Adding subnet to existing Windows 2003 server domain

I currently have a Windows Domain on my company's subnet. The subnet is
Now, I ran out of addresses and I need to add a new subnet to my Windows 2003 server that will be
The computers will be connected through a Layer 3 switch inside my network.
That means, no VPNs,etc.
What would I need to do in order to configure the computers to see my domain?
I should put for example:
IP address
Subnet mask:
Gateway: my firewall's IP address (
DNS server: (my original Windows Domain machine)

Is this a proper setting?
Or do I need to assign an additional IP address to my Domain server machine on the other subnet as well.

I am a bit confused, I know there must be someone here that could clarify.
Thanks much,
  1. Using the settings you give as an example will not work. Your new computers won't be able to see the gateway as they will be on different subnets ( and - also written as and The easiest thing to do would be to change your subnet mask, everywhere, to That will cover the range - (or Otherwise you're going to have to use routing to enable the devices on the and subnets to talk to each other, which is unnecessarily complicated.
  2. Hi ijack,
    Thanks for the prompt answer.
    And if I add a secondary IP to the domain controller PC that will fall on the same subnet as will it work? if not I will go with your first option to switch all PCs (including all other VPN incoming connection from various sites) to subnet to allow subnets to talk to each other.
    Other than that there is nothing else I need to do so that computers can talk to each other right?
  3. You'd need to add a secondary IP address to the Firewall, as that's the gateway, and then set the appropriate gateway address depending upon which subnet a computer is on. Your computers need to be able to talk directly to the gateway, and they can only do that if it is on the same subnet as them. You'd also need to set up routing, on the gateway, between the and subnets if devices on these two subnets wanted to communicate. With the gateway having addresses on both subnets, and routing in place, there would be no need for two addresses on your DNS server.

    Changing the subnet mask everywhere to would be the simpler option. In fact if your addresses are given out by a DHCP server most of the work could be done automatically.
  4. Sorry in the above should have read!

    I do wish they'd sort out the problem with editing messages on these forums.
  5. Great, thanks so much for your help! it is much appreciated!

  6. Hi,

    I have a question. If a guest comes with the laptop and asks for an ip through dhcp (our company's current scenario), he will get the ip without any issue. What would be the best part in a security point of view? Also, 2 different subnetted clients should not talk to each other but should be able to talk to server only.

    Thanks & regards
    Tuhin Chakravorty.
