IP Subnet & CIDR Calculator

Comprehensive IPv4 subnetting utility: calculate network addresses, broadcast addresses, usable host ranges, wildcard masks, and binary bit masks with one click.

IPv4 Address & CIDR Prefix
Quick Presets:
Common CIDR Subnet Cheat Sheet
CIDRSubnet MaskTotal AddressesUsable HostsTypical Use Case
/32255.255.255.25511Single host / Loopback
/30255.255.255.25242Point-to-point router links
/28255.255.255.2401614Small office / DMZ segment
/24255.255.255.0256254Standard LAN / Wi-Fi network
/20255.255.240.04,0964,094Cloud VPC Subnet (AWS / GCP)
/16255.255.0.065,53665,534Enterprise Campus / Large VPC
/8255.0.0.016,777,21616,777,214Tier 1 ISP / National Carrier

Comprehensive Guide to IPv4 Subnetting & Network Architecture

Every device connected to an Internet Protocol version 4 (IPv4) network is assigned a 32-bit logical address, traditionally represented as four decimal octets separated by dots (e.g., 192.168.1.100). In binary, this represents a string of 32 ones and zeros.

An IP address is split into two logical segments: the Network Portion (which identifies the physical network segment where the device resides) and the Host Portion (which uniquely identifies the specific interface or computer on that network). The Subnet Mask acts as a binary stencil that informs routers and network cards exactly where the network portion ends and the host portion begins.

The Bitwise Mathematics Behind Subnet Calculation

Routers perform a fundamental Bitwise AND logic operation between the incoming destination IP address and the configured Subnet Mask to determine whether a packet should be delivered locally or forwarded to a default gateway:

Host IP (192.168.1.100):   11000000.10101000.00000001.01100100
Subnet Mask (/24):         11000000.10101000.00000001.00000000 (255.255.255.0)

Network Address:             11000000.10101000.00000001.00000000 (192.168.1.0)
Broadcast Address:           11000000.10101000.00000001.11111111 (192.168.1.255)

Because the host portion contains 8 bits, the total addresses are 2^8 = 256. Subtracting the network address and broadcast address leaves 254 usable host addresses (from 192.168.1.1 to 192.168.1.254).

Subnetting in Cloud Environments (AWS, Azure & Google Cloud)

Cloud infrastructure requires disciplined IP planning to ensure seamless peering between VPCs, Kubernetes clusters, and on-premises corporate datacenters:

AWS Reserved IPs

Always account for the 5 IP addresses AWS reserves in each subnet (e.g. in a /24 subnet with 256 total addresses, AWS only allows 251 usable EC2 instances).

Non-Overlapping CIDRs

Never use overlapping CIDR blocks across multiple VPCs or corporate VPNs. Once allocated, changing a VPC's primary CIDR range requires rebuilding the entire network.

Kubernetes Pod Sizing

In Amazon EKS (using AWS VPC CNI), every Kubernetes pod consumes a real VPC IP address from the node's subnet. A /24 subnet can easily be exhausted by a handful of nodes running many pods.

Comprehensive CIDR Subnet Reference Table

CIDRSubnet MaskTotal AddressesUsable HostsTypical Real-World Use Case
/32255.255.255.25511Single host route, VPN client address, Loopback interface
/30255.255.255.25242Legacy point-to-point router links
/28255.255.255.2401614Small office network segment, database DMZ cluster
/24255.255.255.0256254Standard office LAN, Wi-Fi hotspot subnet, AWS public subnet
/20255.255.240.04,0964,094Enterprise department VPC, large container cluster
/16255.255.0.065,53665,534Complete AWS VPC network root, corporate headquarters campus
/8255.0.0.016,777,21616,777,214Tier 1 Internet Service Provider (ISP), entire Class A block

Frequently Asked Questions

A subnet (subnetwork) is a logical, segmented subdivision of an IP network. Without subnetting, all network devices connected to an organization's network would inhabit a single enormous broadcast domain, leading to crippling broadcast storm traffic, severe network congestion, and security vulnerabilities. Subnetting enables network administrators to partition large IP address allocations into smaller, isolated subnets, improving network routing efficiency, security isolation, and address management.

CIDR stands for Classless Inter-Domain Routing (introduced in 1993 by RFC 1519). Before CIDR, IPv4 addresses were rigidly divided into Class A (/8), Class B (/16), and Class C (/24) blocks. This architecture caused immense address wastage (for example, allocating an entire Class B block of 65,536 addresses to an organization requiring only 500 hosts). CIDR replaced fixed classes with variable-length prefix notation (e.g., /23 or /27), allowing network architects to size subnets precisely according to host requirements.

In standard IPv4 subnets, the lowest numerical address (where all host bits are binary 0) is reserved as the Network Address, which identifies the entire subnet to external routers in their routing tables. The highest numerical address (where all host bits are binary 1) is reserved as the Broadcast Address, used to deliver packets simultaneously to all active network interfaces within that subnet. Therefore, the formula for usable host addresses is always 2^(32 - prefix) - 2.

Under RFC 3021, a /31 subnet prefix (which provides only 2 total addresses) is permitted on point-to-point links between two routers without allocating separate network and broadcast addresses, making both IPs usable. A /32 prefix represents a single specific host address with zero host bits, commonly used for loopback interfaces, VPN client assignments, and precise firewall access control list (ACL) rules.

The Internet Engineering Task Force (IETF) reserved three dedicated IPv4 address blocks for private enterprise and home networks in RFC 1918: 10.0.0.0/8 (10.0.0.0 to 10.255.255.255), 172.16.0.0/12 (172.16.0.0 to 172.31.255.255), and 192.168.0.0/16 (192.168.0.0 to 192.168.255.255). These addresses are guaranteed not to be routed on the public internet, allowing millions of private networks to reuse the same address space behind Network Address Translation (NAT) gateways.

A wildcard mask is the exact bitwise inverse of a subnet mask (calculated by subtracting each octet from 255). For example, a subnet mask of 255.255.255.0 has a wildcard mask of 0.0.0.255. In networking hardware (notably Cisco IOS routers, OSPF configurations, and Access Control Lists), a 0 bit signifies 'must match exactly', while a 1 bit signifies 'ignore / match any value'.

AWS reserves 5 IP addresses in every VPC subnet: the network address (first IP), the VPC router gateway (.1), the DNS server (.2), a future use address (.3), and the broadcast address (last IP). When designing AWS VPCs, choose a /16 block (such as 10.0.0.0/16) for the main VPC, and divide it into /20 or /24 subnets distributed across multiple Availability Zones (AZs) for public and private application tiers.

IPv4 uses 32-bit addresses written in dotted decimal format (totaling approximately 4.29 billion possible addresses), necessitating careful subnetting and NAT. IPv6 uses 128-bit addresses written in hexadecimal notation (providing 340 undecillion addresses). In IPv6, standard end-user subnets are almost universally assigned a /64 prefix, which contains 18 quintillion addresses in a single local segment, completely eliminating the need for NAT.

Explore Related Tools

Hand-picked utilities and calculators related to this tool.

Developer Tools