings-on-my-Nighthawk-router

  3. 3.

    Netgear, "How do I specify the pool of IP addresses assigned by my Nighthawk router," kb.netgear.com, accessed June 2026. https://kb.netgear.com/24089/How-do-I-specify-the-pool-of-IP-addresses-assigned-by-my-Nighthawk-router

  4. 4.

    O. Troan and R. Droms, "IPv6 Prefix Options for Dynamic Host Configuration Protocol (DHCP) version 6," RFC 3633, IETF, December 2003. https://www.rfc-editor.org/rfc/rfc3633.html

  5. 5.

    V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632

FAQ

192.168.1.1. The admin interface is at http://routerlogin.net or http://192.168.1.1. Default admin credentials are admin/password unless changed during setup.

Go to Advanced > Setup > LAN Setup in the admin UI. Edit the IP Address and Subnet Mask fields. Update the DHCP pool start and end to match the new subnet. Click Apply and allow the router to restart its DHCP service.

The RS700S supports guest network isolation natively. For full multi-VLAN configuration, connect it to a managed 802.1Q switch. CapyToolkit's subnet calculator helps you pre-plan the CIDR for each VLAN before configuring the switch. Check the RS700S firmware release notes for current VLAN tagging capabilities on LAN ports.

The default DHCP lease time is 1440 minutes (24 hours). Adjust this under Advanced > Setup > LAN Setup. Shorter leases suit high-turnover environments; longer leases reduce DHCP traffic on stable home networks.

Not natively in the standard firmware. The RS700S provides one DHCP server for its primary LAN subnet. To serve DHCP across multiple VLANs, add a DHCP relay or use pfSense/OPNsense as the DHCP server while the RS700S handles wireless access.

eero Pro 7 Subnet Settings

The Amazon eero Pro 7 is a Wi-Fi 7 mesh router designed for zero-configuration setup. Its default subnet is 192.168.4.0/22. Unusually, eero uses a /22 rather than the /24 common on competing routers, giving the system 1,022 usable addresses across its DHCP pool. This larger subnet accommodates smart homes with many devices without pool exhaustion.

Run this check yourself in the Subnet Calculator.

Open in the tool →

Specifications1

Default LAN IP192.168.4.1
Default subnet mask255.255.252.0
CIDR notation192.168.4.0/22
Default DHCP pool192.168.4.2 – 192.168.7.254
Max DHCP leases1022 (full /22 pool)
IPv6 supportYes — DHCPv6 and SLAAC via eero app
Wi-Fi standardWi-Fi 7 (802.11be), tri-band
Management interfaceeero app (iOS/Android only); no browser UI

What a /22 flat network allows and risks

eero's /22 default (192.168.4.0/22, as eero owners report it)2 spans four /24 blocks: 192.168.4.x through 192.168.7.x. This provides 1,022 usable addresses, far more than the 254 of a standard /24. The larger pool prevents DHCP exhaustion in dense smart-home environments where dozens of IoT sensors, speakers, and appliances each claim a lease. Yet a /22 flat network means every connected device can reach every other. A compromised smart device has access to all 1,021 other addresses in the pool. Building on this, eero's Network+ feature (paid subscription) adds profile-based device segmentation, but true VLAN isolation requires a managed switch behind the eero.

When a /22 flat network makes sense

A flat /22 suits households with a single trusted zone where every device can freely communicate with every other. Smart-home ecosystems benefit from this openness during initial setup because mDNS and discovery protocols reach across the entire subnet without routing configuration. The tradeoff is that a compromised device can probe all 1,021 other leases, so /22 deployments work best when every connected device is trusted and firmware is kept up to date.

Changing subnet settings via the eero app

Open the eero app, tap Settings (gear icon) > Advanced Settings > DHCP & NAT. The current subnet and gateway IP are displayed. To change the subnet, tap the IP address and enter a new gateway IP and subnet mask. For example, setting 10.0.0.1 with 255.255.0.0 moves the network to 10.0.0.0/16 with 65,534 available addresses. Tap Save; the eero network restarts its DHCP service and clients must renew leases. Furthermore, DHCP reservations are available under the individual device settings. Tap a device in the app, then Reserve IP to bind a static address to that device's MAC so the device keeps the same lease even after it disconnects from the mesh for several days.

Choosing a non-default subnet on the eero Pro 7

Changing the subnet mask is uncommon on eero but useful when you want fewer addresses and a smaller broadcast domain for tighter device isolation. For example, switching the mask to 255.255.255.0 on a 192.168.4.0 configuration gives you a /24 with 254 usable addresses and a smaller flood scope. CapyToolkit's subnet calculator shows you the available address count for any gateway-and-mask combination before you apply changes in the eero app.

The same DHCP & NAT screen also exposes a NAT type toggle with three modes: automatic (eero manages NAT itself), custom (you define the NAT behavior manually), and bridged (NAT is disabled entirely so an upstream router handles it). Switching to custom NAT is the setting to use alongside a non-default subnet, since automatic mode assumes eero's own addressing scheme and can conflict with a manually chosen gateway and mask.

Guest network and trust-zone VLANs behind the eero

eero supports a guest network through the app. This creates a second SSID with its own isolated segment. Guest devices cannot reach the primary network but can access the internet. For full VLAN segmentation (IoT isolation, homelab servers, cameras), connect a managed switch to the eero's LAN port with IEEE 802.1Q VLAN tagging. Configure the switch with VLAN IDs matching intended trust zones and set the eero as the upstream gateway.

Planning CIDR blocks for each trust zone

Each VLAN receives its own CIDR block planned with the subnet calculator. IoT zones work well as /24 networks with 254 usable addresses, guest zones as /25 networks with 126 usable addresses, and management zones as /26 networks that limit exposure to 62 devices. Consequently, IoT sensors sit in a /24 that the switch blocks from reaching the personal device VLAN, while the main eero still routes internet-bound traffic for all VLANs.

Why eero chose /22 instead of /24 and what it means for you

Most home routers default to a /24 subnet (254 usable addresses).3 eero quadrupled that to a /22 (1,022 usable addresses) because modern smart homes routinely have 30 to 80 connected devices: phones, laptops, tablets, smart speakers, thermostats, cameras, smart plugs, TVs, and streaming sticks. A /24 exhausts in large households or multi-unit dwellings where neighbors' networks contribute devices that briefly roam onto the mesh. Building on this, the tradeoff is a larger broadcast domain: every ARP request from any device reaches all 1,021 other potential addresses. In practice, this rarely causes performance issues on modern Wi-Fi hardware, but it does mean compromised devices can scan a wider address space. If your household has fewer than 50 devices and you want smaller broadcast domains, switching to a /24 in the eero app reduces the address pool without affecting functionality.

Port forwarding and DHCP reservations on the eero Pro 7

The eero app's Reserve IP feature (under device settings) binds a MAC address to a fixed IP within the DHCP pool. This is critical for devices that need consistent addresses: a home server running Plex, a NAS that network shares reference, or a gaming console that needs inbound ports open. After reserving the address, navigate to Settings > Advanced Settings > Reservations & Port Forwarding to map external ports to that reserved IP. Building on this, eero+ (the paid subscription) adds advanced threat scanning and ad blocking at the DNS level, but port forwarding and DHCP reservation work without a subscription. The eero Pro 7's NAT table supports up to 20 simultaneous port forwarding rules; for server hosting needs beyond that scale, consider a dedicated gateway that gives you full iptables or pfSense control.4

Bridge mode and using the eero behind a dedicated router

Placing the eero Pro 7 in bridge mode (Settings > Advanced Settings > DHCP & NAT > Bridge) disables its routing function and turns the mesh into a pure wireless access point. Your upstream router, whether a pfSense box, a UDM Pro, or an OpenWrt gateway, handles all subnetting, DHCP, firewall rules, and inter-VLAN routing without any configuration changes on the eero itself.

Building on this, bridge mode is the correct choice when you need proper VLAN segmentation, as eero's native firmware does not support VLAN tagging on its LAN ports. In bridge mode, eero's built-in security features (threat scanning, content filtering) still operate at the DNS level, but firewall rules must live on the upstream gateway where they can inspect traffic across all VLANs.

The eero app continues to manage Wi-Fi settings, firmware updates, and device profiles even when routing is disabled, which means you can adjust channel widths, pause client access, and push firmware to mesh nodes without touching the upstream routing stack. CapyToolkit's DHCP pool calculator helps determine the correct addresses to assign to eero nodes as static leases under the upstream router's subnet so each mesh unit keeps a consistent management IP even as wireless clients roam across different access points. Before you flip the eero to bridge mode, reserve a fixed IP for every eero Pro 7 node under the upstream router's subnet so each unit keeps that address as clients roam.5

Sources
  1. 1.

    eero, "Advanced Networking Settings," eero.com, accessed June 2026. https://support.eero.com/hc/en-us/articles/360036385311-What-are-the-Advanced-networking-settings

  2. 2.

    Roon Community, "Several problems with Nucleus+ after recent router upgrade to Eero," community.roonlabs.com, accessed October 2026. https://community.roonlabs.com/t/several-problems-with-nucleus-after-recent-router-upgrade-to-eero/299247

  3. 3.

    Tom's Hardware, "Amazon eero 7 Pro Review," tomshardware.com, accessed June 2026. https://www.tomshardware.com/networking/routers/amazon-eero-7-pro-wi-fi-7-mesh-router-review

  4. 4.

    V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632

  5. 5.

    R. Baker, "Address Allocation for Private Internets," RFC 1918, IETF, February 1996. https://www.rfc-editor.org/rfc/rfc1918.html

FAQ

192.168.4.0/22, which provides 1,022 usable DHCP addresses across the range 192.168.4.2 to 192.168.7.254. eero uses a /22 instead of the more common /24 to accommodate large smart-home device counts.

Open the eero app > Settings > Advanced Settings > DHCP & NAT. Edit the gateway IP and subnet mask. After saving, the eero restarts its network stack and devices must renew DHCP leases. The eero app is required; there is no browser-based admin page.

No. eero devices are managed exclusively through the eero iOS or Android app. All settings including subnet, DHCP, and port forwarding are configured in the app. No browser admin interface is available.

The eero app provides a guest network for basic isolation. eero+ (paid) offers profile-based access controls per device. For true subnet isolation, add a managed switch behind the eero with VLAN tagging. CapyToolkit's subnet calculator helps you pre-plan each VLAN's CIDR before assigning them to the eero's trust zones.

A /22 provides 1,022 DHCP addresses versus 254 for a /24. eero targets customers with many smart-home devices, including speakers, sensors, cameras, and appliances, so the larger pool prevents DHCP exhaustion without requiring users to change settings.

Ubiquiti UDM-Pro 10G Cloud Gateway Subnet Settings

The Ubiquiti UDM-Pro 10G Cloud Gateway is the leading prosumer and homelab networking gateway in 2026. Unlike consumer routers, the UDM Pro is designed from the start for multi-VLAN deployments. Creating separate networks with different subnets is a first-class feature in the UniFi OS console. Each network gets its own CIDR block, DHCP range, firewall zone, and optional VPN policy.

Run this check yourself in the Subnet Calculator.

Open in the tool →

Specifications1

Default LAN IP192.168.1.1
Default subnet mask255.255.255.0
CIDR notation192.168.1.0/24
Default DHCP pool192.168.1.6 – 192.168.1.254
Max DHCP leases249 (default pool)
IPv6 supportYes — DHCPv6-PD, SLAAC, static prefix
Wi-Fi standardRequires separate UniFi APs (not built-in)
Management interfacehttps://unifi.ui.com or local https://192.168.1.1

The default LAN as one of many networks

The UDM Pro ships with a 192.168.1.0/24 LAN,2 placing the router at .1 and allocating DHCP from .6 to .254. Five addresses (.1 through .5) are reserved for static assignments to the gateway and management services. In contrast to consumer routers, the UDM Pro treats the default network as just one of many possible networks. Adding a second network takes three clicks in the UniFi console and immediately provisions a new DHCP server and firewall zone. Building on this, the default network typically serves management devices (switches, APs) while additional networks serve user segments, IoT devices, and cameras in well-designed UniFi deployments.

Adding networks in UniFi OS

Log into the UniFi console at https://unifi.ui.com or https://192.168.1.1. Navigate to Settings > Networks > Create New Network. Enter a name, choose the purpose (Corporate, Guest, VLAN Only), and set the CIDR subnet. For example, 10.0.10.0/24 is a solid choice for an IoT VLAN. The VLAN ID field assigns an 802.1Q tag (e.g., VLAN 10). Enable DHCP and set the pool range. UniFi OS automatically creates inter-VLAN routing rules and firewall zones. Consequently, restricting IoT devices from reaching the main LAN requires one firewall rule: Block IoT Zone to LAN Zone in Settings > Firewall Policies. The UDM Pro enforces these rules at hardware speed for throughput above 1 Gbps.

Seven VLANs carved from one 10.0.0.0/20 block

UniFi lets you create a separate virtual network for each VLAN, and a UDM Pro homelab might use seven of them: Management (10.0.0.0/24), Trusted LAN (10.0.1.0/24), IoT (10.0.2.0/24), Guest (10.0.3.0/24), Cameras (10.0.4.0/24), Servers (10.0.5.0/24), VPN clients (10.0.6.0/24).3 Planning these from a parent /20 block (10.0.0.0/20) keeps all subnets within one summarizable prefix that simplifies firewall summarization and route tables across the UDM Pro routing engine. Building on this, UniFi OS supports site-to-site VPN between UDM Pro units and requires that each site publish a unique non-overlapping prefix so tunnel traffic routes without ambiguity during failover or mesh reconvergence. CapyToolkit's subnet calculator verifies each CIDR allocation before you commit values to the UniFi console and prevents overlapping ranges from breaking pooled address plans.

Allocating CIDR blocks across trust zones

When you segment the available address block into flat /24 networks, you can leave headroom for future expansion by reserving CIDR prefixes on tier boundaries. The UDM Pro itself supports route summarization across six to eight contiguous networks at once, which means that a single advertising entry for 10.0.0.0/21 covers your IoT, Guest, Cameras, and Servers VLANs in one route table line rather than four individual entries that complicate leaks during topology changes.4 This summarization behavior is essential to keep the UniFi OS routing engine from bloating dynamic rules across multiple SD-WAN tunnels during multi-site failover events. CapyToolkit's subnet calculator enumerates each CIDR prefix in the recommended order so the entire plan fits inside one summarizable block before you enter the first CIDR value into the console.

DHCP configuration per VLAN on the UDM Pro

Each network on the UDM Pro runs its own DHCP server with an independently configurable pool. After creating a VLAN network at 10.0.10.0/24, the DHCP pool defaults to the full subnet range. Narrowing the pool (for example, 10.0.10.100 through 10.0.10.200) reserves addresses below .100 for static assignments to servers, printers, and access points. Building on this, DHCP reservations under Settings > Networks > [Network Name] > DHCP Name Server let you bind specific MAC addresses to fixed IPs within the pool. A UniFi access point that always receives 10.0.10.2 retains that address even after firmware updates or replacement hardware; simply update the MAC address in the reservation to match the new device.

Firewall rule design for multi-VLAN deployments

UniFi OS creates automatic firewall zones for each network: default, guest, VPN, and any custom VLAN networks you add. Inter-VLAN routing is enabled by default, which means devices on any network can reach devices on any other network unless you block it. A single firewall rule blocking IoT Zone to LAN Zone at Settings > Firewall Policies restricts IoT devices to internet-only access while allowing LAN devices to initiate connections to IoT endpoints for management. Building on this, placing blocking rules above allowing rules in the policy list matters: UniFi OS processes rules top-to-bottom, and the first matching rule wins. Adding an allow rule for a specific port above a blanket block gives granular exceptions without opening the entire zone.

DNS configuration across VLANs

The UDM Pro's built-in DNS forwarder serves all VLANs by default. Conditional DNS forwarding under Settings > Networks > [Network] > DHCP Name Server lets you specify which DNS server handles each VLAN. Directing IoT VLAN DNS queries to a Pi-hole or AdGuard instance at 10.0.2.10, while keeping the primary LAN on Cloudflare's 1.1.1.1, gives you per-zone DNS filtering without separate physical hardware. Clients within each VLAN inherit the DNS server automatically through DHCP option 6.

VPN integration with VLAN-backed subnets

The UDM Pro supports L2TP, OpenVPN (via Teleport), and WireGuard (since UniFi OS 3.x). Remote access VPN clients receive an IP from a dedicated VPN subnet configured under Settings > Teleport & VPN. Building on this, adding a firewall rule that permits VPN Zone traffic to specific VLAN subnets (for example, allowing VPN clients to reach 10.0.5.0/24 for the Servers VLAN but not 10.0.2.0/24 for the IoT VLAN) provides secure remote access to management interfaces without exposing the entire network. Site-to-site WireGuard tunnels between two UDM Pro units require non-overlapping CIDR allocations at each site; planning these from separate /20 blocks (10.0.0.0/20 for site A, 10.16.0.0/20 for site B) ensures no routing conflicts when the tunnel comes up. split a /20 across VPN sites on the Dream Machine Pro so each tunnel gets a unique prefix before the link comes up.5

Monitoring traffic between VLANs

UniFi OS traffic identification classifies packets by application type and displays per-client statistics in the UDM Pro dashboard. Under Insights > Traffic, you can filter by VLAN to see bandwidth consumption per zone. Setting traffic rules with bandwidth profiles (for example, limiting the Guest VLAN to 50 Mbps aggregate) prevents one segment from saturating the uplink. CapyToolkit's subnet calculator helps plan the CIDR allocations that feed into this entire workflow: each VLAN's subnet size determines the DHCP pool, which determines the address range your firewall rules target.

This traffic identification runs through the UDM Pro's Deep Packet Inspection engine, which the official tech specs rate at 3.5 Gbps of combined IDS/IPS throughput. Because that inspection capacity is shared across every VLAN, a Guest network saturating its bandwidth cap still leaves headroom for the DPI engine to keep classifying traffic on the Servers and Management VLANs without dropping visibility into either segment.

Sources
  1. 1.

    Ubiquiti, "UDM-Pro Quick Start Guide," ui.com, accessed June 2026. https://dl-origin.ubnt.com/qsg/UDM-Pro/UDM-Pro_EN.html

  2. 2.

    Ubiquiti, "UniFi Dream Machine Pro Tech Specs," ui.com, accessed June 2026. https://techspecs.ui.com/unifi/cloud-gateways/udm-pro

  3. 3.

    Ubiquiti, "Creating Virtual Networks (VLANs)," help.ui.com, accessed October 2026. https://help.ui.com/hc/en-us/articles/9761080275607-Creating-Virtual-Networks-VLANs

  4. 4.

    V. Fuller and T. Li, "Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan," RFC 4632, IETF, August 2006. https://www.rfc-editor.org/info/rfc4632

  5. 5.

    R. Baker, "Address Allocation for Private Internets," RFC 1918, IETF, February 1996. https://www.rfc-editor.org/rfc/rfc1918.html

FAQ

Go to Settings > Networks > Create New Network in UniFi OS. Set the subnet CIDR, VLAN ID, enable DHCP, and configure the pool range. UniFi automatically creates firewall zones for the new network and enables inter-VLAN routing.

192.168.1.1 on the default LAN. For each additional network you create, the gateway is the first usable address in that subnet. For a 10.0.10.0/24 network, UniFi OS sets the gateway automatically to 10.0.10.1.

Yes. Create the IoT network on a separate VLAN. Then in Settings > Firewall Policies, add a rule blocking traffic from the IoT zone to the LAN zone. UniFi OS applies this rule in the firewall engine so IoT devices can still reach the internet but not the main network. CapyToolkit's subnet calculator helps you pre-allocate the CIDR for the IoT zone and the LAN zone before you create the corresponding firewall rules.

Yes. Configure IPv6 PD under Settings > Internet > IPv6 Connection. The UDM Pro requests a prefix from your ISP and distributes /64 blocks to each network automatically.

UniFi OS supports up to 4094 VLANs (the 802.1Q maximum). Practical deployments rarely exceed 20 active networks. Each network runs its own DHCP server process, and the UDM Pro handles 15 to 20 active DHCP scopes without performance issues.

FAQ

Pick a range that nothing else you connect to uses. The three private IPv4 blocks are 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. A /24 inside 10.x.x.x is a common choice because few ISP modems or hotel networks use it, which avoids clashes when you connect over a VPN.

Yes, briefly. The router moves to the new address and every device has to request a new lease. Most reconnect on their own within a minute; devices with a static IP do not, and you have to change their address by hand.

Update every DHCP reservation, every port forwarding or DMZ rule, any device with a static IP and any bookmark to the router's admin page. If you run a NAS or home server, update the clients that reach it by IP as well.

Many routers leave part of the subnet outside the pool for static addresses. A TP-Link Archer BE900 hands out 150 leases from .100 to .249 by default, and a UDM-Pro starts its pool at .6. Keep static devices outside the pool so DHCP never gives their address to something else.

A mesh extends one subnet across all its nodes, so every device shares the same range no matter which node it joins. Guest and IoT networks add an isolated segment, but full VLAN separation needs a router or gateway built for it, such as the UDM-Pro, or a managed switch.

No. CapyToolkit offers the subnet calculator as a page that runs entirely in your browser, so you can plan the new range before you log in to the router or while you are offline.

Additional resources