Why this matters
"Is a /27 big enough for 40 machines?" "Is this IP one of ours?" You will be asked this in reviews, in tickets and in interviews, usually with no calculator in sight. One formula and one four-step method answer all of it.
What you need to know already: 8.1 - prefix length, network and broadcast address, block size = 256 minus the mask octet.
CIDR (Classless Inter-Domain Routing) is simply the address/prefix notation: 10.0.0.0/16. People say "a CIDR" or "a CIDR block" for a range written that way.
The one formula
addresses in a block = 2^(32 - prefix)
usable hosts = 2^(32 - prefix) - 2
2^n means 2 multiplied by itself n times. Minus two because the first address is the network and the last is the broadcast; neither goes on a machine.
Learn this table. It comes up in interviews, reviews and every "is that range big enough":
/32 = 1 one address - how you write a single IP in a route or rule
/31 = 2 links between exactly two routers only (both usable)
/30 = 4 2 usable
/29 = 8 6 usable
/28 = 16 14 usable
/27 = 32 30 usable
/26 = 64 62 usable
/25 = 128 126 usable
/24 = 256 254 usable
/23 = 512
/22 = 1,024
/21 = 2,048
/20 = 4,096
/19 = 8,192
/18 = 16,384
/16 = 65,536
/12 = 1,048,576 172.16.0.0/12
/8 = 16,777,216 10.0.0.0/8
The pattern: each bit you take off the prefix doubles the block. If you know /24 is 256, then /22 is 256 x 4 = 1024 and /20 is 256 x 16 = 4096. That is how you rebuild the table when your memory blanks.
Network, broadcast and range by hand: the block-size method
Four steps, for any address and prefix:
- Find the interesting octet - the one the prefix ends in. /8-/15 = 2nd, /16-/23 = 3rd, /24-/32 = 4th.
- Block size = 256 minus the mask value of that octet.
- Network = the largest multiple of the block size at or below the octet's value. Octets to the right become 0.
- Broadcast = network + block - 1 in that octet; octets to the right become 255.
Worked, 10.40.77.130/19:
1. /19 is in the 3rd octet (16..23)
2. mask octet for /19 is 224 (three 1s: 128+64+32), block = 256 - 224 = 32
3. 77 -> largest multiple of 32 at or below it is 64 network 10.40.64.0
4. 64 + 32 - 1 = 95 broadcast 10.40.95.255
hosts 10.40.64.1 - 10.40.95.254, 8190 of them
Check it:
$ ipcalc -b 10.40.77.130/19
Address: 10.40.77.130
Netmask: 255.255.224.0 = 19
Wildcard: 0.0.31.255
=>
Network: 10.40.64.0/19
HostMin: 10.40.64.1
HostMax: 10.40.95.254
Broadcast: 10.40.95.255
Hosts/Net: 8190 Class A, Private Internet
Another in the last octet, 192.168.10.77/27:
block = 256 - 224 = 32
77 -> 64 network 192.168.10.64
64 + 31 = 95 broadcast 192.168.10.95
hosts .65 - .94 30 usable
And one where the interesting octet is the second, 10.77.3.4/12:
/12 is in the 2nd octet, mask 255.240.0.0, block 16
77 -> 64 network 10.64.0.0
64 + 15 = 79 broadcast 10.79.255.255
Does IP X fall inside range Y?
Work out Y's network and broadcast, then compare. Only the interesting octet needs thought; octets to its left must match exactly.
Is 10.1.5.9 in 10.1.0.0/16? /16 -> first two octets must match. Yes.
Is 10.1.5.9 in 10.1.4.0/23? block 2 in the 3rd octet: 4-5. Yes.
Is 10.1.6.9 in 10.1.4.0/23? 6 is outside 4-5. No.
Is 172.31.9.9 in 172.16.0.0/12? block 16 in the 2nd octet: 16-31. Yes.
Is 172.32.0.1 in 172.16.0.0/12? 32 is outside 16-31. No - and it is PUBLIC.
That last one is a real trap: people assume "172.anything" is private.
Private and public addresses
A public address is unique on the whole internet and reachable from it. Private addresses are three ranges set aside for internal use; anyone can use them inside their own network, and the internet never carries them. They are written down in RFC 1918 (an RFC is one of the numbered documents that define internet standards):
10.0.0.0/8 10.0.0.0 - 10.255.255.255 16.7M addresses
172.16.0.0/12 172.16.0.0 - 172.31.255.255 1M addresses
192.168.0.0/16 192.168.0.0 - 192.168.255.255 65k addresses
Your lab network (10.64.0.0/24) is one; your home Wi-Fi (usually 192.168.x) is another. Because everyone picks from the same three ranges, two companies (or two teams) often pick the same one. That overlap problem is the next lesson.
/31 and /32
/32 is a single address. You write it in routes and firewall rules when you mean exactly one machine:
$ ipcalc -b 10.0.3.53/32
Address: 10.0.3.53
Netmask: 255.255.255.255 = 32
Wildcard: 0.0.0.0
=>
Hostroute: 10.0.3.53
Hosts/Net: 1 Class A, Private Internet
Hostroute is ipcalc's name for a one-address route. /31 has no room for a network and a broadcast address, so a standard (RFC 3021) lets both addresses be used on a link between exactly two routers. You will not see it on normal server networks.
Split a range into equal parts
Adding n bits to the prefix gives 2^n equal pieces. Four pieces = two bits:
10.0.0.0/16 -> four /18s, block 64 in the 3rd octet
10.0.0.0/18 10.0.0.0 - 10.0.63.255
10.0.64.0/18 10.0.64.0 - 10.0.127.255
10.0.128.0/18 10.0.128.0 - 10.0.191.255
10.0.192.0/18 10.0.192.0 - 10.0.255.255
ipcalc splits for you when you give it a second, longer prefix:
$ ipcalc -b 10.0.0.0/22 24
Address: 10.0.0.0
Netmask: 255.255.252.0 = 22
Wildcard: 0.0.3.255
=>
Network: 10.0.0.0/22
HostMin: 10.0.0.1
HostMax: 10.0.3.254
Broadcast: 10.0.3.255
Hosts/Net: 1022 Class A, Private Internet
Subnets after transition from /22 to /24
Netmask: 255.255.255.0 = 24
Wildcard: 0.0.0.255
1.
Network: 10.0.0.0/24
...
4.
Network: 10.0.3.0/24
...
Subnets: 4
Hosts: 1016
A subnet is one of those smaller pieces carved out of a bigger range. Note the last line: four /24s have 1016 usable hosts between them, while the one /22 had 1022. Every split costs two addresses per subnet. Many tiny subnets waste space.
How to practise
Do the arithmetic first, then run ipcalc as the answer key. The drill after this lesson hands you random addresses and does not count the round if you ran ipcalc before writing your answer. That is on purpose: the tool is always on a real box, but not in an interview or a design meeting.
What you can now do
- Say how many addresses and hosts any prefix holds.
- Find network, broadcast and host range with the four steps.
- Tell private from public addresses, including the 172.16/12 trap.