Subnetting and CIDR explained without the headache

8 min read
networking

CIDR notation looks cryptic until you separate the two things it is actually encoding: an address, and how many of its bits are fixed.

What the slash means

192.168.1.0/24 means the first 24 bits of the 32-bit IPv4 address are the fixed network portion, and the remaining 8 bits identify hosts within that network. More bits after the slash means a smaller network; fewer bits means a bigger one.

  • /32 — a single host, no room for anything else.
  • /24 — 256 addresses, the classic "Class C"-sized network.
  • /16 — 65,536 addresses.
  • /8 — 16.7 million addresses.

Converting the prefix to a subnet mask

Each bit in the prefix becomes a 1 in the subnet mask, grouped into four octets:

PrefixMask
/24255.255.255.0
/25255.255.255.128
/26255.255.255.192
/28255.255.255.240

The pattern within an octet follows powers of two counted from the left: 128, 192, 224, 240, 248, 252, 254, 255 for one through eight bits set.

Counting usable hosts

Total addresses in a subnet = 2^(32 - prefix). Two of those are reserved — the network address (all host bits zero) and the broadcast address (all host bits one) — so usable hosts = 2^(32 - prefix) - 2.

A /26 gives 2^6 = 64 total addresses, so 62 usable hosts. A /30 gives 4 total, 2 usable — exactly enough for a point-to-point link between two routers, which is why /30 (and /31, using a special rule that allows both addresses) shows up constantly in WAN configuration.

Finding the network and broadcast address

Given 10.20.30.77/27, a /27 has 5 host bits (32-27), meaning subnets are 32 addresses apart (2^5). 30 falls in the range starting at 0, 32, 64... — the third octet stays 30, and within the last octet the block boundaries are every 32: 64-95 covers 77. So:

  • Network address: 10.20.30.64
  • Broadcast address: 10.20.30.95
  • Usable range: 10.20.30.6510.20.30.94

Why subnetting exists at all

Splitting a large allocation into smaller subnets lets you route traffic between segments, apply different firewall rules per segment, and avoid wasting an entire /24 on a network that only needs a dozen hosts. A cloud VPC is almost always subdivided this way — a /16 VPC split into /24 subnets per availability zone is a common pattern.

Private ranges worth memorizing

  • 10.0.0.0/8 — large private networks.
  • 172.16.0.0/12 — medium private networks, often used by Docker.
  • 192.168.0.0/16 — small/home networks.
  • 127.0.0.0/8 — loopback.
  • 169.254.0.0/16 — link-local, assigned automatically when DHCP fails.

Reading CIDR in firewall rules and security groups

0.0.0.0/0 means "any IPv4 address" — a prefix of zero fixes no bits at all. Seeing this in an inbound security group rule for anything other than a public web server (ports 80/443) is almost always a misconfiguration worth double-checking.

The mental shortcut

You rarely need to compute this by hand under pressure — the useful skill is reading a /24 and immediately knowing "256 addresses, last octet is the host part" without reaching for a calculator, and reaching for one anyway when the prefix does not land on an octet boundary.

Tools from this article

Comments

No login needed. Comments appear after a quick review.

Protected by an on-site captcha — no third-party trackers.

Optional: get an alert when your comment is published or replied to, plus new tool announcements. No sign-up.

Loading comments…

← All articles