IPv4 CIDR Range Calculator
All articles

IPv4 CIDR Explained: Subnet Masks and IP Ranges

Learn IPv4 history, binary addressing, subnet masks and CIDR calculations, including network, broadcast and usable ranges for /24, /22 and other prefixes.

Futuristic IPv4 address divided into four binary octets and branching into organized CIDR subnet ranges

Introduction

Every device that communicates through an IPv4 network depends on two related ideas: an address identifies where an interface belongs, and a prefix tells routers which part of that address represents a network. Home routers, cloud virtual networks, corporate VLANs, VPNs, firewalls, container platforms and Internet service providers all use this network-and-host division.

An address such as 192.168.6.130 is incomplete for routing analysis unless its prefix is known. With /24 it belongs to the range 192.168.6.0 through 192.168.6.255; with /22 it belongs to the larger range 192.168.4.0 through 192.168.7.255. The digits did not change, but the boundary between network bits and host bits did.

This article develops the idea from the origin of the Internet Protocol through binary arithmetic, classful networks, subnet masks, CIDR, private ranges and modern routing. You can verify every worked example with the utily.tools IPv4 CIDR Range Calculator while following the reasoning.

From interconnected networks to a 32-bit address

IP means Internet Protocol. It was designed to move independent datagrams across interconnected packet-switched networks, even when those underlying networks used different technologies. IP supplies addressing, forwarding and fragmentation rules, but it deliberately does not promise delivery, ordering or retransmission; protocols such as TCP add reliability when an application needs it.

The January 1980 specification in RFC 760 and the September 1981 specification in RFC 791 describe Internet Protocol version 4. The version number is carried in a four-bit field at the beginning of every IP header so a receiver can identify the header format. IPv4 is therefore the protocol whose Version field has value 4, not simply a marketing name for a fourth consumer release.

RFC 791 defines an IPv4 address as four octets, or 32 bits. An octet is exactly eight bits. For human readability, the four octets are written as decimal numbers separated by periods, producing dotted-decimal notation such as 203.0.113.42. The binary value remains what routers process; the decimal form is a convenient representation.

IPv4 provides 2^32 distinct bit patterns, equal to 4,294,967,296 addresses. That once seemed extremely large, but global growth, inefficient early allocation and routing-table pressure exposed its limits. CIDR made allocation far more flexible and enabled route aggregation, while IPv6 later expanded addresses from 32 to 128 bits.

Technical foundations and behavior

A CIDR calculation is a boundary calculation over a 32-bit unsigned value. The prefix length says how many most-significant bits are fixed as the network portion. All remaining bits form the host portion and can vary from all zeroes to all ones inside the block.

The calculation is deterministic: construct a contiguous subnet mask, retain the network bits, clear the host bits for the first address and set every host bit for the last address. Decimal notation hides this structure, so understanding the binary form makes every prefix from /0 to /32 predictable.

Why an octet has values from 0 to 255

Eight binary positions have weights 128, 64, 32, 16, 8, 4, 2 and 1. When every bit is zero the value is 0. When every bit is one, their sum is 255. There are 256 possible combinations because 2^8 equals 256, but the values are numbered from 0 through 255. Decimal 256 requires a ninth bit and therefore cannot fit in one IPv4 octet.

Prefix length and subnet mask

A /22 prefix means that the first 22 bits are network bits and the remaining 10 are host bits. Its mask is twenty-two ones followed by ten zeroes, which becomes 255.255.252.0 in dotted decimal. A valid CIDR mask is contiguous: once a zero appears, every following bit is also zero.

Network, broadcast and usable hosts

The network address has every host bit set to zero. The directed broadcast address has every host bit set to one. In traditional subnets through /30, those two endpoints are reserved, so usable hosts begin one address after the network and end one address before the broadcast. RFC 3021 gives /31 point-to-point links different semantics, and /32 identifies one host route.

Block size and alignment

With p prefix bits, the number of host bits is 32 - p and the block contains 2^(32-p) addresses. CIDR blocks are aligned to their own size. A /22 contains 1,024 addresses, so valid boundaries occur every four values in the third octet: 0, 4, 8, 12 and so on.

Real-world applications

Cloud virtual networks

A platform team divides a private /16 into smaller application, database and management subnets without overlapping address ranges.

Firewall and access-control rules

A security rule permits one CIDR prefix rather than maintaining hundreds of individual addresses, making the intended trust boundary explicit.

Routing and aggregation

An ISP or enterprise advertises one aligned aggregate that covers several contiguous child networks, reducing routing-table entries.

Incident investigation

An operator checks whether a source address belongs to an expected subnet and identifies the exact network and broadcast boundaries.

Standards and deeper technical reference

How IP emerged and why the protocol is called IPv4

Early packet networks could move data inside their own systems, but connecting heterogeneous networks required a common layer above each local technology. The Internet Protocol was created to carry datagrams from a source to a destination through gateways, now called routers. RFC 760 states that its 1980 text was based on five earlier editions of the ARPA Internet Protocol specification; RFC 791 then standardized the familiar September 1981 design.

The first four bits of an IP header are the Version field. RFC 760 and RFC 791 both state that their header format is version 4. This is the precise origin of “IPv4”: receivers see the value 4 and interpret the remaining header accordingly. The number reflects protocol-format evolution during the research process, not four generations of the public Internet.

Version number 5 was later associated with the experimental Internet Stream Protocol, whose ST-II specification says that ST uses IP Version Number 5. It did not replace IPv4. The standardized successor was named IPv6; RFC 8200 describes IPv6 as the successor to IPv4 and expands addresses from 32 to 128 bits.

Selected milestones in IP addressing
DateDocumentImportance
January 1980RFC 760DoD Internet Protocol specification describing version 4
September 1981RFC 791Foundational IPv4 specification with 32-bit addresses
August 1985RFC 950Standardized address masks and subnetting
September 1993RFC 1519Introduced the CIDR assignment and aggregation strategy
February 1996RFC 1918Reserved three address blocks for private internets
December 2000RFC 3021Standardized /31 use on point-to-point links
August 2006RFC 4632Current CIDR address assignment and aggregation plan
July 2017RFC 8200Current base IPv6 specification

What IP does — and what it intentionally does not do

IPv4 is a network-layer, connectionless datagram protocol. A sender places a source address, destination address and upper-layer protocol identifier in a header, and routers independently forward the datagram toward the destination. Each router may select a next hop from its routing table; the path is not reserved in advance.

RFC 791 does not promise reliability, acknowledgements, retransmission, ordering or flow control. A datagram may be lost, duplicated, delayed or delivered out of order. TCP can provide an ordered reliable byte stream above IP, while UDP exposes a lightweight datagram service. Separating these responsibilities allowed the same IP layer to support many applications and link technologies.

Address
Identifies the source and destination used by the network layer.
Prefix
Identifies a contiguous block used for routing and subnet membership.
Route
Describes how a router should forward traffic toward a destination prefix.
Datagram
The complete IPv4 header and its carried upper-layer data.
Time to Live
A field reduced by routers so forwarding loops cannot circulate a datagram forever.

Bits, octets and the meaning of 0 through 255

A bit has two states, conventionally written 0 and 1. Eight bits form an octet, so an octet has 2^8, or 256, distinct patterns. Numbering begins at zero; consequently the smallest value is 0 and the largest is 255. Saying that an IPv4 octet “goes to 256” is a common off-by-one mistake: 256 is the count of possible values, not a representable eight-bit value.

IPv4 concatenates four octets into one 32-bit unsigned number. The address 192.168.1.10 is therefore shorthand for four binary groups. Periods are display separators and consume no bits in the address. A router can treat the complete address as one number or compare its most-significant bits against a prefix.

The eight positions in one IPv4 octet
Bit position76543210
Power of two2^72^62^52^42^32^22^12^0
Decimal weight1286432168421
All bits set1286432168421
Running total128192224240248252254255

Dotted decimal is only a human-readable projection

Each decimal octet can be converted by adding the weights of its one bits. Decimal 192 equals 128 + 64, so its binary form is 11000000. Decimal 168 equals 128 + 32 + 8, producing 10101000. Decimal 10 equals 8 + 2, producing 00001010.

For example, 192.168.1.10 becomes 11000000.10101000.00000001.00001010. Keeping leading zeroes in the binary view is essential because every octet always occupies eight positions. Decimal notation may omit those zeroes; the underlying address cannot.

Binary expansion of 192.168.1.10
Decimal octetBinary octetSelected weights
19211000000128 + 64
16810101000128 + 32 + 8
1000000011
10000010108 + 2

From classful networks to subnet masks

RFC 791 originally described class A, B and C unicast formats. Their leading bits implied a fixed network length: class A used an /8-style boundary, class B /16 and class C /24. Class D became multicast and class E was reserved. This was easy to infer from an address but offered only a few allocation sizes.

The classful model wasted space. An organization too large for one class C block could be assigned a class B block containing 65,536 addresses even when it needed only a few thousand. RFC 950 introduced subnet masks so an organization could divide its assigned network internally, but global allocation and routing still needed a classless solution.

Class terminology remains useful for history and appears in old documentation, yet RFC 1812 calls the distinction among class A, B and C no longer important. Modern routing uses an explicit prefix length, not an inferred class.

Historical classful IPv4 formats
ClassLeading bitsHistorical boundaryHistorical purpose
A0/8Very large unicast networks
B10/16Medium unicast networks
C110/24Smaller unicast networks
D1110No network/host splitMulticast groups
E1111No network/host splitReserved or experimental space

Why CIDR was necessary

By the early 1990s the Internet faced rapid depletion of class B network numbers, explosive growth in global routing tables and eventual exhaustion of the 32-bit address space. RFC 1519 introduced Classless Inter-Domain Routing in 1993 as a short-to-medium-term response. RFC 4632 later replaced it with the current address assignment and aggregation plan.

CIDR makes the network length explicit with slash notation. The value after the slash ranges from 0 through 32 and counts significant high-order bits. 192.168.6.0/24 fixes the first 24 bits. 192.168.4.0/22 fixes only 22, so it covers four adjacent /24 networks.

Because prefixes may be allocated in topology-aligned blocks, an upstream provider can advertise one aggregate instead of many customer routes. This is route summarization: fewer routing-table entries describe the same reachable address space, provided that the component networks are contiguous and correctly aligned.

Subnet masks, wildcard masks and prefix arithmetic

A subnet mask is a 32-bit value containing p consecutive ones followed by 32 - p zeroes. The ones preserve network bits and the zeroes identify host positions. A bitwise AND between an address and its mask therefore produces the network address.

A wildcard mask is the bitwise complement of the subnet mask: every one becomes zero and every zero becomes one. It directly shows the range of host variation. For /22 the subnet mask is 255.255.252.0 and the wildcard is 0.0.3.255.

The address count is 2^(32-p). For traditional prefixes through /30, the commonly usable host count is that result minus two. A block boundary is always a multiple of its block size in the 32-bit address space; this alignment rule is why arbitrary start and end values cannot be expressed as one CIDR prefix.

Common IPv4 CIDR prefixes and block sizes
PrefixSubnet maskHost bitsTotal addressesTraditional usable hosts
/8255.0.0.02416,777,21616,777,214
/12255.240.0.0201,048,5761,048,574
/16255.255.0.01665,53665,534
/20255.255.240.0124,0964,094
/21255.255.248.0112,0482,046
/22255.255.252.0101,0241,022
/23255.255.254.09512510
/24255.255.255.08256254
/25255.255.255.1287128126
/26255.255.255.19266462
/27255.255.255.22453230
/28255.255.255.24041614
/29255.255.255.248386
/30255.255.255.252242
/31255.255.255.254122 on point-to-point links
/32255.255.255.255011 host route

Worked example: calculating 192.168.6.130/24

A /24 fixes the first three octets and leaves eight host bits. The mask is 255.255.255.0. Applying it to 192.168.6.130 preserves 192.168.6 and clears the final octet, so the network address is 192.168.6.0.

Eight host bits provide 2^8 = 256 addresses. Setting all host bits to one makes the last octet 255, so the broadcast address is 192.168.6.255. Under traditional subnet semantics, usable hosts run from 192.168.6.1 through 192.168.6.254, a total of 254.

The important detail is that /24 does not mean “the last number may reach 256.” It means that 24 bits are fixed and the remaining eight can form 256 patterns numbered 0 through 255.

192.168.6.130/24 result
PropertyValue
Subnet mask255.255.255.0
Wildcard mask0.0.0.255
Network address192.168.6.0
Broadcast address192.168.6.255
Usable range192.168.6.1 – 192.168.6.254
Total / usable256 / 254

Worked example: why 192.168.6.130/22 begins at 192.168.4.0

A /22 leaves ten host bits and contains 2^10 = 1,024 addresses. Its mask is 255.255.252.0. In the third octet, decimal 252 is binary 11111100, so the final two bits of that octet belong to the host portion together with all eight bits of the fourth octet.

Two host bits in the third octet create groups of four: 0–3, 4–7, 8–11 and so on. The input third octet is 6, which falls in the 4–7 group. Clearing the host bits gives 4 and setting them gives 7. The fourth octet ranges from 0 through 255.

Therefore the complete block is 192.168.4.0 through 192.168.7.255. The traditional usable host range is 192.168.4.1 through 192.168.7.254. This crossing of dotted-decimal boundaries is exactly why memorizing only /24 behavior is insufficient.

192.168.6.130/22 result
PropertyValue
Subnet mask255.255.252.0
Wildcard mask0.0.3.255
Third-octet block size4
Network address192.168.4.0
Broadcast address192.168.7.255
Usable range192.168.4.1 – 192.168.7.254
Total / usable1,024 / 1,022

The special meanings of network, broadcast, /31 and /32

In conventional IPv4 subnetting, an all-zero host field denotes the network itself and an all-one host field denotes the directed broadcast. These conventions explain the familiar subtraction of two addresses from a subnet. The limited broadcast 255.255.255.255 is a separate special destination restricted to the local network.

A point-to-point link has exactly two endpoints and no meaningful set of additional hosts to broadcast to. RFC 3021 therefore requires both addresses of a /31 to be interpreted as host addresses on such a link, halving the address consumption compared with /30. A /32 has no host bits and represents exactly one address, commonly called a host route.

A calculator can display the numerical low and high endpoints for every prefix, but operational meaning still depends on context. /31 semantics apply to point-to-point links, and broadcast behavior can be restricted by router policy for security reasons.

Private, shared and special-purpose address ranges

Not every syntactically valid IPv4 address is globally reachable unicast space. RFC 1918 reserves three blocks for private internets. Organizations can reuse them without coordinating with IANA, but the addresses are not globally unique and should not be routed across inter-enterprise links.

IANA maintains the authoritative special-purpose registry. It includes loopback, link-local, shared carrier-grade NAT space, documentation blocks, benchmarking ranges, multicast and reserved space. A CIDR calculation tells you the mathematical boundaries; it does not by itself tell you whether a block is public, private, forwardable or appropriate for a particular purpose.

Frequently encountered IPv4 special ranges
RangePurposeKey caution
10.0.0.0/8RFC 1918 private useNot globally reachable
172.16.0.0/12RFC 1918 private useOnly 172.16 through 172.31 are private
192.168.0.0/16RFC 1918 private useCommon in home and enterprise LANs
100.64.0.0/10Shared address spaceUsed for carrier-grade NAT; not ordinary RFC 1918 space
127.0.0.0/8LoopbackMust not appear outside a host
169.254.0.0/16IPv4 link-localNot forwarded beyond the local link
192.0.2.0/24TEST-NET-1 documentationUse in examples, not public operation
198.51.100.0/24TEST-NET-2 documentationUse in examples, not public operation
203.0.113.0/24TEST-NET-3 documentationUse in examples, not public operation
224.0.0.0/4MulticastIdentifies groups rather than unicast hosts
255.255.255.255/32Limited broadcastMust not be routed beyond the local network

Longest-prefix matching and route aggregation

A destination may match several routes. For example, 192.168.6.130 matches 0.0.0.0/0, 192.168.0.0/16 and 192.168.6.0/24. A router chooses the matching route with the greatest prefix length because it is the most specific description of the destination. The /24 wins over /16 and /0.

Aggregation works in the opposite direction: several aligned, contiguous specific prefixes can be represented by a shorter common prefix. Four /24 networks from 192.168.4.0/24 through 192.168.7.0/24 aggregate into 192.168.4.0/22. An apparently similar set beginning at 192.168.5.0 cannot form one /22 because the start is not aligned to a four-/24 boundary.

More-specific routes can intentionally override an aggregate, but they also create security and stability concerns when advertised incorrectly. Prefix filters, route-origin authorization and careful address planning matter because routing follows the most specific accepted route.

Subnet planning, VLSM and common mistakes

Variable Length Subnet Masking allocates different prefix sizes according to actual need. A practical plan usually places the largest subnets first, aligns each allocation to its block size, reserves room for growth and documents infrastructure addresses. Every child prefix must remain inside its parent and must not overlap another child.

Common failures include confusing address count with usable host count, treating every 172.x.x.x address as private, entering a non-contiguous mask, forgetting /31 semantics, choosing an unaligned network boundary and assuming that a mathematically valid range is globally routable. Another frequent mistake is using decimal intuition without checking which bits cross an octet boundary.

The utily.tools IPv4 CIDR Range Calculator exposes the network, broadcast, usable endpoints, subnet mask, wildcard mask and counts together. Use those results as a verification aid, then apply the operational rules of the network where the block will be deployed.

Primary specifications and references

Conclusion

IPv4 subnetting becomes much easier once dotted decimal is translated back into its 32-bit structure. The prefix fixes the network bits, the remaining host bits determine a power-of-two block, and the all-zero and all-one host patterns define its boundaries. /24 and /22 are therefore not arbitrary labels: they are precise statements about how many bits belong to the network.

In my view, binary subnetting is worth understanding even when a calculator performs the arithmetic. The theory lets you detect overlapping networks, incorrect firewall ranges and allocation waste before they become production incidents. Use the utily.tools IPv4 CIDR Range Calculator to explore different addresses and prefixes, then continue with the other articles on utily.tools for deeper explanations of the standards behind everyday developer tools.

Open IPv4 CIDR Range Calculator Read more articles