Type an IP address with a prefix such as /26 or a mask such as 255.255.255.192, or drag the slider. The calculator shows the network, the first and last usable addresses, the broadcast address and the masks, colours the network and host bits so you can see where the boundary falls, and explains in plain words how many devices fit and which address is usually the gateway.
Table of Contents
Subnets in plain words
An IP address has two parts. The network part says which street a device is on and is the same for every device in the subnet; the host part is the house number and is different for each device. The prefix, such as /24, says how many of the 32 bits belong to the network part. The bigger the prefix, the smaller the subnet: a /24 has 256 addresses, a /26 has 64 and a /30 has 4.
Two addresses in every subnet are reserved: the first one names the network and the last one is the broadcast address. That is why a /24 has 254 usable addresses, not 256.
Reading the bit view
The orange bits are the network part and the blue bits are the host part. Moving the slider one step to the right turns one host bit into a network bit and halves the number of addresses. The map below the bits shows the neighbouring subnets of the same size inside the parent block; click one to open it.
Quick CIDR reference
/24 = 255.255.255.0 with 254 hosts, /25 = 126 hosts, /26 = 62, /27 = 30, /28 = 14, /29 = 6 and /30 = 2 for point-to-point links. A /31 has two usable addresses and no broadcast (RFC 3021), and a /32 is a single address. The wildcard mask is the inverse of the subnet mask and is what Cisco ACLs and OSPF network statements expect.
Everything is calculated in your browser; nothing is sent to our server.
Splitting a network
Open the split section and choose a longer prefix to carve the network into equal subnets, for example a /24 into four /26 networks for separate VLANs. Each row shows the usable range and broadcast address, and clicking a subnet opens it in the calculator.
IP Subnet Calculator (IPv4 CIDR) at a glance



How to use this tool
- Type an IPv4 address in one of three forms:
192.168.1.10/24,192.168.1.10 255.255.255.0or192.168.1.10 0.0.0.255. The last one is a wildcard mask as used in Cisco ACLs; the calculator recognises it and converts it to /24. - If you type only an address, the prefix currently selected in the dropdown is kept.
- Change the size with the dropdown (every prefix from /32 to /0 with its mask), the slider or the preset buttons for /24 to /30, /16 and /8. Results update as you type; there is no submit button.
- Click a block in the map, a row in the split table or a prefix in the cheat sheet to open that network.
- The calculator is IPv4 only. For IPv6 prefixes use the IPv6 subnet calculator.
How to read the results
| Result | What it shows |
|---|---|
| Network | The network address with the prefix, for example 192.168.10.0/26: your address with all host bits set to zero. This is the value to use in routes, firewall rules and VPC settings. |
| Usable hosts | Addresses you can give to devices: total minus two for prefixes from /0 to /30, 2 for a /31, 1 for a /32. The total block size is shown underneath. |
| First usable, Last usable | Network address plus one and broadcast minus one. For a /31 both addresses are usable; for a /32 the single address is shown in both. |
| Broadcast | The last address of the block. Shown as none for /31 and /32. |
| Subnet mask | The dotted mask (255.255.255.192) with the wildcard mask (0.0.0.63) under it. |
| Address type | What kind of address you typed: public, private (RFC 1918), carrier-grade NAT (100.64.0.0/10), loopback, link-local (169.254.0.0/16), documentation (192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24), benchmark (198.18.0.0/15), multicast, reserved or “this network” (0.0.0.0/8). |
| Where this subnet sits | The parent /24, /16 or /8 block divided into networks of your size. It is drawn only for 256 blocks or fewer and not for prefixes shorter than /8. |
| Position | Which address of the block you typed, for example “address number 35 of 64”. Number 1 means you typed the network address itself. |
| IP as a number, IP in hex | The address as a 32-bit decimal and hexadecimal value, as stored by databases and some firewalls. |
| Reverse DNS zone | The in-addr.arpa zone on the nearest octet boundary: the /24 zone for /24 and longer prefixes, the /16 zone for /16 to /23, otherwise the /8 zone. |
| Legacy class, IPv4-mapped IPv6 | The old class A to E (no longer used for routing) and the ::ffff: form the address takes on dual-stack sockets. |
The split section divides the network into subnets up to 12 bits longer (up to 4,096 subnets) and lists the first 256 with their usable range and broadcast address. The cheat sheet lists /16 to /32 with mask, wildcard, size and usable hosts.
Common problems and how to fix them
“Enter an IPv4 address such as 192.168.1.10, optionally with /24 or a mask like 255.255.255.0.”
The input is not an IPv4 address: an octet is above 255, there are not exactly four octets, there is extra text, or it is an IPv6 address or hostname. Remove everything except the address and the prefix or mask.
“The mask must be a run of 1 bits followed by 0 bits, e.g. 255.255.255.192.”
A mask such as 255.255.0.255 is neither a subnet mask nor a wildcard mask, because its 1 bits are not contiguous. Valid last octets are 0, 128, 192, 224, 240, 248, 252, 254 and 255. “That subnet mask is not valid.” means an octet of the mask is above 255; “The prefix must be between /0 and /32.” means the number after the slash is too large.
Linux: “Error: Invalid prefix for given prefix length.”
You gave ip route an address with host bits set, such as 192.168.10.34/26. Routes need the network address, which is the Network card in this calculator:
ip route add 192.168.10.0/26 via 192.168.1.1 # correct
ip route add 192.168.10.34/26 via 192.168.1.1 # fails
Linux: “Error: Nexthop has invalid gateway.”
The gateway is not inside any subnet configured on the server, usually because the interface has the wrong prefix (a /32 instead of /24, for example). Check with ip -4 addr show and ip route. Some providers deliberately give a /32 with a gateway outside it; then the route needs the onlink flag:
ip route add default via 203.0.113.1 dev eth0 onlink
Two hosts on the same switch cannot reach each other
Their masks probably differ. If 192.168.1.10 has /24 and 192.168.1.200 has /25, the second host treats .10 as outside its network (its block is 192.168.1.128/25) and sends the traffic to the gateway. Enter each address with its own mask here; if the Network values differ, fix the mask. On Windows run ipconfig, on Linux ip -4 addr show.
VPN users cannot reach the office network
The office LAN and the user’s home LAN use the same range, very often 192.168.0.0/24 or 192.168.1.0/24, so the client sends office traffic to its own home network. Renumber the office (or the VPN pool) into a less common block such as 10.20.0.0/16 or 172.20.0.0/16. Enter both networks here and compare the address ranges to check for overlap. If the VPN also feels slow, see VPN MTU fragmentation.
A cloud subnet has fewer free addresses than the calculator shows
AWS and Azure each reserve five addresses per subnet: the network address, the next three (router and DNS) and the last address. A /24 therefore gives 251 usable addresses there, and a /28 gives 11. AWS also allows subnet sizes only between /16 and /28.
Planning subnets of different sizes
When groups need different sizes, allocate the largest subnet first. Each block must start on a multiple of its own size, and taking the big blocks first keeps the space free of gaps. Splitting 192.168.10.0/24 for an office:
| Use | Need | Subnet | Usable range | Broadcast |
|---|---|---|---|---|
| Staff | 100 hosts | 192.168.10.0/25 | 192.168.10.1 – 192.168.10.126 | 192.168.10.127 |
| Servers | 50 hosts | 192.168.10.128/26 | 192.168.10.129 – 192.168.10.190 | 192.168.10.191 |
| Guest Wi-Fi | 25 hosts | 192.168.10.192/27 | 192.168.10.193 – 192.168.10.222 | 192.168.10.223 |
| Management | 10 hosts | 192.168.10.224/28 | 192.168.10.225 – 192.168.10.238 | 192.168.10.239 |
| Router link 1 | 2 hosts | 192.168.10.240/30 | 192.168.10.241 – 192.168.10.242 | 192.168.10.243 |
| Router link 2 | 2 hosts | 192.168.10.244/30 | 192.168.10.245 – 192.168.10.246 | 192.168.10.247 |
That leaves 192.168.10.248/29 free for later. Leave room to grow: a subnet that is 80 percent full today will need renumbering, which is far more work than starting one size larger. For the VLAN side of this, see pfSense VLANs with a managed switch.
Official documentation: RFC 4632 (CIDR), RFC 1918 (private addresses), RFC 3021 (/31 links).
Related guides: pfSense VLAN Setup with a Managed Switch: Easy 2026 Guide · Install OPNsense 26.7 and set up basic firewall and NAT rules · VPN MTU Fragmentation: Proven Fixes for Slow VPN Throughput.
Frequently asked questions
How many usable hosts are in a /26?
62: a /26 has 64 addresses, minus the network address and the broadcast address.
What is a wildcard mask?
The inverse of the subnet mask, for example 0.0.0.63 for a /26. Cisco ACLs and routing protocols such as OSPF use it to say which bits must match.
Which ranges are private?
10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 (RFC 1918) are private, and 100.64.0.0/10 is shared address space for carrier-grade NAT. They are not routed on the public internet.
Which address should be the gateway?
Any usable address works. Most networks use the first usable address, such as 192.168.1.1, and some hosting providers use the last one, so check your provider’s settings.
Can I enter a wildcard mask instead of a subnet mask?
Yes. Type the address followed by the wildcard, for example 10.0.0.5 0.0.0.255, and the calculator converts it to the matching prefix, here /24.
Does this calculator support IPv6?
No, it handles IPv4 only. Use the separate IPv6 subnet calculator for IPv6 prefixes such as /48 or /64.
How many usable addresses does a /28 have on AWS or Azure?
Eleven. A /28 has 16 addresses and both clouds reserve five of them in every subnet: the first four and the last one.
Should I use a /30 or a /31 for a router-to-router link?
A /31 saves two addresses and is defined for point-to-point links in RFC 3021, but every device on the link must support it. A /30 works everywhere and leaves two usable addresses.
How do I know whether an address is the network address?
Check the Position row. If it says address number 1, you typed the network address, which should not be assigned to a device in a normal subnet.
Why does a /22 need four reverse DNS zones?
Reverse zones are usually delegated per /24, and a /22 covers four /24 blocks. Each of them needs its own in-addr.arpa zone or delegation.