Subnet Mask
Calculator
Calculate subnet masks, CIDR ranges, network & broadcast addresses, host counts, and binary visualisations instantly — for network engineers, IT students, and cybersecurity professionals.
—
Subnet Mask Calculator: Calculate CIDR & IP Ranges Instantly
Whether you are configuring a router, designing a cloud VPC, studying for your CCNA, or troubleshooting a network connectivity issue, understanding subnet masks is fundamental. This free subnet mask calculator uses exact binary arithmetic to instantly compute every parameter of an IPv4 subnet — mask, CIDR, network address, broadcast address, usable host range, wildcard mask, and binary visualisation — for any IP address and prefix length.
Quick example: Enter 192.168.1.0/24 to get subnet mask 255.255.255.0, network address 192.168.1.0, broadcast 192.168.1.255, and 254 usable hosts. The calculator also shows binary representations and adjacent subnet blocks for VLSM planning.
What is a Subnet Mask?
A subnet mask is a 32-bit number that divides an IPv4 address into two portions: the network portion (identifying the subnet) and the host portion (identifying individual devices within that subnet). Written in dotted-decimal notation, subnet masks consist of a contiguous block of 1 bits followed by 0 bits.
Every device in a TCP/IP network requires three pieces of information to communicate: an IP address, a subnet mask, and a default gateway. The subnet mask tells the device which addresses are reachable directly on the local network versus which require routing through the gateway.
The most common subnet masks are 255.255.255.0 (/24) used in home and small office networks, 255.255.0.0 (/16) used in medium enterprise networks, and 255.0.0.0 (/8) used by large organisations and ISPs.
Understanding IPv4 Addressing
An IPv4 address is a 32-bit binary number written as four decimal octets separated by dots. Each octet represents 8 bits and ranges from 0 to 255. For example, 192.168.1.100 in binary is:
The total IPv4 address space contains 4,294,967,296 (2³²) possible addresses. However, large portions are reserved for private use, loopback, multicast, and experimental purposes, making the number of publicly routable addresses significantly smaller.
The key insight of subnetting is that you can use part of the host portion of an address to create additional network identifiers — dividing one large network into many smaller, more manageable ones.
What is CIDR Notation?
CIDR (Classless Inter-Domain Routing) notation was introduced in 1993 to replace the inefficient classful networking system. Instead of fixed Class A/B/C boundaries, CIDR allows any prefix length from /0 to /32 to be used, enabling precise allocation of address space.
In CIDR notation, an IP address is followed by a forward slash and a number indicating how many leading bits are network bits:
| CIDR | Subnet Mask | Network Bits | Host Bits | Usable Hosts |
|---|---|---|---|---|
/8 | 255.0.0.0 | 8 | 24 | 16,777,214 |
/16 | 255.255.0.0 | 16 | 16 | 65,534 |
/24 | 255.255.255.0 | 24 | 8 | 254 |
/25 | 255.255.255.128 | 25 | 7 | 126 |
/28 | 255.255.255.240 | 28 | 4 | 14 |
/30 | 255.255.255.252 | 30 | 2 | 2 |
/32 | 255.255.255.255 | 32 | 0 | 1 (host route) |
How Subnetting Works
Subnetting performs three core bitwise operations on an IP address:
- Network Address: IP AND Subnet Mask — zeroes all host bits to identify the subnet
- Broadcast Address: Network OR Wildcard Mask — sets all host bits to 1, the last address in the subnet
- Usable Hosts: 2^(host bits) − 2, subtracting the network and broadcast addresses
Network vs Broadcast Address Explained
Every subnet has two reserved addresses that cannot be assigned to devices. The network address (first in range, all host bits = 0) identifies the subnet in routing tables. The broadcast address (last in range, all host bits = 1) delivers packets to every device in the subnet simultaneously — used by ARP, DHCP, and other protocols.
This is why the formula subtracts 2 from the total address count. A /30 subnet has 4 total addresses but only 2 usable — making it ideal for point-to-point WAN links where exactly 2 devices need IPs.
Public vs Private IP Addresses
RFC 1918 defines three private IPv4 ranges that are not routed on the public internet. Devices using these addresses access the internet through NAT (Network Address Translation):
- 10.0.0.0/8 — Class A: 16,777,216 addresses (large enterprises, cloud VPCs)
- 172.16.0.0/12 — Class B: 1,048,576 addresses (medium networks)
- 192.168.0.0/16 — Class C: 65,536 addresses (home and small office)
Additional reserved ranges include 127.0.0.0/8 (loopback), 169.254.0.0/16 (APIPA link-local), and 224.0.0.0/4 (multicast). This calculator automatically detects and labels the scope of any IP address you enter.
Class A, B, and C Networks
Before CIDR, IPv4 addresses used fixed classes based on the first octet. Class A (1–126) had default /8 masks, Class B (128–191) had /16 masks, and Class C (192–223) had /24 masks. This system was wasteful — a company needing 500 hosts had to receive a Class B (65,534 hosts) because a Class C (254 hosts) was too small. CIDR eliminated this waste by enabling any prefix length.
VLSM and Advanced Subnetting
Variable Length Subnet Masking (VLSM) allows different subnets within the same address block to use different prefix lengths. Instead of allocating identical /24 subnets everywhere, you can use a /28 for a 10-device segment and a /22 for a 900-device floor — matching address allocation precisely to actual requirements. This calculator’s adjacent subnet display supports VLSM planning by showing consecutive subnet blocks.
Cybersecurity and Network Segmentation
Proper subnet design is a cornerstone of network security. Dividing a network into isolated segments — with firewall rules controlling inter-segment traffic — creates a principle-of-least-privilege architecture where a breach in one segment cannot automatically reach others.
DMZ Subnets
Internet-facing servers placed in a dedicated subnet with restricted access to internal networks. Typically a small /28 or /29.
Management VLANs
Network device management interfaces isolated in a dedicated subnet, accessible only from specific admin workstations.
IoT Segmentation
Smart devices and cameras isolated in their own subnet to prevent lateral movement if any device is compromised.
Cloud VPC Design
AWS, Azure, and GCP all require CIDR-based subnet planning. Common pattern: /16 VPC, /24 per availability zone subnet.
Common Networking Mistakes
Even experienced engineers make subnetting errors. The most frequent mistakes include assigning the network address (e.g. 192.168.1.0 on a /24) or broadcast address (192.168.1.255) to a device — both are reserved. Overlapping subnets in VLSM designs cause routing loops. Using a default gateway outside the local subnet makes it unreachable at Layer 2. And confusing subnet mask with wildcard mask in Cisco ACL configurations is a classic error that generates hard-to-debug access control failures.
Related Networking Calculators
Frequently Asked Questions
Explore more networking tools
IP Address Calculator, Binary Converter, Bandwidth Calculator — free IT tools, all instant and no sign-up required.
Explore networking calculators →This calculator provides networking calculations based on RFC-standard IPv4 formulas. Verify critical configurations against your equipment documentation.