Subnetting From Scratch: How to Read and Calculate CIDR Notation
Every time you configure a router interface, write a firewall rule, or plan an IP addressing scheme, you are working with subnets and CIDR notation. If those calculations still feel slightly uncertain β or you are studying for CCNA, CompTIA Network+, or a similar certification β this guide walks through the entire process from first principles. No hand-waving, no skipping steps.
What Is an IP Address?
An IP address is a 32-bit number. The dotted-decimal notation you see every day β 192.168.1.100 β is just a human-friendly way to write that number: four groups of eight bits, each expressed as a decimal integer between 0 and 255.
IPv4 Structure: Four Octets, 32 Bits
Each group is called an octet (eight bits). So 192.168.1.100 in full binary is:
192 168 1 100
11000000 10101000 00000001 01100100
That 32-bit string is the actual address the hardware works with. Dotted decimal exists only because humans struggle to memorise 32-bit binary strings.
Why 4 Billion Addresses Ran Out
2^32 = 4,294,967,296. That sounds enormous, but it isn't β not with every smartphone, IoT sensor, cloud VM, and home router needing an address. The internet community anticipated exhaustion in the 1990s and designed two mitigations: NAT (which lets many devices share one public IP) and IPv6 (which uses 128-bit addresses). Subnetting β dividing the available address space into smaller, efficient blocks β is the other key tool. It prevents waste caused by the old classful system that allocated addresses in fixed blocks of millions at a time.
What Is a Subnet?
A subnet (short for sub-network) is a logical subdivision of an IP network. Instead of one flat block of 65,536 addresses for an entire organisation, you divide that block into smaller segments β one per department, floor, function, or security zone.
Network vs. Host Portion
Every IP address is interpreted in two parts simultaneously:
- Network portion β identifies which subnet the address belongs to. All devices on the same subnet share this portion.
- Host portion β identifies the individual device within that subnet.
The subnet mask defines the boundary between the two. In dotted-decimal form, 255.255.255.0 means "the first 24 bits are the network portion; the last 8 bits are the host portion."
Why We Divide Networks Into Subnets
Subnetting has three main benefits:
- Traffic isolation β broadcast traffic stays within the subnet and does not flood the entire network.
- Security segmentation β firewalls and ACLs operate at subnet boundaries, letting you restrict traffic between zones.
- Address efficiency β you allocate only as many host addresses as each segment actually needs, rather than wasting a /16 on a point-to-point link.
Understanding CIDR Notation
CIDR stands for Classless Inter-Domain Routing. It replaced the old classful system (Class A/B/C) in 1993 and is now universal. CIDR notation combines an IP address and a prefix length in a single string:
192.168.1.0/24
The number after the slash is the prefix length β how many bits, counted from the left, belong to the network portion.
What the /24 (Prefix Length) Means
/24 means the first 24 bits are the network. Since there are 32 bits total, that leaves 8 bits for hosts.
- 8 host bits β 2^8 = 256 addresses in the block
- Subtract 2 (network address + broadcast) β 254 usable host addresses
/25 leaves 7 host bits: 2^7 = 128 addresses, 126 usable.
/30 leaves 2 host bits: 2^2 = 4 addresses, 2 usable β the minimal block for a point-to-point link.
How to Convert Between Slash Notation and Dotted-Decimal Mask
Write out 32 bits. Fill the first n bits (where n is the prefix length) with 1s, and the remaining bits with 0s. Then read them as four octets in decimal.
For /24:
11111111 11111111 11111111 00000000
255 255 255 0
Subnet mask: 255.255.255.0
For /22:
11111111 11111111 11111100 00000000
255 255 252 0
Subnet mask: 255.255.252.0
The reverse β converting a mask back to slash notation β is just counting the 1-bits. Use FileCrank's Subnet to CIDR Converter β to do this instantly.
How to Calculate a Subnet by Hand
Working through the arithmetic once cements the concept in a way that tool output alone never will. Here is the systematic process.
Step 1 β Convert to Binary
Take the IP address and write out all 32 bits. For 172.16.5.0:
172 16 5 0
10101100 00010000 00000101 00000000
Step 2 β Identify Network and Host Bits
With a /22 prefix, the first 22 bits are the network portion and the last 10 bits are the host portion. Draw a line at bit 22:
10101100 00010000 000001 | 01 00000000
<---------- network (22 bits) ----> <-- host (10 bits) -->
Notice the split falls in the middle of the third octet. That is the source of most confusion in subnetting β the boundary does not have to align on an octet boundary.
Step 3 β Find Network Address, Broadcast, Usable Range
- Network address: set all host bits to 0.
10101100 00010000 00000100 00000000 β 172.16.4.0 - Broadcast address: set all host bits to 1.
10101100 00010000 00000111 11111111 β 172.16.7.255 - Usable range: network address + 1 through broadcast - 1.
172.16.4.1to172.16.7.254
Worked Example: 172.16.5.0/22
Notice that the input address 172.16.5.0 is a host address within the subnet β the network address of that /22 block is 172.16.4.0. This is a common exam trick: the address given is not always the network address itself.
Tip: Verify your hand calculations immediately against FileCrank's IPv4 Subnet Calculator β. Paste in
172.16.5.0/22and confirm all six values match before moving on to harder exercises.
Common Subnet Sizes at a Glance
The /24 is by far the most common in practice because 254 hosts is the right size for most VLANs, and the arithmetic is trivial (the host portion is always the last octet).
Using the FileCrank Subnet Calculator
For day-to-day work β writing firewall rules, planning address allocation, verifying a config β you do not need to do binary arithmetic by hand. Enter any IP address with a prefix length into FileCrank's IPv4 Subnet Calculator β and it instantly returns the network address, broadcast, usable range, subnet mask, wildcard mask, and host count.
If you need to see every individual IP address within a CIDR block β useful when configuring whitelists or auditing allocations β the CIDR Range Expander β lists them all. Both tools run entirely in your browser: no data leaves your device, no account required.
For quick access to all subnet and CIDR utilities in one place, the networking tools β hub lists all 24 tools.
What Is VLSM and Why Does It Matter for Exam Candidates?
Variable Length Subnet Masking (VLSM) extends basic subnetting by allowing different subnets within the same network to use different prefix lengths. Instead of carving a /24 into four equal /26s (62 usable hosts each), VLSM lets you allocate exactly the block size each segment needs.
Example: You have 10.0.0.0/24 to distribute across four segments:
VLSM minimises address waste and is tested heavily on CCNA and Network+ exams. The key skill examiners test is: given a requirement (number of hosts), identify the smallest prefix that satisfies it, then allocate non-overlapping blocks from the address space in order.
Both the CCNA and Network+ exam simulations give you a fixed address pool and ask you to subnet it for multiple requirements simultaneously β VLSM is the only practical approach. Practising with hand calculations and verifying with the IPv4 Subnet Calculator β is the fastest way to build fluency.
Frequently Asked Questions
What is the difference between a subnet mask and a wildcard mask?
A subnet mask has 1s in the network portion and 0s in the host portion. A wildcard mask is its bitwise inverse β 0s in the network portion and 1s in the host portion. Wildcard masks are used in Cisco ACLs and OSPF network statements. For a /24, the subnet mask is 255.255.255.0 and the wildcard is 0.0.0.255.
What does "host bits all zero" and "host bits all one" mean?
When all host bits are 0, the address is the network address β it identifies the subnet itself and cannot be assigned to a device. When all host bits are 1, the address is the broadcast address β packets sent here are delivered to every host on the subnet. Neither can be used as a host address.
Can two subnets overlap?
No. Overlapping subnets cause routing ambiguity: the router cannot determine which interface to forward a packet through. Always verify that newly allocated blocks do not contain addresses already in use by checking their ranges do not intersect.
What is the smallest subnet I should use on a point-to-point link?
A /30 (4 addresses: network, two hosts, broadcast) is the traditional choice. A /31 (RFC 3021) provides exactly 2 addresses with no network or broadcast β valid for point-to-point use in most modern IOS/NX-OS versions and generally preferred because it wastes no addresses.
How do I convert a subnet mask to CIDR notation?
Count the contiguous 1-bits in the binary representation of the mask. 255.255.255.0 = 24 ones = /24. 255.255.252.0 = 22 ones = /22. FileCrank's Subnet to CIDR Converter β does this in one step.
Why does my router show a "host route" with /32?
A /32 has zero host bits β it is a route to a single specific address, not a network. Routers use /32 host routes to force specific next-hops for individual addresses (common in BGP, loopback interfaces, and policy-based routing).