OnCallReady

Lesson 8.1 · Addressing & DNS · 22 min read

An address is a 32-bit number

In plain words

Imagine a row of 32 light switches. Each one is on or off. Any pattern of those switches is one IP address, and we just write it in four groups of eight as numbers, like 10.64.0.2, because "on off on on off..." is hard to read.

Now put a piece of tape across the row after, say, the 24th switch. Everything left of the tape says which street you are on; everything right of it says which house. That tape is the netmask, and /24 just counts how many switches are left of it.

On oncall-lab, ip -4 -br a shows 10.64.0.2/24: the address, and where the tape sits. ipcalc literally prints a space where the tape is, which is why the lesson uses it.

Why this matters

Someone asks "is 10.0.3.200 inside 10.0.3.192/26?" or "how big is a /20?". Every networking question in the next two chapters comes down to that kind of check. Tools can answer it, but you need to understand the answer - and the trick is that an IP address is just a 32-bit number.

What you need to know already: Ch 1 · Network identity (1.9) - your box has the address 10.64.0.2/24 on the interface enp0s1, and /24 marks which part is "the network". This lesson explains what that /24 really means.

A few words first

Four octets, 32 bits

10       .64       .0        .2
00001010 .01000000 .00000000 .00000010

The top line is how you normally write it. The bottom line is the same address in bits. Inside one octet, each bit position has a value. Left to right:

128  64  32  16   8   4   2   1

To turn a number into bits, walk left to right and take each value that still fits. For 168: 128 fits (40 left), 64 does not, 32 fits (8 left), 16 does not, 8 fits (0 left). So 168 is 10101000. Do a few until it is boring:

  0 = 00000000      128 = 10000000      192 = 11000000
 64 = 01000000      224 = 11100000      240 = 11110000
100 = 01100100      248 = 11111000      252 = 11111100
255 = 11111111      254 = 11111110

The right-hand column is worth knowing by heart, for a reason you will see in a minute.

The network part and the host part

An address has two parts:

A netmask marks where the split is: 1s over the network bits, 0s over the host bits. A prefix length (the /24) just counts the 1s. They are two spellings of the same fact:

255.255.255.0   = 11111111.11111111.11111111.00000000 = /24
255.255.255.192 = 11111111.11111111.11111111.11000000 = /26
255.255.240.0   = 11111111.11111111.11110000.00000000 = /20
255.255.0.0     = 11111111.11111111.00000000.00000000 = /16

A mask is always a run of 1s followed by a run of 0s. That is why a mask octet can only be one of the values in the right-hand column above (plus 0).

/26 is 24 + 2: three full octets of 1s and two more bits. Linux uses the prefix form. You still meet dotted masks in older configs and on Windows.

$ ip -4 -br a
lo               UNKNOWN        127.0.0.1/8
enp0s1           UP             10.64.0.2/24

ip -4 -br a: show addresses (a), IPv4 only (-4), brief, one line per interface (-br). Columns: interface name, state, address/prefix. 10.64.0.2/24 says two things: this interface's address, and that the first 24 bits (10.64.0) are the network it sits on.

Network address = address AND mask

AND is a bit-by-bit rule: the result is 1 only where both inputs are 1. Doing an AND with the mask keeps the network bits and forces every host bit to

  1. What is left is the network address - the name of the whole network:
address   10.0.3.200   00001010.00000000.00000011.11001000
mask /26               11111111.11111111.11111111.11000000
AND                    00001010.00000000.00000011.11000000  = 10.0.3.192

So 10.0.3.200/26 lives in the network 10.0.3.192/26.

The broadcast address is the opposite: every host bit set to 1. It means "everyone on this network" (a message sent to it reaches every machine there):

network   10.0.3.192   ...00000011.11 000000
host bits all 1        ...00000011.11 111111  = 10.0.3.255

Every address strictly between the two is a usable host address: .193 to .254.

Let ipcalc show you the bits

ipcalc is a small calculator for exactly this. You install it with apt, like tree in Ch 1. It prints the binary with a space where the network part ends, which is the whole point:

$ sudo apt install -y ipcalc
$ ipcalc 10.0.3.200/26
Address:   10.0.3.200           00001010.00000000.00000011.11 001000
Netmask:   255.255.255.192 = 26 11111111.11111111.11111111.11 000000
Wildcard:  0.0.0.63             00000000.00000000.00000000.00 111111
=>
Network:   10.0.3.192/26        00001010.00000000.00000011.11 000000
HostMin:   10.0.3.193           00001010.00000000.00000011.11 000001
HostMax:   10.0.3.254           00001010.00000000.00000011.11 111110
Broadcast: 10.0.3.255           00001010.00000000.00000011.11 111111
Hosts/Net: 62                    Class A, Private Internet

Read it line by line:

When the split falls inside an octet

This is the only case that needs thought. /20 = 16 + 4, so the split is four bits into the third octet:

$ ipcalc -b 172.20.77.9/20
Address:   172.20.77.9
Netmask:   255.255.240.0 = 20
Wildcard:  0.0.15.255
=>
Network:   172.20.64.0/20
HostMin:   172.20.64.1
HostMax:   172.20.79.254
Broadcast: 172.20.79.255
Hosts/Net: 4094                  Class B, Private Internet

(-b = brief: skip the binary columns.) 77 in binary is 0100 1101. Keep the top four bits (0100 = 64), zero the rest: the third octet of the network is

  1. The mask octet 240 is 1111 0000; its lowest 1 is worth 16, so the network

is 16 wide in that octet: 64 to 79.

That width is the block size, and there is a shortcut: 256 minus the mask octet. The next lesson builds on it:

mask octet 240 -> block 16     mask octet 192 -> block 64
mask octet 248 -> block 8      mask octet 128 -> block 128
mask octet 252 -> block 4      mask octet 224 -> block 32

The mistake everyone makes once

Writing a network with host bits set:

10.0.3.200/26     <- an address inside a network: right on an interface
10.0.3.192/26     <- the network itself: what a route or a firewall rule wants

Some tools quietly fix it, some reject it. Linux fixes it silently, which surprises you later. A route is a line in the kernel's table that says "to reach this network, go this way" (routes get their own lesson, 8.11); here is one added with host bits set:

$ sudo ip route add 10.0.3.200/26 via 10.64.0.1
$ ip route | grep 10.0.3
10.0.3.192/26 via 10.64.0.1 dev enp0s1

You typed .200, the kernel stored .192. If you later try to delete "the route you typed", it is not there under that name.

Special addresses worth recognising

0.0.0.0/0          "every address" - the default route, or "any" in a firewall
0.0.0.0            as a listen address: every interface on this box
127.0.0.0/8        loopback (this box talking to itself). 127.0.0.53 is the
                   local DNS helper (8.16); 127.0.1.1 is Ubuntu's alias for
                   its own hostname in /etc/hosts
169.254.0.0/16     link-local: a machine gives itself one of these when DHCP
                   failed - so seeing one means "no DHCP answer"
255.255.255.255    broadcast to the local network

169.254.169.254 deserves a note: cloud providers answer on that one address from inside every virtual machine they rent you, with details about the machine and even login tokens. Anything on the machine that can make a web request can read it, so security teams care who can reach it.

Later (Ch 16): blocking 169.254.169.254 for applications is a standard rule in shared clusters.

What you can now do

Why it helps

Every networking decision you make later is this one operation. A firewall rule allowing 10.0.3.200/26, a route to 10.20.0.0/16, a subnet in a cloud network: all of them are "which bits are fixed". When a teammate writes a network with host bits set, some tools reject it and Linux silently changes it, and you will know why at a glance.

It also helps with triage. 169.254.x.x on an interface means DHCP got no answer. A program that can reach 169.254.169.254 on a cloud machine can ask for the machine's login tokens, which is a security finding. And in interviews, being able to turn one octet into binary on a whiteboard is what makes the subnet questions easy instead of memorised.

Commands in this lesson

ip apt ipcalc

FAQ

Is a netmask the same as a prefix length?

Yes, two spellings of one fact. 255.255.255.192 is 26 ones followed by 6 zeros, so it is /26. Linux and cloud consoles use the prefix form; older configs and Windows still show dotted masks. A mask octet can only be one of nine values (0, 128, 192, 224, 240, 248, 252, 254, 255), because a mask is always a run of ones then a run of zeros.

What is the difference between 10.0.3.200/26 and 10.0.3.192/26?

The first is an address inside a network, with the prefix telling you the network's size. That is right on an interface. The second is the network itself, with every host bit zero. That is what routes, firewall rules and subnet definitions want. Linux quietly turns the first into the second in a route; other tools reject it. Get in the habit of zeroing the host bits before you write a range down.

Why do I lose two addresses in every subnet?

The first address (all host bits zero) is the network address and the last (all host bits one) is the broadcast address. Neither can go on a machine. So a /26 has 64 addresses and 62 usable hosts. Cloud providers take three more, which lesson 8.9 covers. The exceptions are /31 on links between two routers and /32 for a single address.

What does the "Class A, Private Internet" line in ipcalc mean?

The "Class A" part is history: before 1993, networks were sized by their first octet (classes A, B, C). CIDR replaced that, so it only tells you the first octet is below 128 and changes nothing. "Private Internet" is the useful part: the address is in one of the RFC 1918 private ranges (10/8, 172.16/12, 192.168/16) that the internet never carries.

What is the wildcard mask for?

It is the netmask flipped: ones where the host bits are. /26 has wildcard 0.0.0.63, meaning "the last six bits can be anything". You meet it in the configuration of some routers and firewalls. Linux never asks for it, but if a network engineer hands you a rule with 0.0.0.255 in it, that is a /24.

In an interview Junior

What are the network address, broadcast address and usable range of 10.0.3.200/26?

/26 means the first 26 bits are the network part; the remaining 6 are host bits.

On a real box I would confirm with ipcalc 10.0.3.200/26, which prints the same Network, Broadcast, HostMin/HostMax and Hosts/Net lines.

Also asked: What is the difference between a netmask and a prefix length? · What does 127.0.0.1 mean, and what does 0.0.0.0 mean as a listen address? · How many bits is an IPv4 address, and what is an octet?

Practise this lesson in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.