Subnet Calculator

Enter a network in CIDR notation or as an address and mask. You get the network and broadcast addresses, the usable host range, the wildcard mask, and a bit-level view showing exactly where the network part ends and the host part begins.

Accepts 10.0.0.0/8, 10.0.0.0 255.0.0.0, or a bare address (treated as /24).

—

Key takeaway: the mask decides how many addresses belong to one network, and two of them are never usable by a device — the first identifies the network itself, the last is the broadcast address. That is why a /24 gives 254 usable addresses rather than 256, and why the number halves every time you add a bit to the prefix.

How a subnet mask works

An IPv4 address is 32 bits. The mask splits those bits into two parts: a network part that every device on the segment shares, and a host part that identifies the individual device. The prefix length is simply how many bits belong to the network — /24 means the first 24 bits are the network, leaving 8 bits, which is 256 addresses.

That is the whole idea, and the binary view above shows it directly: the blue digits are identical for every device on the network, and the green ones are the only part that changes.

A device uses the mask to answer one question constantly — is this destination on my network? If the network bits match its own, it sends the packet directly. If they do not, it hands the packet to the router instead. Getting the mask wrong is why a machine can sometimes reach half the network and not the rest: with a mismatched mask, two devices disagree about whether they are neighbours.

Why two addresses are always lost

The first address in the range, with all host bits set to zero, names the network itself. The last, with all host bits set to one, is the broadcast address — anything sent to it goes to every device on the segment. Neither can be assigned to a machine, which is where the “minus two” in every host count comes from.

There is one modern exception. A /31 has only two addresses and no room for that convention, so RFC 3021 allows both to be used on point-to-point links between routers. This calculator follows that rule. A /32 is a single address, used for loopbacks, host routes and firewall rules rather than for a network with devices on it.

Choosing a prefix

Work from the number of devices, then add headroom — running out means renumbering, which is far more painful than allocating a slightly larger block on day one.

You needUseGives you
A couple of routers on a link/30 or /312 usable addresses
A handful of servers/296 usable
A small office/27 or /2630 or 62 usable
A typical home network/24254 usable
A large flat network/221,022 usable

Bigger is not automatically better. Every device on a segment sees the broadcast traffic of every other device, so very large flat networks get noisy and are harder to contain when something goes wrong. Splitting into smaller subnets — the table above the fold does this for you — is how networks stay manageable, and it is why a business separates guest Wi-Fi, cameras and workstations instead of putting all three in one /16.

Private ranges, and the one that surprises people

Three blocks are reserved for private use and are never routed on the public internet: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Your router hands out addresses from one of them, and NAT translates them to your single public address on the way out.

The surprise is 100.64.0.0/10. It looks public but is not — it is carrier-grade NAT space, used by providers to share one public address between many customers. If your router’s WAN address sits in that range you are behind CGNAT, which is why port forwarding will not work no matter how you configure it. This calculator labels that range for exactly that reason.

Reaching a device on your subnet from outside

The usual instinct is to forward a port, which publishes that service to the entire internet — and our port scanner exists largely because of what that exposes. Running a VPN back into the network instead gives you an address on the subnet without opening anything, and it is the only approach that works at all when your provider has you behind CGNAT.

PureVPN Set one up on your router

Affiliate link. We do not rank by commission — compare providers yourself.

What this calculator does not cover

IPv6. The arithmetic is the same in principle but the scale is different — a /64 holds more addresses than the entire IPv4 internet, so the “usable hosts” question stops being interesting. See whether you should enable IPv6.

Whether an address is actually free. This is arithmetic, not a scan. A /24 has 254 usable addresses; how many are in use on your network is a different question.

Routing. Knowing a destination is outside your subnet tells you the packet goes to the router. Where it goes after that depends on routing tables and the networks between you.

Frequently asked questions

What does the /24 in an address mean?

It is the prefix length — the count of leading bits that identify the network. /24 is the same thing as the mask 255.255.255.0, just written more compactly. CIDR notation replaced the old class A/B/C system in the 1990s precisely because fixed classes wasted enormous numbers of addresses.

Why does my network use 192.168.1.x?

Convention, nothing more. Router manufacturers ship it as the default from the private 192.168.0.0/16 block. It is worth changing if you use a VPN into your network, because if the network you are joining from also uses 192.168.1.x, the two collide and routing breaks.

What is a wildcard mask for?

It is the subnet mask inverted, and Cisco access-control lists use it to match ranges. Where a mask has 255.255.255.0, the wildcard is 0.0.0.255: zeros mean “must match”, ones mean “do not care”.

Can two subnets overlap?

They should never be configured to, and this is a common cause of confusing faults — traffic for one range disappears into the other. If you are adding a subnet to an existing network, check it does not fall inside a block already in use. Splitting a parent network with the table above guarantees the children do not overlap.

Does subnetting improve security?

It helps by limiting what a compromised device can reach directly, which is why putting cameras and IoT gear on their own segment is worth doing. On its own it is not a security control — without firewall rules between the subnets, a router will happily forward traffic from one to the other. See securing a home network.

CIDR reference

PrefixMaskWildcardAddressesUsable

Related reading

Other tools

Scroll to Top