August 9, 2026
CIDR and subnetting, explained: prefixes, netmasks and VLSM
Take apart any firewall rule, routing table entry, cloud security group or DNS allow-list, and you will find the same kind of string inside: 192.168.1.0/24, 10.0.0.0/8, 172.19.87.203/18. That notation is CIDR — Classless Inter-Domain Routing — and it is the language networks speak when they mean “a block of IP addresses”. Reading it fluently is a core skill for anyone who touches infrastructure: it tells you which traffic a rule actually matches, whether two hosts sit in the same subnet, and how much room a network has left to grow.
This guide builds that skill from the ground up: what the number after the slash means, how to convert between prefix lengths and netmasks, how to find the network and broadcast addresses by hand, and how to carve one address block into right-sized subnets using VLSM. Every example in this article can be checked live in the CIDR calculator — it runs entirely in your browser, so you can paste your real addresses into it and compare the results against the manual arithmetic done here.
What the number after the slash actually means#
An IPv4 address is 32 bits, written as four 8-bit octets. 192.168.1.130 is really this:
11000000 . 10101000 . 00000001 . 10000010
192 . 168 . 1 . 130
CIDR notation a.b.c.d/n says: the first n bits are the fixed network part, and the remaining 32 − n bits are free host bits that identify individual addresses inside the block. A /24 pins the first 24 bits — the 192.168.1 part — and leaves the last octet free, which gives exactly 2^8 = 256 addresses: the classic home-network range. A /25 pins one more bit, halving the block to 128 addresses. Every step of the prefix either doubles or halves the block, nothing in between.
The notation exists because the system it replaced was rigid. The original “classful” addressing of the 1980s handed out blocks in exactly three sizes: class A (16,777,214 usable hosts), class B (65,534) and class C (254). An organization needing 300 addresses had to take a class B and strand 65,000 of them. CIDR, standardized in RFC 1519 in 1993, replaced the three fixed sizes with a single rule — any power-of-two block, on a power-of-two boundary — and almost certainly saved the IPv4 address space from exhausting years earlier than it did.
One detail that trips people up: the address before the slash does not have to be the block’s base address. 192.168.1.130/24 is perfectly valid notation for “host .130 inside the block whose base is 192.168.1.0”. The network address is derived by masking, not by reading what you typed. Firewalls and routers conventionally show the base address in their configs, but any address in the block describes the same block once the prefix is applied.
Prefix, netmask, wildcard: three dialects, one meaning#
You will meet the same subnet written three different ways, depending on which system you are configuring.
The netmask writes the prefix as a dotted quad: n one-bits followed by 32 − n zero-bits. A /18 mask is 11111111.11111111.11000000.00000000, which reads 255.255.192.0. Because of this structure, only nine values can ever appear in a mask octet — 0, 128, 192, 224, 240, 248, 252, 254, 255 — and the pattern is always “ones from the left”. If someone shows you a mask like 255.0.255.0, it is not a legal netmask.
The wildcard mask (or inverse mask) is the bitwise NOT of the netmask: 0.0.63.255 for a /18. Cisco-style access lists use it — permit ip any 192.168.1.0 0.0.0.255 means “the 256 addresses whose first 24 bits match 192.168.1”. One-bits in a wildcard mean “this bit can be anything”.
The prefix length /n is the modern shorthand, and the only form that scales cleanly to IPv6.
A quick conversion trick for reading masks in your head: in the last non-zero octet of the mask, 256 − mask value is the block size in that octet. 255.255.255.192 → 256 − 192 = 64, so the subnet steps through .0, .64, .128, .192. 255.255.240.0 → 256 − 240 = 16, so the third octet steps through 0, 16, 32, 48 and so on. That single trick lets you list every possible network of a given mask inside a larger block.
The reference table worth internalizing:
Prefix Netmask Addresses Usable hosts
/30 255.255.255.252 4 2
/29 255.255.255.248 8 6
/28 255.255.255.240 16 14
/27 255.255.255.224 32 30
/26 255.255.255.192 64 62
/25 255.255.255.128 128 126
/24 255.255.255.0 256 254
/23 255.255.254.0 512 510
/22 255.255.252.0 1,024 1,022
/20 255.255.240.0 4,096 4,094
/16 255.255.0.0 65,536 65,534
Network address, broadcast, and the minus-two rule#
Two addresses in every IPv4 subnet are reserved, and everything else about subnet arithmetic follows from them.
The network address is address AND netmask — the host bits forced to zero. It names the subnet itself. The broadcast address is the network address with every host bit forced to one (network OR wildcard); traffic sent to it reaches all hosts in the subnet. Because those two are taken, the number of addresses you can actually assign to interfaces is 2^(32−n) − 2 for every prefix from /1 through /30.
Two exceptions exist at the small end. A /32 is a single address — one host, nothing reserved, which is why routing tables carry /32 host routes. A /31 contains two addresses, and under the old rule that would leave zero usable; RFC 3021 redefined /31 for point-to-point links between exactly two routers, where a broadcast is meaningless — both addresses are usable and none is reserved. Modern gear implements this, though equipment from before about 2000 may not.
Worked example: reading a /18 the way a router does#
Let us compute a real subnet entirely by hand, then verify it. Take 172.19.87.203/18.
Step one, the mask. /18 means 18 one-bits: the first two octets are fully masked (255.255), the third octet gets its top two bits masked (11000000 = 192), the fourth is free. Netmask 255.255.192.0; wildcard 0.0.63.255.
Step two, the network address. Only the third octet has both fixed and free bits, so focus there. 87 is 01010111 in binary; the mask octet is 11000000. AND them bit by bit: 01010111 AND 11000000 = 01010000, which is 64. So the network address is 172.19.64.0 — the block does not start at .87, it starts at .64, because 64 is the largest multiple of the block size (64) that fits under 87.
Step three, the far end. The host part spans the lower 6 bits of the third octet and all of the fourth. Setting every host bit to one gives third octet 64 + 63 = 127 and fourth octet 255: broadcast 172.19.127.255. The assignable range is everything between: first host 172.19.64.1, last host 172.19.127.254.
Step four, the counts. Total addresses 2^(32−18) = 2^14 = 16,384; usable 16,384 − 2 = 16,382. The full picture:
Network: 172.19.64.0
Netmask: 255.255.192.0
Wildcard: 0.0.63.255
Broadcast: 172.19.127.255
First host: 172.19.64.1
Last host: 172.19.127.254
Total: 16,384
Usable: 16,382
Also worth noting: 172.19.0.0 through 172.31.255.255 falls inside the private range 172.16.0.0/12 reserved by RFC 1918, so this block is not routable on the public internet — exactly the kind of detail worth confirming before you publish a service on it.
Try it live with the CIDR calculator#
The CIDR calculator turns everything above into a one-field check, and it is worth running each example through it while you read:
- Open the tool and paste
172.19.87.203/18into the input. The result panel fills in as you type and should match the block above field for field — network, netmask, wildcard, broadcast, first and last host, total and usable counts, plus the legacy class, IP version and a private/public scope flag. - Reload the default sample
192.168.1.130/24and notice what we discussed earlier: the address you typed (.130) is a host inside the block, while the Network field shows the derived base192.168.1.0. The tool masked the host bits off; it did not “fix” your input. - Type
10.0.0.0/31and watch the usable count come back as 2, not 0 — the calculator follows RFC 3021 for point-to-point links rather than blindly applying the minus-two rule. - Type
10.1.2.3/32to see the single-host case: total 1, usable 1, no broadcast reserved. - Try
2001:db8::/64for the IPv6 side — the address count (2^64= 18,446,744,073,709,551,616) is computed exactly, because the math runs on arbitrary-precision integers rather than floating point.
Because everything is computed locally in the page, pasting the real addresses from your own network into it leaks nothing anywhere.
VLSM: carving a /24 into right-sized subnets#
Real networks rarely need one giant flat subnet. Variable Length Subnet Masking (VLSM) lets different segments take different prefix lengths out of the same parent block, which is the whole point of having abandoned classful sizing.
The sizing rule: a segment that must hold N hosts needs the smallest prefix k such that 2^k − 2 ≥ N. Then you allocate, largest block first, from the bottom of the parent range upward.
Worked scenario: you are given 192.168.10.0/24 and need three LANs — 100 hosts, 50 hosts, 25 hosts — plus two router-to-router links (2 hosts each).
- LAN A, 100 hosts:
2^7 − 2 = 126 ≥ 100→ 7 host bits →/25→192.168.10.0/25, hosts.1–.126, broadcast.127. - LAN B, 50 hosts:
2^6 − 2 = 62 ≥ 50→/26→192.168.10.128/26, hosts.129–.190, broadcast.191. - LAN C, 25 hosts:
2^5 − 2 = 30 ≥ 25→/27→192.168.10.192/27, hosts.193–.222, broadcast.223. - Link 1:
/30→192.168.10.224/30, hosts.225–.226. - Link 2:
/30→192.168.10.228/30, hosts.229–.230.
Segment Need Prefix Subnet Usable Range
LAN A 100 /25 192.168.10.0/25 126 .1 – .126
LAN B 50 /26 192.168.10.128/26 62 .129 – .190
LAN C 25 /27 192.168.10.192/27 30 .193 – .222
Link 1 2 /30 192.168.10.224/30 2 .225 – .226
Link 2 2 /30 192.168.10.228/30 2 .229 – .230
leftover — 3 × /29 192.168.10.232 – .255 24 free
Everything fits into the /24 with 24 addresses still spare. The largest-first order is not a style preference — it is what keeps the blocks aligned. A /25 may only start on a multiple of 128 within its parent, a /26 on a multiple of 64, a /27 on a multiple of 32. If you allocated LAN C’s /27 first at .0–.31, the /25 for LAN A could not start until .128, splitting the range into fragments too small for the remaining segments. Largest first, lowest address first, and alignment takes care of itself.
The last piece of day-to-day subnetting is the membership question: which segment does this address belong to? Take 192.168.10.200. AND it with the /27 mask 255.255.255.224: 200 AND 224 = 192, so it falls in 192.168.10.192/27 — LAN C. Type 192.168.10.200/27 into the calculator and it will show exactly that network, first host .193, last host .222.
IPv6: the same idea, bigger numbers#
Everything above transfers to IPv6 with the prefix range extended to /128. What changes is convention, not arithmetic. A /64 is the standard LAN size on IPv6 — enormous by IPv4 standards (2^64 addresses), chosen so that stateless autoconfiguration has a full interface identifier to work with. A typical site receives a /48 from its provider and can therefore run 65,536 separate /64 networks without ever asking for more.
Two simplifications make IPv6 subnets easier: there is no broadcast address, and there are no legacy classes — so there is no minus-two rule, and the usable count equals the total. A quick engineering note if you ever implement these calculations yourself: JavaScript’s ordinary Number type silently corrupts integers beyond 2^53, which IPv6 address math exceeds immediately; exact results require arbitrary-precision integers. (This is why the calculator on this site does all its IPv6 arithmetic on BigInt.)
Address compression follows RFC 5952: the longest run of zero groups collapses to ::, hex letters are lowercase, leading zeros are dropped. 2001:0db8:0000:0000:0000:0000:0000:0001 becomes 2001:db8::1 — the canonical form firewalls and routers expect to see.
FAQ#
Why does a /24 give 254 usable hosts and not 256?#
256 addresses exist, but two are reserved in every IPv4 subnet from /1 to /30: the network address (all host bits zero) names the subnet itself, and the broadcast address (all host bits one) reaches every host at once. 256 − 2 = 254. The only exceptions are /31 (RFC 3021 point-to-point: both addresses usable) and /32 (a single host: one address, nothing to reserve).
The IP I typed is different from the network address shown. Which one is right?#
Both are, and they describe different things. 192.168.1.130/24 names the host .130 inside a block; the block’s network address is 192.168.1.0, derived by masking the host bits off. If you actually meant a block starting at .128, the notation you want is 192.168.1.128/25. Tools that show you both are doing exactly the right thing.
A /31 looks like it has zero usable hosts. What is it for?#
Under the minus-two rule it would be useless — which is why RFC 3021 exists. On a point-to-point link connecting exactly two routers, there is nobody to broadcast to, so both addresses are assignable and no broadcast is reserved. /31 links are standard practice for router interconnections in modern networks. Only gear predating roughly 2000 may insist on /30 links instead.
How do I pick a prefix for N hosts?#
Find the smallest k with 2^k − 2 ≥ N, and the prefix is 32 − k. For 50 hosts: 2^6 − 2 = 62 ≥ 50 while 2^5 − 2 = 30 is too small, so k = 6 and the prefix is /26. Then add headroom — a segment at 100% utilization cannot take one more device, a fact always discovered at the worst moment. Design to at most half-full if the address space allows it, and remember the two reserved addresses when you size IPv4 segments.
Where to go next#
- Run every example in this guide through the CIDR calculator — IPv4 and IPv6, full subnet breakdown, private-range detection, all computed locally in your browser.
- Masks are binary underneath; the radix converter is the fastest way to check octet arithmetic like
87 AND 192in decimal, binary and hex side by side.