~/jackwent.co.uk
jack@jackwent:~$ ./subnet-calc

Subnet Calculator

Type an IP address with its prefix (192.168.1.10/24) or its mask (192.168.1.10 255.255.255.0) and everything updates as you type. It all runs in your browser, so nothing you enter is sent anywhere. The address bar updates too, so you can bookmark or share a result.

jack@jackwent: ~/tools/subnet-calcIPv4
Network
Usable hosts
Broadcast
Host count
Subnet mask
Wildcard mask
Address type
IP in hex
Binary

Split this network

#NetworkUsable rangeBroadcast

How to read the results

  • Network is the first address in the subnet. It identifies the subnet itself, so you can’t give it to a device.
  • Usable hosts is the range you can actually hand out to PCs, printers and servers.
  • Broadcast is the last address. Anything sent there goes to every device on the subnet, so it can’t be used either.
  • Wildcard mask is the mask flipped over. Cisco access lists and OSPF use it instead of the subnet mask.
  • Binary shows the network bits in amber and the host bits in blue. The prefix is simply how many amber bits there are.

That’s why a /24 has 256 addresses but only 254 usable hosts: one goes on the network address and one on the broadcast.

The exceptions: /31 and /32

A /31 has just two addresses and no network or broadcast address, so both are usable. That’s perfect for a link between two routers and saves wasting a whole /30 (RFC 3021).

A /32 is a single address. You’ll see it for loopback addresses on routers, and in firewall rules that match one host.

CIDR cheat sheet

PrefixSubnet maskAddressesUsable hostsTypical use
/8255.0.0.016,777,21616,777,214The whole 10.x.x.x private range
/16255.255.0.065,53665,534A large site or campus
/20255.255.240.04,0964,094A big Wi-Fi network
/22255.255.252.01,0241,022A busy office floor
/23255.255.254.0512510A medium office
/24255.255.255.0256254Nearly every home network
/25255.255.255.128128126Half a /24
/26255.255.255.1926462A small VLAN, like printers or CCTV
/27255.255.255.2243230Servers or management
/28255.255.255.2401614A small block of public IPs
/29255.255.255.24886The block of public IPs your ISP gives you
/30255.255.255.25242An old style point to point link
/31255.255.255.25422A modern point to point link
/32255.255.255.25511A single host

Private address ranges

These ranges are never routed on the internet, so you can use them freely inside your own network:

RangeCIDRNotes
10.0.0.0 to 10.255.255.25510.0.0.0/8Loads of room, popular in business networks
172.16.0.0 to 172.31.255.255172.16.0.0/12Often forgotten, and the one Docker likes to use
192.168.0.0 to 192.168.255.255192.168.0.0/16What almost every home router uses

Two more worth recognising: 100.64.0.0/10 is carrier-grade NAT, which means your ISP is sharing one public IP between lots of customers, and 169.254.x.x means a device asked for a DHCP address and didn’t get one.

Tips from the real world

  • Plan bigger than you need. A /24 for a VLAN with 30 devices feels wasteful, until you’re renumbering everything two years later.
  • Avoid 192.168.0.x and 192.168.1.x for anything that needs a VPN. Every home router uses them, so remote workers end up with clashing networks.
  • Keep subnets on clean boundaries. A /26 has to start on 0, 64, 128 or 192. The split tool above only ever gives you valid ones.
  • Write it down. A simple spreadsheet of subnets, VLANs and what lives where saves hours later.

For checking what’s actually on a network, the commands page has the ipconfig, arp and route commands that go hand in hand with this. If you work with RAM and disk sizes as well, there’s also a memory calculator.

[jackwent]