| Network (CIDR) | |
|---|---|
| Network address | |
| Broadcast address | |
| First usable host | |
| Last usable host | |
| Total addresses | |
| Usable hosts | |
| Subnet mask | |
| Wildcard mask | |
| Prefix length | |
| Address type | |
| Legacy class | |
| IP as hex / integer |
Split this network into smaller subnets
| # | Subnet | Usable host range | Broadcast | Usable hosts |
|---|
CIDR cheat sheet: /8 to /32
Every IPv4 prefix length from /8 to /32 with its dotted-decimal subnet mask, wildcard mask, total number of addresses and usable host count. Common prefixes are in bold.
| CIDR | Subnet mask | Wildcard mask | Total addresses | Usable hosts |
|---|---|---|---|---|
| /8 | 255.0.0.0 | 0.255.255.255 | 16,777,216 | 16,777,214 |
| /9 | 255.128.0.0 | 0.127.255.255 | 8,388,608 | 8,388,606 |
| /10 | 255.192.0.0 | 0.63.255.255 | 4,194,304 | 4,194,302 |
| /11 | 255.224.0.0 | 0.31.255.255 | 2,097,152 | 2,097,150 |
| /12 | 255.240.0.0 | 0.15.255.255 | 1,048,576 | 1,048,574 |
| /13 | 255.248.0.0 | 0.7.255.255 | 524,288 | 524,286 |
| /14 | 255.252.0.0 | 0.3.255.255 | 262,144 | 262,142 |
| /15 | 255.254.0.0 | 0.1.255.255 | 131,072 | 131,070 |
| /16 | 255.255.0.0 | 0.0.255.255 | 65,536 | 65,534 |
| /17 | 255.255.128.0 | 0.0.127.255 | 32,768 | 32,766 |
| /18 | 255.255.192.0 | 0.0.63.255 | 16,384 | 16,382 |
| /19 | 255.255.224.0 | 0.0.31.255 | 8,192 | 8,190 |
| /20 | 255.255.240.0 | 0.0.15.255 | 4,096 | 4,094 |
| /21 | 255.255.248.0 | 0.0.7.255 | 2,048 | 2,046 |
| /22 | 255.255.252.0 | 0.0.3.255 | 1,024 | 1,022 |
| /23 | 255.255.254.0 | 0.0.1.255 | 512 | 510 |
| /24 | 255.255.255.0 | 0.0.0.255 | 256 | 254 |
| /25 | 255.255.255.128 | 0.0.0.127 | 128 | 126 |
| /26 | 255.255.255.192 | 0.0.0.63 | 64 | 62 |
| /27 | 255.255.255.224 | 0.0.0.31 | 32 | 30 |
| /28 | 255.255.255.240 | 0.0.0.15 | 16 | 14 |
| /29 | 255.255.255.248 | 0.0.0.7 | 8 | 6 |
| /30 | 255.255.255.252 | 0.0.0.3 | 4 | 2 |
| /31 | 255.255.255.254 | 0.0.0.1 | 2 | 2* |
| /32 | 255.255.255.255 | 0.0.0.0 | 1 | 1* |
Source: thealltools.com/tools/subnet-calculator
About this tool
This subnet calculator takes an IPv4 address with a CIDR prefix or a dotted subnet mask and works out the network address, broadcast address, usable host range, host count, wildcard mask and a binary view of the address and mask. It also tells you whether the address sits in a private, shared (CGNAT), loopback, link-local, multicast or documentation range, and it can split the network into equal smaller subnets. Everything is calculated in your browser, and nothing you type is sent anywhere. It handles IPv4 only.
How to use the subnet calculator
- Enter an address. Type it in CIDR form such as
192.168.1.130/26, with a mask such as10.0.0.5 255.255.0.0, or just the address on its own. - Pick a mask from the dropdown if you typed only the address. The dropdown lists every prefix from /0 to /32 with its dotted mask, and choosing one rewrites the address field to match.
- Read the results. They update as you type, and Calculate runs them again. Copy results copies everything as plain text.
- Split the network if you need smaller subnets. Choose a longer prefix, or type how many subnets you need and the tool picks the smallest prefix that gives at least that many. Up to 256 rows are listed.
How CIDR works
An IPv4 address is a 32-bit number, written as four 8-bit octets in decimal. Classless Inter-Domain Routing, defined in RFC 4632, splits those 32 bits into a network part and a host part. The prefix length after the slash says how many leading bits belong to the network. A /26 means the first 26 bits identify the network and the remaining 6 bits number the hosts inside it.
The subnet mask is the same idea written as an address: 26 one-bits followed by 6 zero-bits, which is 255.255.255.192. The calculator derives everything else from that:
network address = IP AND mask wildcard mask = NOT mask broadcast address = network OR wildcard total addresses = 2^(32 − prefix) usable hosts = total − 2 (except /31 and /32)
Two addresses are normally lost in every subnet. The all-zeros host part names the network itself, and the all-ones host part is the directed broadcast address, so neither can be given to a device. The wildcard mask is the bitwise inverse of the subnet mask. Network engineers meet it in access lists and routing configuration, where a 0 bit means the bit must match and a 1 bit means it does not matter.
Worked example
The tool loads with 192.168.1.130/26. The mask for /26 is 255.255.255.192, so only the last octet is split: 130 is 10000010 in binary, and the mask's last octet is 11000000. ANDing them keeps the top two bits, 10000000, which is 128. The calculator reports:
Network address 192.168.1.128 Broadcast address 192.168.1.191 Usable hosts 192.168.1.129 – 192.168.1.190 Total addresses 64 Usable hosts 62 Subnet mask 255.255.255.192 Wildcard mask 0.0.0.63 IP (binary) 11000000.10101000.00000001.10000010 Mask (binary) 11111111.11111111.11111111.11000000
The split section starts at /28, which divides the /26 into 4 subnets of 16 addresses (14 usable hosts each):
192.168.1.128/28 192.168.1.129 – 192.168.1.142 broadcast 192.168.1.143 192.168.1.144/28 192.168.1.145 – 192.168.1.158 broadcast 192.168.1.159 192.168.1.160/28 192.168.1.161 – 192.168.1.174 broadcast 192.168.1.175 192.168.1.176/28 192.168.1.177 – 192.168.1.190 broadcast 192.168.1.191
Special address ranges the tool recognizes
The address type comes from the IANA special-purpose address registry described in RFC 6890. Any address not in one of these blocks is shown as public.
| Block | Purpose | Defined in |
|---|---|---|
| 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 | Private use | RFC 1918 |
| 100.64.0.0/10 | Shared address space (carrier-grade NAT) | RFC 6598 |
| 127.0.0.0/8 | Loopback | RFC 1122 |
| 169.254.0.0/16 | Link-local (automatic addressing when no DHCP answers) | RFC 3927 |
| 192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24 | Documentation (TEST-NET-1, 2 and 3) | RFC 5737 |
| 198.18.0.0/15 | Benchmarking | RFC 2544 |
| 224.0.0.0/4 | Multicast (224.0.0.0 to 239.255.255.255) | RFC 5771 |
| 240.0.0.0/4 | Reserved | RFC 1112 |
| 0.0.0.0/8 | This host on this network | RFC 1122 |
The tool also flags 192.0.0.0/24 (IETF protocol assignments), 192.88.99.0/24 (the deprecated 6to4 relay anycast block) and the limited broadcast address 255.255.255.255. The legacy class (A to E) is shown for reference only. Classful addressing was replaced by CIDR, and the class of an address says nothing about its real mask today.
The /31 and /32 edge cases
A /32 is a single address. It has no separate network or broadcast address, and it is how a single host is written in routing tables, firewall rules and loopback interfaces. A /31 has only two addresses, and under the classic rule it would have no usable hosts at all. RFC 3021 allows both addresses of a /31 to be used as host addresses on point-to-point links, which saves half the addresses of the /30 that would otherwise be used. Directed broadcast is not possible on such a link. The calculator follows RFC 3021 and reports 2 usable hosts and no broadcast address for a /31.
Common mistakes
- Forgetting to subtract 2. A /24 has 256 addresses but only 254 usable hosts.
- Assigning the network or broadcast address to a device, for example giving 192.168.1.191 to a host in 192.168.1.128/26.
- Applying the minus-2 rule to /31 and /32. Those prefixes follow different rules, covered above.
- Typing a non-contiguous mask such as 255.0.255.0. A subnet mask must be ones followed by zeros, and the tool rejects anything else.
- Writing octets with leading zeros. Some software reads
010as octal 8, so the tool asks you to remove them rather than guess. - Mixing up the subnet mask and the wildcard mask when writing access lists.
- Assuming 172.16.0.0/12 ends at 172.16.255.255. It runs from 172.16.0.0 to 172.31.255.255.
Use cases
- Planning a home or office network, or carving a cloud VPC into subnets for each tier.
- Checking which range a DHCP pool should use and which addresses are left for static devices.
- Writing firewall rules, routes and access lists with the right network and wildcard mask.
- Studying for networking exams that test subnetting by hand, then checking answers here.
To see the bit patterns behind the octets, try the Binary & Hex Converter. For checking address patterns in logs, the Regex Tester is handy.
Frequently asked questions
It depends on the new prefix length. Each extra prefix bit doubles the number of subnets and halves their size: a /25 gives 2 subnets, a /26 gives 4, a /27 gives 8, a /28 gives 16, and a /30 gives 64 subnets with 2 usable hosts each. Use the split section above to list them.
In 192.168.0.0/24 it is not, because it is the broadcast address of that subnet. In a larger network such as 192.168.0.0/23, which runs from 192.168.0.0 to 192.168.1.255, it is an ordinary host address in the middle of the range. Whether an address is usable always depends on the mask.
A /0 prefix has no network bits, so it matches every IPv4 address. It is how a default route is written: traffic that matches no more specific route is sent to the gateway configured for 0.0.0.0/0. In firewall rules it means any address.
Wildcard masks appear mainly in router and firewall configuration. Cisco IOS access control lists and OSPF network statements, for example, take a wildcard mask instead of a subnet mask, so 192.168.1.0 0.0.0.255 matches the whole 192.168.1.0/24 network.
On Windows, run ipconfig in Command Prompt and read the IPv4 Address and Subnet Mask lines. On Linux, ip addr shows each address in CIDR form, such as 192.168.1.20/24. On macOS, the Network pane in System Settings shows the details, and ifconfig prints the netmask in hexadecimal.
Two CIDR blocks are either completely separate or one sits entirely inside the other. If you assign overlapping blocks to different networks, such as two VPCs you later connect, routing becomes ambiguous and some hosts cannot reach each other. Plan non-overlapping ranges before connecting networks.
No. It handles IPv4 only, from /0 to /32. IPv6 uses 128-bit addresses, has no broadcast address and is normally subnetted on different conventions, so it needs a separate calculator. If you paste an IPv6 address the tool says so instead of guessing.