Working with Overlapping IP Addresses

Overlapping Internet Protocol (IP) addresses occur when IP addresses repeat across your network, as in retail branches, Operational Technology environments, or merged corporate networks.

By default, the Internal Network defined in the only supports a single domain of unique IP addresses. This guide describes configuration options and tools that support networks with overlapping IPs. When these options are enabled, you can configure segments with overlapping IPs and assign these segments to Appliances.

eyeSight Components that Support Overlapping IP Addresses

In addition to the eyeSight, the following components support working with networks that use overlapping IP addresses:

Component Provided in Module

CEF Plugin

A Core Extensions Module

DNS Enforce Plugin

A Core Extensions Module

eyeExtend for Splunk

An eyeExtend Module

eyeSegment An eyeSegment Module

Flow Collector

A Core Extensions Module

Operational Technology Module

An eyeInspect Module

Reports Plugin

A Core Extensions Module

Rogue Device Plugin

A Network Module

Switch Plugin

A Network Module

VMware vSphere Plugin

A Hybrid Cloud Module

VPN Concentrator Plugin

A Network Module

Wireless Plugin

A Network Module

For eyeSegment only, overlapping IP addresses will only work when using eyeSight v8.5.3 and above and v9.1.5.

Networking Requirement for Flow Collector

For the Flow Collector to support working with networks that use overlapping IP addresses, the following networking requirement must be fulfilled:

  • For any given switch device in the enterprise's network, each connected endpoint must be assigned a different, unique IP address.