hasibai

Tech & everyday

Subnet calculator (IPv4)

Give it an address and a prefix and it will give you the network, the broadcast, the usable range and the mask in every form you might need to type into something.

Address only, or CIDR notation like 10.0.0.0/16 — both work.

Subnet
Enter an IPv4 address and prefix length.

What the prefix actually means

An IPv4 address is 32 bits. The prefix length says how many of those bits identify the network; the rest identify the host within it. A /24 fixes the first 24 bits, leaving 8 for hosts, which is 256 addresses.

Total addresses = 2(32 − prefix)    Usable hosts = that − 2

The subtraction of two is why a /24 gives 254 usable addresses rather than 256. The first address in the block is the network identifier and the last is the broadcast address, and neither can be assigned to a device.

The prefixes worth memorising

PrefixNetmaskAddressesUsable hosts
/30255.255.255.25242
/29255.255.255.24886
/28255.255.255.2401614
/27255.255.255.2243230
/26255.255.255.1926462
/25255.255.255.128128126
/24255.255.255.0256254
/16255.255.0.065,53665,534
/8255.0.0.016,777,21616,777,214

Every subnet boundary is a power of two, which is why networks always start on addresses divisible by the block size. A /26 can begin at .0, .64, .128 or .192 and nowhere else. Trying to define a subnet starting at .100 is not a configuration you can make work; it is a misunderstanding of what the mask does.

Wildcard masks and where they appear

A wildcard mask is the bitwise inverse of a netmask. Cisco access control lists and OSPF configuration use them, and mixing the two up is one of the most common causes of an ACL that silently does nothing. A /24 has a netmask of 255.255.255.0 and a wildcard of 0.0.0.255.

Private ranges and the /31 exception

Three ranges are reserved by RFC 1918 for private use and are never routed on the public internet: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Two more you will see are 169.254.0.0/16, which a device self-assigns when DHCP fails, and 100.64.0.0/10, reserved for carrier-grade NAT.

One useful special case: RFC 3021 permits /31 networks on point-to-point links, where both addresses are usable because there is no need for a broadcast address with exactly two devices. Before it, engineers used /30 and wasted half of every link subnet.

Common questions

How many hosts are in a /24?

Two hundred and fifty-four. The block holds 256 addresses, but the first is the network address and the last is the broadcast address, leaving 254 assignable to devices. The same subtraction applies to every prefix from /0 to /30.

What is the difference between a netmask and a wildcard mask?

They are bitwise inverses. A /24 netmask is 255.255.255.0 and the matching wildcard is 0.0.0.255. Netmasks appear in interface configuration; wildcard masks appear in Cisco access lists and OSPF network statements. Using one where the other belongs is a classic source of rules that match nothing.

Why can I not start a subnet at any address?

Because the mask works on bits, not decimals. A subnet boundary must fall where the host bits are all zero, which means networks start at multiples of the block size. A /26 with 64 addresses can only begin at .0, .64, .128 or .192.

What is a /31 used for?

Point-to-point links between routers. RFC 3021 allows both addresses in a /31 to be assigned, since a link with exactly two endpoints has no use for a broadcast address. It halves the address consumption compared with the /30 that was previously required.