Type an IP address with its prefix (192.168.1.10/24) or its mask (192.168.1.10 255.255.255.0) and everything updates as you type. It all runs in your browser, so nothing you enter is sent anywhere. The address bar updates too, so you can bookmark or share a result.
- Network
- Usable hosts
- Broadcast
- Host count
- Subnet mask
- Wildcard mask
- Address type
- IP in hex
- Binary
Split this network
| # | Network | Usable range | Broadcast |
|---|
How to read the results
- Network is the first address in the subnet. It identifies the subnet itself, so you can’t give it to a device.
- Usable hosts is the range you can actually hand out to PCs, printers and servers.
- Broadcast is the last address. Anything sent there goes to every device on the subnet, so it can’t be used either.
- Wildcard mask is the mask flipped over. Cisco access lists and OSPF use it instead of the subnet mask.
- Binary shows the network bits in amber and the host bits in blue. The prefix is simply how many amber bits there are.
That’s why a /24 has 256 addresses but only 254 usable hosts: one goes on the network address and one on the broadcast.
The exceptions: /31 and /32
A /31 has just two addresses and no network or broadcast address, so both are usable. That’s perfect for a link between two routers and saves wasting a whole /30 (RFC 3021).
A /32 is a single address. You’ll see it for loopback addresses on routers, and in firewall rules that match one host.
CIDR cheat sheet
| Prefix | Subnet mask | Addresses | Usable hosts | Typical use |
|---|---|---|---|---|
/8 | 255.0.0.0 | 16,777,216 | 16,777,214 | The whole 10.x.x.x private range |
/16 | 255.255.0.0 | 65,536 | 65,534 | A large site or campus |
/20 | 255.255.240.0 | 4,096 | 4,094 | A big Wi-Fi network |
/22 | 255.255.252.0 | 1,024 | 1,022 | A busy office floor |
/23 | 255.255.254.0 | 512 | 510 | A medium office |
/24 | 255.255.255.0 | 256 | 254 | Nearly every home network |
/25 | 255.255.255.128 | 128 | 126 | Half a /24 |
/26 | 255.255.255.192 | 64 | 62 | A small VLAN, like printers or CCTV |
/27 | 255.255.255.224 | 32 | 30 | Servers or management |
/28 | 255.255.255.240 | 16 | 14 | A small block of public IPs |
/29 | 255.255.255.248 | 8 | 6 | The block of public IPs your ISP gives you |
/30 | 255.255.255.252 | 4 | 2 | An old style point to point link |
/31 | 255.255.255.254 | 2 | 2 | A modern point to point link |
/32 | 255.255.255.255 | 1 | 1 | A single host |
Private address ranges
These ranges are never routed on the internet, so you can use them freely inside your own network:
| Range | CIDR | Notes |
|---|---|---|
| 10.0.0.0 to 10.255.255.255 | 10.0.0.0/8 | Loads of room, popular in business networks |
| 172.16.0.0 to 172.31.255.255 | 172.16.0.0/12 | Often forgotten, and the one Docker likes to use |
| 192.168.0.0 to 192.168.255.255 | 192.168.0.0/16 | What almost every home router uses |
Two more worth recognising: 100.64.0.0/10 is carrier-grade NAT, which means your ISP is sharing one public IP between lots of customers, and 169.254.x.x means a device asked for a DHCP address and didn’t get one.
Tips from the real world
- Plan bigger than you need. A
/24for a VLAN with 30 devices feels wasteful, until you’re renumbering everything two years later. - Avoid 192.168.0.x and 192.168.1.x for anything that needs a VPN. Every home router uses them, so remote workers end up with clashing networks.
- Keep subnets on clean boundaries. A
/26has to start on 0, 64, 128 or 192. The split tool above only ever gives you valid ones. - Write it down. A simple spreadsheet of subnets, VLANs and what lives where saves hours later.
For checking what’s actually on a network, the commands page has the ipconfig, arp and route commands that go hand in hand with this. If you work with RAM and disk sizes as well, there’s also a memory calculator.