This network still at a design stage, My customer need to design a network for many as 100-200 subnets. But he is not satified with 10.0.0.0 address space available, his method is to dedicate one octate as a whole to identify the function. for example 10.4.0.0, 10.5.0.0 etc are the stores, and 3rd octate reserve for functions withing the stores.
When he goes like that, he ran out of address space, and now he want to use 220.127.116.11, 18.104.22.168 etc for his expansion.
How could I present a argument in a suttle manner to persuade them to comply with RFC1918, is there any guideline document I could use to build a address space for them
Any help would be appreciated.
Here are my 2 cents on the subject.
To do address spacing like the customer is doing right now is truly not a good idea.
For one thing it is very easy to hide hacking equipment in a big address space.
Try searching a 10.5.x.y space for a rouge unit, with a portscanner or simply just by trying to ping it.
It will take you a while. Now do that 250 more times or so. get the point ?
Design a network with what you need and be generous with addresses and make shure that the ones you think will grow have potential to atleast double in size.
fx 192.168.1.0 /24 might need to grow to 192.168.1.0 /23 or even /22.
plan ahead for things like that.
but build the network with 192.168.1.0/24 if you only need 150 addresses today, just leave space enough to grow so that you do not need to change addresses on the equipment, only subnetmask.
if he does not want to use rfc 1918 addresses for some reason then let him know that any address he is using that is not an RFC 1918 address will simply not be reachable from the offices that uses those non rfc1918 addresses.
it is a routing thing. (unless he realy wants to make things complicated for himself with double nat and so on).
One big problem was this problem that people used other companies internet addresses and got them selves into trouble.
if he does not listen and understands this then think twice of taking the job.
That said there are some good reasons why one would like to use Proper internet addresses but make shure they are registred to you if you actually do that.