Tools
Guides

CIDR / IP Subnet Calculator

Convert

Compute network address, broadcast, netmask, host ranges and class for IPv4/IPv6 CIDR blocks using BigInt.

100% client-side No backend
Network address
Netmask
Wildcard
Broadcast
First host
Last host
Total addresses
Usable hosts
IP class
IP version
Scope
On this page

What is CIDR?#

CIDR — Classless Inter-Domain Routing — is the a.b.c.d/n notation used to describe a block of IP addresses. The number after the slash is the prefix length: how many leading bits stay fixed while the remaining bits identify individual hosts inside the block. 192.168.1.0/24 fixes the first 24 bits (the 192.168.1 part) and leaves the last octet free, which gives exactly 256 addresses — the classic home-network range.

CIDR exists because the older “class A / B / C” system handed out address blocks in only three rigid sizes, wasting huge amounts of space. CIDR lets you carve an address space into blocks of any power-of-two size (a /23, a /27, a /29…) so address space is not wasted. The same notation is also how you write firewall allow-lists, routing table entries, cloud security groups, and DNS ACLs.

This page parses a CIDR (or a bare address) and shows you the full subnet breakdown: network address, broadcast, netmask, wildcard, first and last usable host, total and usable host counts, the legacy IP class, the IP version, and whether the address falls in a private (RFC 1918 / ULA) range. Both IPv4 and IPv6 are supported, with full 128-bit precision via BigInt — a plain JavaScript Number would silently corrupt IPv6 math past 2^53.

How to use it#

  1. Type a CIDR or address into the Input field. The page boots with 192.168.1.130/24 as a sample; replace it with your own. A bare address is treated as /32 for IPv4 or /128 for IPv6.
  2. The result panel fills in as you type. The fields are: Network (the subnet’s base address, host bits zeroed), Netmask (the mask implied by the prefix), Wildcard (IPv4 only — the bitwise NOT of the netmask, used in Cisco-style ACLs), Broadcast (IPv4 only; IPv6 has none), First host and Last host (the assignable range), Total addresses, Usable hosts, Class (legacy A/B/C/D/E), Version, and Scope (Private or Public).
  3. Click Sample to reload the default example, or Clear to empty the field.

Key features#

  • Full IPv6 precision. Every calculation runs in BigInt, so a /48 or /64 IPv6 block — whose address counts run into the quintillions — is exact, not a floating-point approximation.
  • Correct host counts, including edge prefixes. /31 is treated as the RFC 3021 point-to-point pair (2 usable, no reserved broadcast); /32 is a single host; /30 correctly yields 2 usable. The page does not blindly apply 2^(32-p) - 2 to every prefix.
  • RFC 1918 and ULA detection. Private ranges (10/8, 172.16/12, 192.168/16 for IPv4; fc00::/7, fe80::/10, ::1 for IPv6) are flagged in the Scope field, so you can tell at a glance whether a block is routable on the public internet.
  • Wildcard mask. Helpful when you are writing permit ip any 192.168.1.0 0.0.0.255-style rules, where the mask is inverted relative to the netmask.
  • IPv6 compressed per RFC 5952. Output addresses collapse the longest zero run to ::, in lowercase, with no leading zeros — the canonical form firewalls and routers expect.
  • IPv4-mapped IPv6. Inputs like ::ffff:192.168.1.1 parse correctly and are normalized.

Worked example#

With the default 192.168.1.130/24:

Network:     192.168.1.0
Netmask:     255.255.255.0
Wildcard:    0.0.0.255
Broadcast:   192.168.1.255
First host:  192.168.1.1
Last host:   192.168.1.254
Total:       256
Usable:      254
Class:       C
Version:     IPv4
Scope:       Private

Notice that the address you typed — 192.168.1.130 — is a host inside the block, not the network address. The network address is the result of masking the host bits off. The 254 usable count is 256 total − 1 network − 1 broadcast; that is why a /24 is often loosely called “254 usable hosts”.

For a point-to-point link, switch to /31:

Input:       10.0.0.0/31
Usable:      2          (RFC 3021: both addresses usable, no reserved broadcast)
First host:  10.0.0.0
Last host:   10.0.0.1

For IPv6, try 2001:db8::/64 — the standard LAN subnet size:

Network:  2001:db8::
Total:    18446744073709551616   (2^64 — every address in the block is usable; IPv6 has no broadcast)
Scope:    Public

FAQ#

Why does a /24 give 254 usable hosts and not 256?#

Two addresses in every IPv4 subnet (except /31 and /32) are reserved: the network address (all host bits zero) identifies the subnet itself, and the broadcast address (all host bits one) reaches every host in the subnet at once. So a /24 has 2^8 = 256 addresses but only 256 − 2 = 254 you can assign to interfaces.

What is a /31 used for? It looks like it has no usable hosts.#

Under the old rule a /31 would have 2 − 2 = 0 usable hosts, making it useless. RFC 3021 redefined /31 for point-to-point links (the kind that connect two routers directly): both addresses are usable and there is no reserved broadcast. This page follows RFC 3021, so /31 shows 2 usable. Gear that predates 2000 may still expect the old behaviour.

Can it handle IPv6?#

Yes, fully. IPv6 prefixes go up to /128 (a single address) and the address math runs on BigInt, so even a /48 or /32 provider block is exact. Note that IPv6 has no broadcast address and no legacy class — every address in a block is usable, so the Usable count equals the Total count. The Scope field still flags ULA (fc00::/7) and link-local (fe80::/10) ranges as private.

Why does the tool show a different network address than the IP I typed?#

Because your IP is a host inside the block, not the block’s base address. The network address is your_ip AND netmask, which zeroes out the host bits. Typing 192.168.1.130/24 describes “the host .130 inside 192.168.1.0/24” — the /24 block itself starts at .0. If you actually meant a block starting at .128, write 192.168.1.128/25.

Why is my address marked “Private”?#

It falls inside one of the ranges reserved for internal use and not routed on the public internet: IPv4 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, or IPv6 fc00::/7 (unique local) and fe80::/10 (link-local). Traffic from these ranges cannot reach the internet without NAT or a tunnel. If you are configuring a cloud security group or a public-facing service, you almost always want a public address instead.