1/2
How to configure an ISP-provided /29 public subnet using single and multiple interfaces? 20

Newbie634092 Lv1  Posted 2026-Aug-08 19:31

Last edited by Newbie634092 2026-Aug-10 09:40.

Hi Sangfor Community,

I am new to Sangfor and would appreciate some guidance.

We have subscribed to a static /29 public IP service from our ISP. The PPPoE connection has already been configured successfully on eth1.621.

After the PPPoE connection is established, Sangfor detects the assigned public IP with a /32 prefix.
The information below is fictional and does not contain our actual IP addresses or credentials:

Firmware version: 8.0.95
PPPoE interface: eth1.621
PPPoE username: test-office@example-isp.com  
Subscribed public subnet: 203.0.113.216/29
Subnet mask: 255.255.255.248
Public IP detected on PPPoE: 203.0.113.217/32
Remaining public IPs: 203.0.113.218-203.0.113.222

I would like the connected devices or gateways to use the remaining static public IP addresses directly on their WAN interfaces without source NAT. Sangfor should continue handling the PPPoE connection on eth1.621.

I would like to understand how to configure the following two methods.

Method 1: Single Sangfor interface with a switch

ISP ONT   
    |
Sangfor eth1.621 (PPPoE)   
    |
Sangfor eth2   
    |
Switch   
    |   
   +-- Device 1: 203.0.113.218   
   +-- Device 2: 203.0.113.219   
   +-- Device 3: 203.0.113.220   
   +-- Device 4: 203.0.113.221   
   +-- Device 5: 203.0.113.222

Method 2: Multiple Sangfor physical interfaces

ISP ONT   
    | Sangfor eth1.621 (PPPoE)   
    |   
   +-- eth2 --> Device 1: 203.0.113.218   
   +-- eth3 --> Device 2: 203.0.113.219   
   +-- eth4 --> Device 3: 203.0.113.220   
   +-- eth5 --> Device 4: 203.0.113.221   
   +-- eth6 --> Device 5: 203.0.113.222

Could someone please share a sample configuration or step-by-step guide for both methods, including any required interface, zone, routing, NAT and security-policy settings?

If one of these methods is unsupported, please advise why and recommend the closest supported configuration.

Thank you.

By solving this question, you may help 1023 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins, 20 coins of bounty and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Muhammad Abid Lv3  Posted 2026-Aug-15 12:23
  
Recommended Topology

ISP ONT
   |
   | PPPoE
   |
Sangfor eth1.621
203.0.113.217/32
   |
   | eth2
   |
Managed Switch
   |
   +--- Device 1 → 203.0.113.218
   +--- Device 2 → 203.0.113.219
   +--- Device 3 → 203.0.113.220
   +--- Device 4 → 203.0.113.221
   +--- Device 5 → 203.0.113.222

Method:
Simpler configuration
Uses only one Sangfor physical interface for the downstream devices
Centralized firewall/security policies
Easy to add more public-IP devices later
Simpler cabling
Easier troubleshooting and management
No need to dedicate one Sangfor port to each device
Supports your requirement of using public IPs directly without SNAT

Important ISP confirmation

Before implementing Method, confirm with your ISP:

“Our PPPoE session receives 203.0.113.217/32. Is the complete 203.0.113.216/29 subnet routed to this PPPoE session, allowing us to use 203.0.113.218–203.0.113.222 on downstream devices without NAT?”

If the ISP confirms Yes, then Method is the recommended design.

I can also provide the
exact Sangfor 8.0.95 GUI configuration step-by-step for Method 1, including Interface → Zone → Routing → No-NAT → Security Policy → Switch → Device IP/Gateway

Lucky1001 Lv1  Posted 2026-Aug-15 09:38
  
Hi,

Thank you for the detailed explanation.

Based on the topology you described, the key point is that the PPPoE session is established on eth1.621 and Sangfor receives the PPPoE-assigned address as a /32, while the ISP has additionally routed the /29 public subnet to your PPPoE connection.

In this scenario, I would recommend confirming with Sangfor first whether the additional /29 subnet can be routed directly through the PPPoE interface without NAT, and how Sangfor expects the next-hop/gateway to be configured.

For Method 1, where eth2 connects to a switch and multiple devices use the remaining public IP addresses, I believe this would normally require Sangfor to route the /29 subnet toward the LAN-side interface rather than perform source NAT. The connected devices could then use their individual public IP addresses directly.

For Method 2, where each public IP is assigned to a separate physical interface, I would also like to confirm whether Sangfor supports this design, since each interface would essentially need to participate in the routing of the same public /29 subnet.

Could someone from Sangfor please provide guidance on the following?

How should the /29 public subnet be configured when the PPPoE interface itself receives a /32 address?
Should the /29 be configured as a routed subnet, secondary IP network, or through another mechanism?
For Method 1, what interface/zone, routing, NAT and security-policy configuration is required?
For Method 2, is it technically supported to assign one public IP to each physical interface while keeping the PPPoE connection on eth1.621?
If direct public-IP assignment without NAT is not supported, what is the recommended Sangfor topology for this scenario?
Is there any specific configuration required on the ISP side to route the /29 subnet correctly to the PPPoE session?

I would appreciate a sample configuration or step-by-step example for the recommended approach.

Thank you in advance for your assistance.
Newbie634092 Lv1  Posted 2026-Aug-11 11:27
  
Hi, thank you for the replies.

To clarify, I do not want eth2 to use a private subnet with source NAT. The requirement is for downstream devices to configure the public addresses directly on their WAN interfaces.

In the fictional example:
PPPoE eth1.621: 203.0.113.217/32
Downstream devices: 203.0.113.218-203.0.113.222

The PPPoE default route is created automatically when the connection is established.

Could you please advise the exact supported configuration for presenting the routed /29 on eth2 while Sangfor continues terminating PPPoE?

In particular, should eth2 use a public gateway address from the /29, or does Sangfor provide a feature such as public-subnet extension, proxy ARP or an unnumbered interface?

I would also appreciate guidance for using:

One interface with a downstream switch; and Multiple Sangfor physical interfaces.

The downstream devices must retain their public addresses without SNAT.
Prosi Lv4  Posted 2026-Aug-10 10:24
  
Yes, the key point is that the static /29 IP block provided via PPPoE differs from the PPPoE interface configuration itself (which uses a /32 mask).

If the Sangfor device displays the PPPoE-assigned address as x.x.x.x/32, this is likely normal behavior: PPPoE sessions use *point-to-point* addressing, whereas the additional /29 public addresses likely need to be routed through that PPPoE interface.

Additionally, check the Sangfor session/traffic logs while performing external tests. If packets reach the firewall but are dropped, the logs will help determine whether the issue lies with routing, NAT, or security policies.

Important: Specific Sangfor menu names and supported system behaviors may vary depending on the NGAF/NSF model and firmware version; therefore, I do not recommend applying a generic /29 configuration without making the necessary adjustments first.
fuadmahbubun Lv2  Posted 2026-Aug-10 09:19
  
Hi, you can find the fully guidance here :
https://support.sangfor.com/prod ... category_id=2647630

based on your description, you got public ip address from ISP using PPPoE conection to Provider. CMMIW
make sure to ISP possible or not in one PPPOE interface they can handle multi ip address, since you said that  Public IP detected on PPPoE: 203.0.113.217/32 it seems this ip got from ISP DHCP server.

In normal condition without DHCP client in NSF, you can put all public ip address in same interface.
Method 1: Single Sangfor interface with a switch
ISP ONT   
    |
Sangfor eth1.621 (PPPoE)   
IP Address :
   203.0.113.218/29   
   203.0.113.219/29   
   203.0.113.220/29  
   203.0.113.221/29   
   203.0.113.222/29
    |
Sangfor eth2   192.168.1.1/24 (this ip address for your internal gateway)
    |
Switch   
    |
PC Users

#create Zone
Go To Network, and select Zones
klick Add :
insert "ISP" in the name, select layer 3 for type.
select interface (eth1, eth1.162)
Klik OK

Klick Add
insert "local" in the name, select layer 3
select interface (eth2)
klick OK.

#Now you have 2 zones, ISP and Local.

#Continou to create Routing
Go To network and select Routes >> static Routes.
Klick Add
Insert name in description,
insert in DST IP / netmask : "0.0.0.0/0"
Interface : Auto
Next Hope IP : 203.0.113.217 (gateway from ISP)
klick SAVE

#Continou add DNS
Go To network, select DNS >> DNS Server
insert in prefered DNS and Alternate DNS then Save.

#Continou to Create policy to allow you connected to internet.
go To Policies, Select network Security >> Policies
Klikc Add then select Add Policy for internet Access Scenario
Insert The name "internet
Src Zone : local
Src Address : network object select all

Dst zone : select ISP
dst Address : All (0.0.0.0/0)

Klick Next
Basic protection
Select intrution prevention and Content security, action deny

Klick next, select botnet detection then save.

# now you can test connect client to internet.

Please reply if you find some error. and share here.


   

I Can Help:

Change

Moderator on This Board

1
159
3

Started Topics

Followers

Follow

1144
248
101

Started Topics

Followers

Follow

Board Leaders