Toolkit
All tools
Network reference · Free

IPv4 Subnet Calculator

Give it an address and a prefix and get the whole picture back: network and broadcast addresses, the usable host range, both masks, and the 32 bits laid out in binary with the network and host halves separated.

Pure arithmetic in this browser · No lookups, nothing uploaded

Network 192.168.1.128/26. Mask 255.255.255.192. Broadcast 192.168.1.191. Usable range 192.168.1.129 to 192.168.1.190, 62 usable of 64 addresses.

The address field also takes 192.168.1.130/26 or 192.168.1.130 255.255.255.192 whole, and the mask field takes either form.

Prefix length255.255.255.192 · wildcard 0.0.0.63 · 62 usable
/26
/0/8/16/24/32
Try
Binary

Where the network ends and the host begins

The prefix is a count of bits, not a number of addresses. Everything left of the rule is fixed for every machine on this subnet; everything right of it is what tells them apart.

ValueOctet 1Octet 2Octet 3Octet 4
Address
192.168.1.130
11000000
192
10101000
168
00000001
1
10000010
130
Subnet mask
255.255.255.192
11111111
255
11111111
255
11111111
255
11000000
192
Network
192.168.1.128
11000000
192
10101000
168
00000001
1
10000000
128
Broadcast
192.168.1.191
11000000
192
10101000
168
00000001
1
10111111
191
26 network bits6 host bitsPrefix boundary

Setting every one of the 6 host bits to 0 gives 192.168.1.128, the network address; setting them all to 1 gives 192.168.1.191. Every address in between belongs to this subnet, which is why 2^6 is 64.

The address itself

Other notations, and what this address is for

Hexadecimal
0xC0A80182
Dotted hex
C0.A8.01.82
32-bit integer
3232235906
Binary
11000000.10101000.00000001.10000010
Private (RFC 1918)192.168.0.0/16

The smallest RFC 1918 block and the one home equipment ships with. 65,536 addresses, normally handed out as /24s.

RFC 1918 space is unrouteable on the public internet, which is not the same as unreachable. A VPN, a misconfigured route, or anything already inside the perimeter reaches it perfectly well; treat private addressing as an addressing decision, never as a security control.

Historical classClass Cfirst octet 192–223 · 192.0.0.0 – 223.255.255.255default /24

Three octets of network and one of host: 254 usable addresses, which is why “a class C” is still shorthand for a /24.

Classful addressing was replaced by CIDR in 1993 and no current router uses it. The class is shown because the vocabulary survived, not because it constrains anything; this address’s real prefix is /26, whatever its first octet suggests.

Divide the block

Cut it into equal subnets

Borrowing host bits for the network part splits the block in half for every bit taken. Each extra bit doubles the number of subnets and halves the size of each one.

2 bits borrowed · 255.255.255.240
4 subnets × 16 addresses

The /28 subnets inside 192.168.1.128/26
#SubnetUsable rangeBroadcast
0192.168.1.128/28192.168.1.129 – 192.168.1.142192.168.1.143
1192.168.1.144/28192.168.1.145 – 192.168.1.158192.168.1.159
2192.168.1.160/28192.168.1.161 – 192.168.1.174192.168.1.175
3192.168.1.176/28192.168.1.177 – 192.168.1.190192.168.1.191

All 4 subnets are listed. The highlighted row is the one holding 192.168.1.130.

Reference

Every prefix from /8 to /32

Subnet mask, wildcard mask, and host count for each prefix length
PrefixMaskWildcardUsable
/8255.0.0.00.255.255.25516,777,214
/9255.128.0.00.127.255.2558,388,606
/10255.192.0.00.63.255.2554,194,302
/11255.224.0.00.31.255.2552,097,150
/12255.240.0.00.15.255.2551,048,574
/13255.248.0.00.7.255.255524,286
/14255.252.0.00.3.255.255262,142
/15255.254.0.00.1.255.255131,070
/16255.255.0.00.0.255.25565,534
/17255.255.128.00.0.127.25532,766
/18255.255.192.00.0.63.25516,382
/19255.255.224.00.0.31.2558,190
/20255.255.240.00.0.15.2554,094
/21255.255.248.00.0.7.2552,046
/22255.255.252.00.0.3.2551,022
/23255.255.254.00.0.1.255510
/24255.255.255.00.0.0.255254
/25255.255.255.1280.0.0.127126
/26255.255.255.1920.0.0.6362
/27255.255.255.2240.0.0.3130
/28255.255.255.2400.0.0.1514
/29255.255.255.2480.0.0.76
/30255.255.255.2520.0.0.32
/31255.255.255.2540.0.0.12
/32255.255.255.2550.0.0.01
Sizing

Pick a prefix from a host count

Work the arithmetic backwards: say how many hosts have to fit and take the smallest block that holds them.

Smallest fit
/23
Usable hosts
510

Mask 255.255.254.0, wildcard 0.0.1.255, with 10 addresses spare. Leave room to grow: re-addressing a live subnet is far more work than taking one extra bit now.

How it works

Thirty-two bits, split in one place.

An IPv4 address is a single 32-bit number that we write as four decimal octets because nobody wants to read 3232235906. The prefix says how many of those bits, counting from the left, identify the network; whatever is left identifies a host inside it. Every value a subnet calculator returns falls out of that one split. Set the host bits all to 0 and you have the network address; set them all to 1 and you have the broadcast. The mask is simply the prefix drawn as an address (1 bits for the network part, 0 bits for the host part), and the wildcard mask is that inverted. Because the boundary can sit anywhere in the 32 bits rather than only on an octet edge, a /26 splits an octet down the middle, which is why 192.168.1.130 belongs to 192.168.1.128 and not to 192.168.1.0.

  1. 01

    Type the address, with or without the slash

    192.168.1.130/26 works whole, and so does the address on its own with a prefix or a dotted mask in the field beside it. Leading zeros, out-of-range octets, and non-contiguous masks are each refused with the specific reason rather than a blanket rejection.

  2. 02

    Drag the prefix and watch the block move

    The slider runs from /0 to /32. Every value on the page redraws as it moves, so the moment a /24 becomes a /25 you can see the network address shift, the host count halve, and the boundary in the binary view step one bit to the right.

  3. 03

    Read the answer, then divide the block

    The dark panel holds the network, the broadcast, the usable range, and both masks with a copy button on each. Below it, choose a longer prefix to list the equal-size subnets the block contains.

Built for people who subnet at 2am

Every derived value, and the bits behind it.

The binary view is the point

Address, mask, network, and broadcast in dotted binary with a rule drawn exactly where the prefix ends. Nothing explains why 192.168.1.130/26 lands in 192.168.1.128 as quickly as seeing the last six bits go quiet.

The /31 and /32 cases handled properly

A /31 is not a subnet with no hosts: RFC 3021 makes both of its addresses usable on a point-to-point link and there is no broadcast address to reserve. A /32 is a single host route. Both are reported as what they are rather than as arithmetic that went wrong.

Masks in either direction

Give it /26 or 255.255.255.192 and it takes both. A non-contiguous mask is rejected with the offending bit pattern printed, and a wildcard mask pasted into the mask field is recognised and named instead of dismissed.

Equal-size subnet division

Pick a longer prefix and every child subnet is listed with its network, usable range, and broadcast, with the one holding your address highlighted. Past 256 rows the list says exactly how many were left out; it never truncates silently.

Accurate address classification

RFC 1918 private space, loopback, link-local, CGNAT, multicast, the documentation blocks, and the limited broadcast address are each identified by the block they fall in. The A-to-E class is shown too, labelled as the history it is.

Hex, decimal, and a prefix reference

The 32-bit integer and hexadecimal forms for the times a log or an API wants them, and a full /8 to /32 table of masks, wildcards, and host counts. Every derived value has a copy button.

Subnetting questions

CIDR, host counts, wildcard masks, and the special prefixes.

What does the /24 in 192.168.1.0/24 actually mean?+

It is a count of bits, not a count of addresses. An IPv4 address is 32 bits, and the prefix says how many of them from the left are fixed for every machine on the network. /24 fixes the first 24 bits (192.168.1) and leaves 8 bits free, which is 256 combinations. That notation is called CIDR, and it replaced the old class system in 1993 precisely because a network's size stopped having to match an octet boundary: /23 and /25 are just as legal as /24, and are how blocks are actually allocated.

Why does a /24 have 254 usable hosts and not 256?+

Two of the 256 are spoken for. The address with every host bit set to 0 (192.168.1.0) is the network address, which names the subnet in a routing table and is not assignable to an interface. The address with every host bit set to 1 (192.168.1.255) is the directed broadcast, received by every host on the segment. That leaves .1 through .254. The same subtraction applies at every size, which is why a /26 gives 62 rather than 64, and why a /30 gives only 2 out of 4.

How can a /31 have two usable addresses when a /30 has two out of four?+

Because RFC 3021 waived the reservation for that one case. A /31 holds exactly two addresses, so reserving one for the network and one for the broadcast would leave nothing at all. On a point-to-point link between two routers there is no need for a broadcast address (there is only one other device, and sending to it is the same as broadcasting), so both addresses are assigned and the link stops wasting half a /30. Every current router supports it; some older host stacks still refuse, which is the only reason /30 remains common.

What is a wildcard mask and where would I use one?+

It is the bitwise inverse of the subnet mask: where the mask has 1 bits, the wildcard has 0. The mask for a /24 is 255.255.255.0, so the wildcard is 0.0.0.255. The convention is inverted because it answers a different question: a mask marks the bits that must match, a wildcard marks the bits that are free to vary. Cisco IOS access lists and OSPF network statements take wildcard masks, which is why an ACL reads 192.168.1.0 0.0.0.255 rather than the mask you would put on an interface. Getting the two the wrong way round is a classic way to write a rule that matches far more than intended.

Why is 255.255.0.255 not a valid subnet mask?+

Because its 1 bits are not contiguous. A mask has to be an unbroken run of 1s followed by an unbroken run of 0s, because that is the only shape a prefix can take: routing hardware matches a leading run of bits and can express “the first N bits” but not “these particular scattered bits”. Early implementations technically permitted discontiguous masks and the results were unroutable, so CIDR ruled them out. If you find yourself wanting one, what you actually need is either a different prefix or a firewall rule.

How do I pick a prefix for the number of hosts I need?+

Work out the number of interfaces (not people, and remembering that printers, access points, and the gateway itself each take one), then find the smallest block whose usable count still exceeds it. 25 hosts needs a /27, because a /27 gives 30 and a /28 gives only 14. Then take one more bit than the arithmetic demands if the segment could plausibly grow, because re-addressing a live subnet is far more disruptive than allocating a slightly larger block on day one. The sizing panel on this page does the lookup, and the reference table shows the whole ladder.

Does using 10.x or 192.168.x make a network private in a security sense?+

No. RFC 1918 addresses are unroutable on the public internet, which means no ISP will carry them; it does not mean nothing can reach them. Anything already inside the perimeter reaches them perfectly well: a VPN client, a compromised laptop, a container on the same host, or a misconfigured route between two sites that both used 192.168.1.0/24. Private addressing is an addressing decision that conserves public space and forces traffic through a NAT; treat the firewall, not the address range, as the control.

Why is 172.16.0.0/12 sometimes written as 172.16 to 172.31?+

Because the /12 boundary does not fall on an octet. Twelve fixed bits cover the first octet and the top four bits of the second, so the second octet is free to range over 16 through 31: 172.16.0.0 up to 172.31.255.255. It catches people out in both directions: 172.15.0.0 and 172.32.0.0 are public addresses belonging to someone else, and writing the block as 172.16.0.0/16 quietly discards fifteen sixteenths of the private space available.

More focused tools, ready when you are.

Explore the growing collection for calculations, documents, writing, and everyday work.

Browse all tools