Subnetting, step by step

By the end of this page you will be able to find the network, broadcast address and host range of any IPv4 subnet by hand, split a network into equal subnets, and plan a VLSM design. Every worked example opens in the calculator so you can check your answer.

01Binary and the 32-bit address

An IPv4 address is a 32-bit number. Routers and hosts work with those 32 bits. The dotted form 192.168.1.37 exists for people. Subnetting is the skill of moving between the two forms and reading meaning from the bits, so it starts with binary.

Bits and octets

A bit is a 0 or a 1. The 32 bits of an address are split into four groups of eight, called octets. Each octet is written as a decimal number and the four are joined with dots. Eight bits give 28 = 256 combinations, so an octet runs from 0 to 255. Thirty-two bits give 232 = 4,294,967,296 possible addresses.

Place values

Inside an octet, each bit position has a fixed value. From left to right:

128  64  32  16   8   4   2   1

Each value is twice the one to its right. The value of an octet is the sum of the positions that hold a 1. 11000000 is 128 + 64 = 192. 11111111 is 255 and 00000000 is 0.

Decimal to binary

Work from left to right. At each position, ask whether the place value fits into what is left. If it fits, write 1 and subtract it. If not, write 0. Here is the last octet of 192.168.1.37:

left  place  fits?  bit
 37    128    no     0
 37     64    no     0
 37     32    yes    1    37 − 32 = 5
  5     16    no     0
  5      8    no     0
  5      4    yes    1     5 − 4 = 1
  1      2    no     0
  1      1    yes    1     1 − 1 = 0

Reading the bit column from top to bottom gives 00100101. The other octets follow the same way: 192 = 128 + 64, 168 = 128 + 32 + 8, and 1 = 1. The whole address:

     192       168         1        37
11000000  10101000  00000001  00100101

Binary to decimal

Reverse the process. Write the place values over the bits and add the values that sit over a 1:

128  64  32  16   8   4   2   1
  1   0   1   0   1   0   0   0    128 + 32 + 8 = 168

Learn the values of octets that are a run of 1s from the left: 128, 192, 224, 240, 248, 252, 254 and 255. They are the only values a netmask octet can take, and the next section depends on them.

The calculator shows any address bit by bit. Select a bit to see its place value: 192.168.1.37/24.

02Netmask and prefix length

An address alone does not say which network it belongs to. A second 32-bit value, the netmask, does. Each 1 in the mask marks a network bit of the address. Each 0 marks a host bit. The 1s always come first, in one unbroken run, and the 0s fill the rest.

Prefix length

Because the 1s are contiguous, counting them is enough to describe the mask. That count is the prefix length, written after a slash. /24 means 24 ones followed by 8 zeros:

/20   11111111.11111111.11110000.00000000   255.255.240.0
/24   11111111.11111111.11111111.00000000   255.255.255.0
/26   11111111.11111111.11111111.11000000   255.255.255.192

This notation is CIDR, Classless Inter-Domain Routing, described in RFC 4632. It replaced the old class system, in which the first bits of an address fixed its mask: /8 for class A, /16 for class B, /24 for class C. Today any prefix from /0 to /32 is valid, and the class of an address tells you nothing about its mask.

Converting between mask and prefix

A mask octet has its 1s on the left, so it can take only nine values:

1 bitsBinaryOctet value
0000000000
110000000128
211000000192
311100000224
411110000240
511111000248
611111100252
711111110254
811111111255

Mask to prefix: count 8 for each 255, then add the 1 bits of the next octet from the table. 255.255.240.0 is 8 + 8 + 4 = /20. Prefix to mask: write 255 for each full group of 8 bits, then look up the remainder. /26 is 24 + 2, so the mask is three 255s followed by 192: 255.255.255.192.

The AND operation

A host or router finds the network of an address with a bitwise AND of the address and the mask. AND returns 1 only when both input bits are 1. Where the mask has a 1, the address bit passes through. Where the mask has a 0, the result is 0. The network bits survive and the host bits are cleared:

Address  11000000.10101000.00000001.00100101   192.168.1.37
Mask     11111111.11111111.11111111.11000000   255.255.255.192
AND      11000000.10101000.00000001.00000000   192.168.1.0

In decimal, a 255 octet copies the address octet unchanged and a 0 octet gives 0. Only an octet with another mask value needs binary. Here that is the fourth: 37 AND 192, or 00100101 AND 11000000, which is 00000000. The network is 192.168.1.0. Check it in the calculator: 192.168.1.37 255.255.255.192.

The wildcard mask

A wildcard mask is the netmask with every bit inverted. Per octet, it is 255 minus the mask octet. The wildcard for 255.255.255.192 is 0.0.0.63.

Cisco IOS uses wildcards in access control lists (ACLs) and in OSPF network statements. A 0 bit means "this bit must match" and a 1 bit means "ignore this bit". To match every address in 192.168.1.0/26:

access-list 10 permit 192.168.1.0 0.0.0.63

router ospf 1
 network 192.168.1.0 0.0.0.63 area 0

The calculator accepts a wildcard as input and works out the prefix. 192.168.1.0 0.0.0.63 gives 192.168.1.0/26.

03Network, broadcast and host range

Once you know which bits are host bits, three facts about the subnet follow.

  • Network address: every host bit set to 0. It names the subnet and appears in routing tables. It is not assigned to a device.
  • Broadcast address: every host bit set to 1. A packet sent to it reaches every host on the subnet. It is not assigned to a device either.
  • Host range: everything in between. The first usable host is the network address plus one. The last usable host is the broadcast address minus one.

For 192.168.1.37/26 the last six bits are host bits:

Network     11000000.10101000.00000001.00000000   192.168.1.0
First host  11000000.10101000.00000001.00000001   192.168.1.1
Last host   11000000.10101000.00000001.00111110   192.168.1.62
Broadcast   11000000.10101000.00000001.00111111   192.168.1.63

The network bits are the same on every line. Only the host bits change. The address 192.168.1.37 itself is one of the hosts in this range.

Counting hosts

With h host bits a subnet has 2h addresses. Two of them are the network and broadcast addresses, so the number of usable hosts is 2h − 2. A /26 has 32 − 26 = 6 host bits, which gives 26 = 64 addresses and 62 usable hosts. Open the example: 192.168.1.37/26.

Each bit added to the prefix halves the size of the subnet:

PrefixNetmaskHost bitsAddressesUsable hosts
/24255.255.255.08256254
/25255.255.255.1287128126
/26255.255.255.19266462
/27255.255.255.22453230
/28255.255.255.24041614
/29255.255.255.248386
/30255.255.255.252242
/31255.255.255.254122
/32255.255.255.255011

The CIDR cheat sheet lists every prefix from /0 to /32.

The /31 and /32 exceptions

The formula breaks down at the small end. A /31 has one host bit and two addresses, and 21 − 2 would leave no hosts at all. RFC 3021 allows a /31 on point-to-point links. Both addresses are assigned, one to each end, and the subnet has no network or broadcast address. A link with only two devices has no need for a broadcast. In 10.0.0.0/31 the two hosts are 10.0.0.0 and 10.0.0.1.

A /32 has no host bits. It describes a single address. You see it on loopback interfaces, in host routes and in firewall rules that match one machine: 10.0.0.1/32.

04The block-size shortcut

Binary always works, but writing out 32 bits for every question is slow. The block-size method reaches the same answer with decimal arithmetic. It is fast enough for exam conditions and for checking a router config by eye.

The method

  1. Write the mask in dotted decimal.
  2. Find the interesting octet: the first octet whose mask value is less than 255. The boundary between network and host bits lies in this octet.
  3. Block size = 256 − the mask value in that octet. Subnets start at multiples of the block size in that octet.
  4. Find the largest multiple of the block size that is not greater than the address's value in that octet. That is the network value.
  5. Network address: octets to the left are copied from the address, the interesting octet takes the network value, and octets to the right are 0.
  6. Broadcast address: one less than the next network. The interesting octet is the network value + block size − 1, and octets to the right are 255.

This works because 256 minus a mask octet is always a power of two: 2 raised to the number of 0 bits in that octet. AND with the mask clears those low bits, which rounds the octet down to a multiple of that power of two.

Worked example: 172.16.40.9/20

  1. /20 is 8 + 8 + 4, so the mask is 255.255.240.0.
  2. The first octet below 255 is the third, with value 240.
  3. Block size = 256 − 240 = 16. Subnets start at third-octet values 0, 16, 32, 48, 64 and so on.
  4. The address has 40 in the third octet. The largest multiple of 16 that is not greater than 40 is 32.
  5. Network: 172.16.32.0.
  6. The next network is 172.16.48.0, so the broadcast is 172.16.47.255.

The host range is 172.16.32.1 to 172.16.47.254. The subnet covers sixteen values of the third octet, 32 to 47, each with a full 0 to 255 in the fourth. There are 32 − 20 = 12 host bits, so 212 − 2 = 4,094 usable hosts. The binary of the third octet confirms the network value:

Address   40   00101000
Mask     240   11110000
AND       32   00100000

Open the example: 172.16.40.9/20.

Worked example: 10.20.30.200/27

  1. /27 is 24 + 3, so the mask is 255.255.255.224.
  2. The interesting octet is the fourth, with value 224.
  3. Block size = 256 − 224 = 32. Subnets start at 0, 32, 64, 96, 128, 160, 192 and 224.
  4. The address has 200 in the fourth octet, which lies between 192 and 223. The network value is 192.
  5. Network: 10.20.30.192.
  6. Broadcast: 192 + 32 − 1 = 223, so 10.20.30.223.

Hosts run from 10.20.30.193 to 10.20.30.222, which is 25 − 2 = 30 usable addresses. Open it: 10.20.30.200/27.

When the prefix is a multiple of 8, the boundary falls between two octets and the interesting octet has mask value 0. The block size is then 256, the only multiple is 0, and the network keeps the leading octets and zeros the rest.

05Splitting a network into equal subnets

Subnetting in its original sense means dividing one network into smaller ones. You move the boundary to the right: some bits that were host bits become network bits. These are the borrowed bits, also called subnet bits. RFC 950 defined the idea in 1985.

Borrowing bits

Each borrowed bit doubles the number of subnets and halves the size of each one. Borrowing n bits gives 2n subnets. The new prefix is the old prefix plus n. Each subnet has 2h − 2 usable hosts, where h is the number of host bits left.

Choose n from the requirement you are given:

  • A number of subnets. Take the smallest n with 2n at least that number. Six subnets need n = 3, because 22 = 4 is too few and 23 = 8 is enough.
  • A number of hosts per subnet. Take the smallest h with 2h − 2 at least that number. Twenty-five hosts need h = 5, because 24 − 2 = 14 is too few and 25 − 2 = 30 is enough. The prefix is then 32 − h, here /27.

If both requirements are given, check that one choice satisfies both. A /24 cannot hold 10 subnets of 25 hosts: 10 subnets need a /28, which leaves only 14 hosts each.

Worked example: 192.168.10.0/24 into four /26

Four subnets need n = 2, because 22 = 4. The new prefix is 24 + 2 = /26 and the mask is 255.255.255.192. Six host bits remain, so each subnet has 64 addresses and 62 usable hosts. The two borrowed bits are the top two bits of the fourth octet, and their four combinations give the four subnets:

Parent     192.168.10.00000000   /24
Subnet 0   192.168.10.00000000   .0
Subnet 1   192.168.10.01000000   .64
Subnet 2   192.168.10.10000000   .128
Subnet 3   192.168.10.11000000   .192

The block-size method gives the same starts: 256 − 192 = 64, so the subnets begin at 0, 64, 128 and 192.

SubnetFirst hostLast hostBroadcast
192.168.10.0/26192.168.10.1192.168.10.62192.168.10.63
192.168.10.64/26192.168.10.65192.168.10.126192.168.10.127
192.168.10.128/26192.168.10.129192.168.10.190192.168.10.191
192.168.10.192/26192.168.10.193192.168.10.254192.168.10.255

Each broadcast address is one less than the next network address. The last subnet ends at 192.168.10.255, the broadcast address of the original /24, so nothing is left over.

Subnet zero and the all-ones subnet

RFC 950 said not to use the first subnet (borrowed bits all 0) or the last (borrowed bits all 1), because they could be confused with the parent network and its broadcast address. Older textbooks therefore count 2n − 2 subnets. That rule is obsolete. Classless routing protocols carry the prefix length with every route, so there is no ambiguity, and Cisco IOS has allowed subnet zero by default since release 12.0. Count 2n subnets unless a question says otherwise.

06VLSM: subnets of different sizes

Equal subnets waste space when needs differ. A sales floor with 120 hosts and a router link with 2 would get blocks of the same size. Variable Length Subnet Masking (VLSM) gives each subnet the prefix that fits its own host count. The parent is still divided into aligned blocks whose sizes are powers of two. They no longer have to be the same size.

Step 1: List the requirements

The example: you have 192.168.1.0/24 and need four subnets. Sales needs 120 hosts, Eng 50, Mgmt 10, and a point-to-point router link (P2P) needs 2. Count every interface that needs an address, including the router's own gateway address on each LAN.

Step 2: Turn host counts into block sizes

For each requirement, find the smallest h with 2h − 2 at least the host count. The prefix is 32 − h.

NameHosts neededHost bitsBlock sizeUsablePrefix
Sales1207128126/25
Eng5066462/26
Mgmt1041614/28
P2P2242/30

The blocks add up to 128 + 64 + 16 + 4 = 212 addresses, which fits in the 256 of a /24. If the total were larger than the parent, no arrangement would fit and you would need a larger parent block.

Step 3: Sort largest first

Every block must start on a multiple of its own size. A /26 can start at .0, .64, .128 or .192, but not at .16. If you place blocks from largest to smallest and pack each one directly after the previous one, every start address is aligned without extra work. Each block placed earlier is the same size or larger, so its size is a multiple of the current size, and so is their sum. No gaps appear, and the free space ends up in one run at the top of the parent.

In any other order you have to skip ahead to the next aligned address, which leaves holes between subnets. Ignoring alignment is worse. If Mgmt took 192.168.1.0/28 and Eng were written down as 192.168.1.16/26, the second entry would not be a subnet at all. The calculator shows that 192.168.1.16/26 is a host inside 192.168.1.0/26, which overlaps Mgmt.

Step 4: Place the blocks

Start at the parent's network address. Sales takes 192.168.1.0 to .127. Eng starts at the next address, .128, and ends at .191. Mgmt takes .192 to .207, and P2P takes .208 to .211.

NameSubnetHost rangeBroadcastUsableSpare
Sales192.168.1.0/25.1 – .126192.168.1.1271266
Eng192.168.1.128/26.129 – .190192.168.1.1916212
Mgmt192.168.1.192/28.193 – .206192.168.1.207144
P2P192.168.1.208/30.209 – .210192.168.1.21120

Spare is the number of usable addresses beyond what was requested. It leaves room for growth in each subnet.

Step 5: Record the free space

The plan uses 212 addresses, 192.168.1.0 to 192.168.1.211. The remaining 44 addresses, 192.168.1.212 to 192.168.1.255, do not form one valid block, because 44 is not a power of two. Written as aligned CIDR blocks they are 192.168.1.212/30, 192.168.1.216/29 and 192.168.1.224/27. Keep this list with the plan. A later request for up to 30 hosts fits in the /27.

Open the whole design in the VLSM planner: 192.168.1.0/24 Sales:120,Eng:50,Mgmt:10,P2P:2.

The /31 option for router links

With RFC 3021, the P2P link can use a /31 instead of a /30. It gets 192.168.1.208/31, with both .208 and .209 assigned to the two routers. The plan then uses 210 addresses and leaves 46 free: 192.168.1.210/31, 192.168.1.212/30, 192.168.1.216/29 and 192.168.1.224/27. Use /31 only on links with exactly two devices, and check that both ends support it. Open this version: 192.168.1.0/24 with /31 links.

07Private and special ranges

Not every address is meant for the public Internet. Several blocks are reserved for particular uses, and you will meet them in almost every network.

RFC 1918 private ranges

RFC 1918 sets aside three blocks for private networks. Any organization can use them internally without asking a registry. They are not routed on the public Internet, so traffic from them to the Internet passes through network address translation (NAT).

BlockRangeAddresses
10.0.0.0/810.0.0.0 – 10.255.255.25516,777,216
172.16.0.0/12172.16.0.0 – 172.31.255.2551,048,576
192.168.0.0/16192.168.0.0 – 192.168.255.25565,536

The middle block is the one people get wrong. A /12 mask is 255.240.0.0, so the block size in the second octet is 256 − 240 = 16, and the range runs from 172.16 to 172.31. An address such as 172.32.0.1 is outside it and is not private.

Other special blocks

BlockNameUseDefined in
100.64.0.0/10Shared address spaceBetween an ISP's carrier-grade NAT and customer equipment. Not a substitute for RFC 1918 space.RFC 6598
127.0.0.0/8LoopbackTraffic to these addresses stays inside the host. 127.0.0.1 is the usual one.RFC 1122
169.254.0.0/16Link-localA host that gets no address from DHCP may assign itself one from this block. Windows calls this APIPA. Not routed.RFC 3927
192.0.2.0/24TEST-NET-1Documentation and examplesRFC 5737
198.51.100.0/24TEST-NET-2Documentation and examplesRFC 5737
203.0.113.0/24TEST-NET-3Documentation and examplesRFC 5737

The three documentation blocks exist for books, manuals and network diagrams. They are never assigned to real networks, so an example that uses them cannot clash with anyone's production addresses. Use them in your own documentation and lab write-ups. The calculator names the special block an address belongs to whenever you enter one.

08Practice questions

Work each question on paper first, using binary or the block-size method. Then open the answer and check it in the calculator.

What are the network address, broadcast address and host range of 10.1.5.130/25?

The mask is 255.255.255.128. The interesting octet is the fourth, and the block size is 256 − 128 = 128, so subnets start at 0 and 128. 130 falls in the second block.

Network 10.1.5.128, broadcast 10.1.5.255, hosts 10.1.5.129 to 10.1.5.254. That is 27 − 2 = 126 usable hosts. 10.1.5.130/25

Which subnet does 172.20.99.14/19 belong to, and how many hosts does it hold?

/19 is 8 + 8 + 3, so the mask is 255.255.224.0. The interesting octet is the third, with block size 256 − 224 = 32. The multiples of 32 are 0, 32, 64, 96, 128 and so on, and 99 lies between 96 and 127.

The subnet is 172.20.96.0/19, with broadcast 172.20.127.255. It has 13 host bits, so 213 − 2 = 8,190 usable hosts. 172.20.99.14/19

A PC has address 192.168.5.77 and mask 255.255.255.248. What is the prefix length, the network and the usable range?

248 is 11111000, five 1 bits, so the prefix is 24 + 5 = /29. The block size is 256 − 248 = 8. The multiple of 8 at or below 77 is 72.

Network 192.168.5.72, broadcast 192.168.5.79, usable hosts 192.168.5.73 to 192.168.5.78. That is 6 hosts. 192.168.5.77 255.255.255.248

You must split 10.8.0.0/16 into at least 5 equal subnets, each as large as possible. What is the new prefix, and what is the third subnet?

Five subnets need 3 borrowed bits, because 22 = 4 is too few and 23 = 8 is enough. The new prefix is 16 + 3 = /19, with mask 255.255.224.0 and a block size of 32 in the third octet. The subnets start at 10.8.0.0, 10.8.32.0, 10.8.64.0 and so on up to 10.8.224.0.

The third subnet is 10.8.64.0/19: hosts 10.8.64.1 to 10.8.95.254, broadcast 10.8.95.255, 8,190 usable hosts. 10.8.64.0/19

Write a standard ACL entry that permits every address in 172.16.32.0/20.

The /20 mask is 255.255.240.0. Subtract each octet from 255 to get the wildcard: 0.0.15.255.

access-list 10 permit 172.16.32.0 0.0.15.255 matches 172.16.32.0 through 172.16.47.255. 172.16.32.0 0.0.15.255

Plan 10.10.0.0/24 with VLSM for Lab (60 hosts), Office (28), Voice (12) and a WAN link (2).

Block sizes: 60 hosts need a /26 (62 usable), 28 need a /27 (30), 12 need a /28 (14) and 2 need a /30 (2). Placed largest first:

Lab 10.10.0.0/26, Office 10.10.0.64/27, Voice 10.10.0.96/28, WAN 10.10.0.112/30. The plan uses 116 addresses. The other 140 are free as 10.10.0.116/30, 10.10.0.120/29 and 10.10.0.128/25. 10.10.0.0/24 Lab:60,Office:28,Voice:12,WAN:2