Subnet Mask Calculator

🌐 Free Networking Tool

Subnet Mask
Calculator

Calculate subnet masks, CIDR ranges, network & broadcast addresses, host counts, and binary visualisations instantly — for network engineers, IT students, and cybersecurity professionals.

IPv4 + CIDR Support
Binary Visualisation
Step-by-Step Breakdown
Quick examples
⚠
💡 Network Insight:
—
—
Subnet Mask
—
/24
Network mask for this subnet
Network Address
—
Broadcast Address
—
Usable Hosts
—
Wildcard Mask
—
First Usable IP
—
Last Usable IP
—
Total Addresses
—
IP Class
—
IP Scope
—
Network Bits
—
Host Bits
—
Subnets (from class)
—
Binary Subnet Visualisation
Network bits
Host bits
Step-by-Step Calculation
Adjacent Subnet Blocks
CIDR Quick Reference — click any to calculate
/8
255.0.0.0
16,777,214 hosts
/12
255.240.0.0
1,048,574 hosts
/16
255.255.0.0
65,534 hosts
/20
255.255.240.0
4,094 hosts
/24
255.255.255.0
254 hosts
/25
255.255.255.128
126 hosts
/28
255.255.255.240
14 hosts
/30
255.255.255.252
2 hosts (P2P)

Subnet Mask Calculator: Calculate CIDR & IP Ranges Instantly

Whether you are configuring a router, designing a cloud VPC, studying for your CCNA, or troubleshooting a network connectivity issue, understanding subnet masks is fundamental. This free subnet mask calculator uses exact binary arithmetic to instantly compute every parameter of an IPv4 subnet — mask, CIDR, network address, broadcast address, usable host range, wildcard mask, and binary visualisation — for any IP address and prefix length.

Quick example: Enter 192.168.1.0/24 to get subnet mask 255.255.255.0, network address 192.168.1.0, broadcast 192.168.1.255, and 254 usable hosts. The calculator also shows binary representations and adjacent subnet blocks for VLSM planning.

What is a Subnet Mask?

A subnet mask is a 32-bit number that divides an IPv4 address into two portions: the network portion (identifying the subnet) and the host portion (identifying individual devices within that subnet). Written in dotted-decimal notation, subnet masks consist of a contiguous block of 1 bits followed by 0 bits.

Every device in a TCP/IP network requires three pieces of information to communicate: an IP address, a subnet mask, and a default gateway. The subnet mask tells the device which addresses are reachable directly on the local network versus which require routing through the gateway.

The most common subnet masks are 255.255.255.0 (/24) used in home and small office networks, 255.255.0.0 (/16) used in medium enterprise networks, and 255.0.0.0 (/8) used by large organisations and ISPs.

Understanding IPv4 Addressing

An IPv4 address is a 32-bit binary number written as four decimal octets separated by dots. Each octet represents 8 bits and ranges from 0 to 255. For example, 192.168.1.100 in binary is:

11000000.10101000.00000001.01100100

The total IPv4 address space contains 4,294,967,296 (2³²) possible addresses. However, large portions are reserved for private use, loopback, multicast, and experimental purposes, making the number of publicly routable addresses significantly smaller.

The key insight of subnetting is that you can use part of the host portion of an address to create additional network identifiers — dividing one large network into many smaller, more manageable ones.

What is CIDR Notation?

CIDR (Classless Inter-Domain Routing) notation was introduced in 1993 to replace the inefficient classful networking system. Instead of fixed Class A/B/C boundaries, CIDR allows any prefix length from /0 to /32 to be used, enabling precise allocation of address space.

In CIDR notation, an IP address is followed by a forward slash and a number indicating how many leading bits are network bits:

CIDRSubnet MaskNetwork BitsHost BitsUsable Hosts
/8255.0.0.082416,777,214
/16255.255.0.0161665,534
/24255.255.255.0248254
/25255.255.255.128257126
/28255.255.255.24028414
/30255.255.255.2523022
/32255.255.255.2553201 (host route)

How Subnetting Works

Subnetting performs three core bitwise operations on an IP address:

  1. Network Address: IP AND Subnet Mask — zeroes all host bits to identify the subnet
  2. Broadcast Address: Network OR Wildcard Mask — sets all host bits to 1, the last address in the subnet
  3. Usable Hosts: 2^(host bits) − 2, subtracting the network and broadcast addresses
Example: 192.168.1.100/24 Subnet Mask: 255.255.255.0 (24 ones, 8 zeros) Network Address: 192.168.1.0 (host bits zeroed) Broadcast: 192.168.1.255 (host bits all 1) Usable Range: 192.168.1.1 → 192.168.1.254 Usable Hosts: 2^8 − 2 = 254

Network vs Broadcast Address Explained

Every subnet has two reserved addresses that cannot be assigned to devices. The network address (first in range, all host bits = 0) identifies the subnet in routing tables. The broadcast address (last in range, all host bits = 1) delivers packets to every device in the subnet simultaneously — used by ARP, DHCP, and other protocols.

This is why the formula subtracts 2 from the total address count. A /30 subnet has 4 total addresses but only 2 usable — making it ideal for point-to-point WAN links where exactly 2 devices need IPs.

Public vs Private IP Addresses

RFC 1918 defines three private IPv4 ranges that are not routed on the public internet. Devices using these addresses access the internet through NAT (Network Address Translation):

  • 10.0.0.0/8 — Class A: 16,777,216 addresses (large enterprises, cloud VPCs)
  • 172.16.0.0/12 — Class B: 1,048,576 addresses (medium networks)
  • 192.168.0.0/16 — Class C: 65,536 addresses (home and small office)

Additional reserved ranges include 127.0.0.0/8 (loopback), 169.254.0.0/16 (APIPA link-local), and 224.0.0.0/4 (multicast). This calculator automatically detects and labels the scope of any IP address you enter.

Class A, B, and C Networks

Before CIDR, IPv4 addresses used fixed classes based on the first octet. Class A (1–126) had default /8 masks, Class B (128–191) had /16 masks, and Class C (192–223) had /24 masks. This system was wasteful — a company needing 500 hosts had to receive a Class B (65,534 hosts) because a Class C (254 hosts) was too small. CIDR eliminated this waste by enabling any prefix length.

VLSM and Advanced Subnetting

Variable Length Subnet Masking (VLSM) allows different subnets within the same address block to use different prefix lengths. Instead of allocating identical /24 subnets everywhere, you can use a /28 for a 10-device segment and a /22 for a 900-device floor — matching address allocation precisely to actual requirements. This calculator’s adjacent subnet display supports VLSM planning by showing consecutive subnet blocks.

Cybersecurity and Network Segmentation

Proper subnet design is a cornerstone of network security. Dividing a network into isolated segments — with firewall rules controlling inter-segment traffic — creates a principle-of-least-privilege architecture where a breach in one segment cannot automatically reach others.

🛡️

DMZ Subnets

Internet-facing servers placed in a dedicated subnet with restricted access to internal networks. Typically a small /28 or /29.

🔒

Management VLANs

Network device management interfaces isolated in a dedicated subnet, accessible only from specific admin workstations.

📡

IoT Segmentation

Smart devices and cameras isolated in their own subnet to prevent lateral movement if any device is compromised.

☁️

Cloud VPC Design

AWS, Azure, and GCP all require CIDR-based subnet planning. Common pattern: /16 VPC, /24 per availability zone subnet.

Common Networking Mistakes

Even experienced engineers make subnetting errors. The most frequent mistakes include assigning the network address (e.g. 192.168.1.0 on a /24) or broadcast address (192.168.1.255) to a device — both are reserved. Overlapping subnets in VLSM designs cause routing loops. Using a default gateway outside the local subnet makes it unreachable at Layer 2. And confusing subnet mask with wildcard mask in Cisco ACL configurations is a classic error that generates hard-to-debug access control failures.

Related Networking Calculators

Frequently Asked Questions

What is a subnet mask?
A subnet mask is a 32-bit number that separates the network and host portions of an IP address. Written as four decimal octets (e.g. 255.255.255.0), it consists of contiguous 1 bits identifying the network, followed by 0 bits for hosts. Devices use it in a bitwise AND with the IP address to determine the network address and identify which addresses are local vs routed.
What does /24 mean in networking?
/24 is CIDR notation indicating that 24 of the 32 IP address bits are network bits, leaving 8 bits for host addresses. This equals subnet mask 255.255.255.0 and provides 256 total addresses with 254 usable hosts. The /24 is the most common subnet in home and small office networks because it maps neatly to the last octet of the IP address.
How many hosts are in a /24 subnet?
A /24 subnet has 2^8 = 256 total addresses, with 254 usable host addresses. The first address (e.g. 192.168.1.0) is the network address and the last (192.168.1.255) is the broadcast address — both are reserved and cannot be assigned to devices.
How do I calculate a subnet mask from CIDR?
Set the first N bits to 1 (where N is the CIDR prefix) and fill the remaining 32−N bits with 0. Convert each 8-bit group to decimal. For /24: 11111111.11111111.11111111.00000000 = 255.255.255.0. For /28: 11111111.11111111.11111111.11110000 = 255.255.255.240. This calculator does the conversion automatically — enter either format.
What is the broadcast address?
The broadcast address is the last IP in a subnet with all host bits set to 1. Packets sent to this address are delivered to every device on the subnet. For 192.168.1.0/24, the broadcast is 192.168.1.255. It is used by ARP requests, DHCP discovery, and certain routing protocols to reach all hosts simultaneously.
What is a wildcard mask?
A wildcard mask is the bitwise inverse of a subnet mask — subtract each octet from 255. If the subnet mask is 255.255.255.0, the wildcard is 0.0.0.255. Wildcard masks are used in Cisco ACLs and OSPF network statements to specify which bits of an address must match (0 = must match, 1 = any value).
What is VLSM?
Variable Length Subnet Masking allows different subnets within the same address block to use different prefix lengths. This lets network engineers allocate address space efficiently — a /30 for a 2-device WAN link, a /26 for a 50-device office, and a /22 for a 900-device campus floor — all carved from the same /16 block. VLSM is supported by all modern routing protocols.
What is the difference between public and private IPs?
Public IPs are globally unique and routable on the internet, assigned by IANA through regional registries. Private IPs (10.x.x.x, 172.16–31.x.x, 192.168.x.x) are defined in RFC 1918 for internal use — they can be reused across different organisations and are not routed on the public internet. Private devices reach the internet via NAT on a router or firewall.
What subnet should I use for a point-to-point link?
Use a /30 for traditional point-to-point WAN links — 4 addresses, 2 usable, minimal waste. For modern environments, a /31 (RFC 3021) is even more efficient — both addresses are usable on P2P links, saving 2 addresses per link. At scale (thousands of router interfaces), /31 addressing saves significant address space.
How accurate is this subnet calculator?
This calculator uses exact 32-bit integer arithmetic with zero floating-point errors. All results are computed from raw binary bit patterns using the same formulas as Cisco IOS, Linux iproute2, and commercial IPAM tools. Results are identical to authoritative networking tools — guaranteed accuracy for exam preparation, production network design, and documentation.

Explore more networking tools

IP Address Calculator, Binary Converter, Bandwidth Calculator — free IT tools, all instant and no sign-up required.

Explore networking calculators →

This calculator provides networking calculations based on RFC-standard IPv4 formulas. Verify critical configurations against your equipment documentation.