A subnet is a range of IP addresses whose members share the same network prefix, so every device inside it reaches every other one without a router in between. A subnet mask sets the prefix by marking which bits of an address name the network and which name a host.
- /24 is 255.255.255.0
- A /24 holds 256 addresses
- 254 of them are usable
- The first and last are always reserved
- Inside a subnet traffic is switched, between subnets it is routed
On this page
FundamentalsWhat a subnet actually is
Every IPv4 address is 32 bits long, written as four numbers between 0 and 255. On its own an address says nothing about which network it belongs to. The subnet mask supplies that missing half.
It is another 32 bit number, and wherever it has a 1 bit, the matching bit of the address belongs to the network portion. Wherever it has a 0 bit, the matching bit belongs to the host portion and identifies one device inside that network.
Take 192.168.10.37 with a mask of 255.255.255.0. In binary the mask is twenty four 1 bits followed by eight 0 bits, so the first three numbers, 192.168.10, are the network and the last number, 37, is the host.
Any other address that begins 192.168.10 is on the same subnet, and the two machines can talk directly. Change one digit in the third position, to 192.168.11.37, and the two are on different networks that need a router to exchange a single packet.
That is the whole idea, and it is worth stating plainly because the arithmetic that follows tends to bury it. If you only remember one thing about what is a subnet, remember that a subnet is a group of addresses that agree on their leading bits, and that agreement is what lets them skip the router.
The address in binary, and the decision every device makes
The four numbers in an IPv4 address are called octets, because each one is eight bits. Writing them in decimal is a convenience for people. Every device on the network works in binary, and the binary is where subnetting stops being mysterious.
192.168.10.37 11000000.10101000.00001010.00100101
255.255.255.0 11111111.11111111.11111111.00000000
network 11000000.10101000.00001010.00000000 = 192.168.10.0
host 00100101 = 37
Every device does this arithmetic before it sends a single packet. It takes the destination address, applies its own mask with a bitwise AND, and compares the result with its own network address.
If the two match, the destination is on the same subnet and the device sends the data straight to it. If they differ, the destination is somewhere else and the packet goes to the default gateway instead.
Two machines on one switch that disagree about their masks will each reach a different conclusion about the same address, which is why a wrong mask produces the strangest symptom in networking: traffic that works in one direction only.
It is worth following the packet a little further. When the destination is local, the device asks for the destination's hardware address with ARP and puts the data on the wire directly, and no router ever sees it.
When the destination is somewhere else, the device asks for the gateway's hardware address instead and hands the packet to the router, which reads the destination network, looks it up, and forwards the packet toward the next network on the path.
Packets crossing the internet repeat that step at every router until one of them finds the destination on a subnet it is directly attached to.
This also explains why some prefixes feel easier than others. A /8, /16 and /24 fall exactly on octet boundaries, so the split can be read straight off the dotted decimal. A /26 cuts through the middle of the fourth octet, and the boundaries have to be counted rather than seen.
Network address, broadcast address, and the two that go missing
Inside every subnet, two addresses are spoken for. The one where all host bits are 0 is the network address, which names the subnet itself and is what appears in a routing table.
The one where all host bits are 1 is the broadcast address, which reaches every host in that subnet at once. Neither can be assigned to a machine, which is why a subnet with 256 addresses offers 254 usable ones.
That subtraction of two is the source of most off by one errors in network design. A team asks for a network that holds 254 devices and is given a /24, which is exactly right. A team asks for one that holds 256 and needs a /23, because a /24 cannot do it.
Subnet masksReading a subnet mask, on its own
Subnet mask explained without the surrounding theory: the mask is a second number, the same shape as an address, that says which part of the address identifies the network and which part identifies the host. Where the mask has a 1 bit, that position belongs to the network. Where it has a 0, it belongs to the host.
address 192 . 168 . 1 . 50
mask 255 . 255 . 255 . 0
--------------- ----
the network the host
That is the whole idea. 255 in an octet means all eight bits are network bits, so that octet is fixed. 0 means all eight are host bits, so that octet varies. A mask of 255.255.255.0 fixes the first three octets and leaves the last one free, which gives 256 addresses.
The only masks that exist are the ones where the 1 bits are contiguous from the left, which is why an octet in a mask is always one of nine values and never anything else.
| Octet value | Bits it contributes | Why it is that number |
|---|---|---|
| 0 | 0 | 00000000 |
| 128 | 1 | 10000000 |
| 192 | 2 | 11000000 |
| 224 | 3 | 11100000 |
| 240 | 4 | 11110000 |
| 248 | 5 | 11111000 |
| 252 | 6 | 11111100 |
| 254 | 7 | 11111110 |
| 255 | 8 | 11111111 |
A mask of 255.255.255.192 is therefore 8 plus 8 plus 8 plus 2, which is a /26. Reading a mask in dotted decimal is adding up that column, and writing one is doing it backward. Any value not on that list, 255.255.255.100 for example, is not a valid mask, and a device given one will reject it or behave unpredictably depending on the platform.
The prefix and the mask are the same statement in two notations, which is why the full table below shows both, and why "a /24" and "255.255.255.0" are interchangeable in every conversation about this.
NotationCIDR notation, and the table worth bookmarking
Before CIDR, addresses came in classes
Until the mid nineties the split between network and host was fixed by the first bits of the address itself. A Class A network began 1 to 126 and reserved a full 8 bits for the network, which handed a single organization sixteen million addresses.
A Class B began 128 to 191 and used 16 bits. A Class C began 192 to 223 and used 24, so it held 254 hosts. Class D from 224 to 239 was multicast and Class E above that was reserved.
The scheme wasted addresses on a scale that is hard to overstate. A company with 300 devices was too big for a Class C and so received a Class B, and then left 65,000 addresses unused.
Classless Inter Domain Routing removed the classes and let the prefix be any length, which is the arrangement every network uses now. The classes survive only as vocabulary: when somebody calls a /24 a Class C network, they mean a network of 254 hosts, and the class itself has meant nothing for thirty years.
Writing masks in dotted decimal is legible but slow. Classless Inter Domain Routing, defined in RFC 4632, replaced it with a slash and the number of network bits. A /24 and 255.255.255.0 mean exactly the same thing.
Every prefix from /8 down to /30 follows the same arithmetic: the number of addresses is 2 raised to the power of 32 minus the prefix, and the usable count is that number minus 2.
| Prefix | Mask | Addresses | Usable hosts | Typical use |
|---|---|---|---|---|
| /8 | 255.0.0.0 | 16,777,216 | 16,777,214 | The whole 10.x private space |
| /16 | 255.255.0.0 | 65,536 | 65,534 | A site allocation to carve up later |
| /20 | 255.255.240.0 | 4,096 | 4,094 | A large campus or a cloud VPC |
| /22 | 255.255.252.0 | 1,024 | 1,022 | A busy floor or a wireless pool |
| /23 | 255.255.254.0 | 512 | 510 | An office that outgrew a /24 |
| /24 | 255.255.255.0 | 256 | 254 | The default office network |
| /25 | 255.255.255.128 | 128 | 126 | Half a /24, often the server half |
| /26 | 255.255.255.192 | 64 | 62 | A department or a VLAN |
| /27 | 255.255.255.224 | 32 | 30 | A small branch or a DMZ |
| /28 | 255.255.255.240 | 16 | 14 | A rack of appliances |
| /29 | 255.255.255.248 | 8 | 6 | A handful of static devices |
| /30 | 255.255.255.252 | 4 | 2 | A router to router link |
| /31 | 255.255.255.254 | 2 | 2 | A point to point link, RFC 3021 |
| /32 | 255.255.255.255 | 1 | 1 | A single host route or a loopback |
The last two rows break the minus two rule on purpose. RFC 3021 allows a /31 on a point to point link, where there is no need for a broadcast address because there is only one possible destination, so both addresses become hosts.
A /32 names exactly one address and is used for loopbacks, host routes, and firewall rules that must match a single machine.
Worked exampleReading a real subnet, start to finish
As an example, take 192.168.10.0/24 and work through every number a network engineer would need.
The network address is 192.168.10.0, because every host bit is 0. The broadcast address is 192.168.10.255, because every host bit is 1. The usable range is 192.168.10.1 through 192.168.10.254, which is 254 addresses.
Convention, not the standard, puts the default gateway at either the first usable address or the last, so 192.168.10.1 or 192.168.10.254. Pick one and use it everywhere, because the cost of mixing the two conventions across sites is paid at three in the morning.
Splitting that /24 into four
In this example, borrowing two host bits from the host portion turns one /24 into four /26 subnets. Each holds 64 addresses and 62 usable hosts, and the boundaries land every 64 addresses.
| Subnet | Network address | Usable range | Broadcast |
|---|---|---|---|
| 192.168.10.0/26 | 192.168.10.0 | .1 to .62 | 192.168.10.63 |
| 192.168.10.64/26 | 192.168.10.64 | .65 to .126 | 192.168.10.127 |
| 192.168.10.128/26 | 192.168.10.128 | .129 to .190 | 192.168.10.191 |
| 192.168.10.192/26 | 192.168.10.192 | .193 to .254 | 192.168.10.255 |
The pattern generalizes. Borrow one bit and you get two halves, borrow two and you get four quarters, borrow three and you get eight.
Because the subnets in a design rarely need to be the same size, most networks use variable length subnet masking, which simply means different prefixes coexist inside one allocation: a /26 for the user VLAN, a /28 for the printers, a /30 for the link to the branch.
MethodSubnetting a network, step by step
Subnetting is the act of taking one allocation and cutting it into smaller networks. Done on paper before anything is configured, it takes four steps.
1. Count what each group needs, then add room. List the groups that need to be separated and the number of devices in each, including printers, cameras, access points and anything else with an address. Add growth. A department of 40 people with 55 devices needs a subnet of 62 usable hosts, which is a /26.
2. Turn each count into a prefix. Round every requirement up to the next size in the table above. Never round down, because a subnet that fills up cannot be extended in place. It has to be renumbered, and renumbering a live network is a weekend nobody enjoys.
3. Allocate the largest first. Working from the largest subnet down keeps the boundaries aligned and avoids leaving unusable gaps. This is variable length subnet masking in practice: a /25 for the users, then a /27 for the servers, then a /28 for the printers, each starting where the previous one ended.
4. Write down the network address, the range and the broadcast for each. These three numbers per subnet are what everything else refers to: the gateway configuration, the DHCP scope, the firewall rules and the routing table. An example of the finished table is the four /26 networks above.
The reason to do this before touching a switch is that the arithmetic is unforgiving. Subnets have to start on their own boundary, so a /26 can begin at .0, .64, .128 or .192 and nowhere else. A /28 can begin every 16 addresses. Choosing a start address that is not a multiple of the subnet size produces a network that looks configured and silently drops traffic.
Why it mattersWhy anyone bothers
Three reasons account for nearly every subnet ever created.
Broadcast traffic stops at the edge. A broadcast reaches every host in its subnet and no further. On a flat network of a thousand devices, every ARP request, every discovery protocol and every misbehaving application interrupts a thousand machines. Cut that into ten subnets and each broadcast bothers a hundred.
Security improves because segmentation becomes enforceable. A firewall rule or an access control list is written against address ranges. Putting the card payment terminals in their own subnet is what makes "only these three servers may reach the payment devices" a rule a device can enforce, rather than a policy in a document.
Who counts as an allowed user is a separate question, answered by multi factor authentication. Compliance frameworks lean on this heavily, which is why an auditor asks for a network diagram with subnets on it.
Routing stays small. Addresses that share a prefix can be advertised as one route. A branch with four /26 subnets inside 192.168.10.0/24 can be advertised to the rest of the company as a single /24, and the core routers carry one entry instead of four.
Public and privateSubnets, public addresses and the internet
Everything above applies to both private and public networks, because the arithmetic does not care. What differs is where the allocation comes from and what the outside world can reach.
A private IP address is one from a block IANA reserved for private internets, which RFC 1918 lists as three ranges:
| 10.0.0.0 to 10.255.255.255 | 10/8, the 24-bit block |
|---|---|
| 172.16.0.0 to 172.31.255.255 | 172.16/12, the 20-bit block |
| 192.168.0.0 to 192.168.255.255 | 192.168/16, the 16-bit block |
There is a fourth range worth recognizing. RFC 6598 set aside 100.64.0.0/10 as Shared Address Space for service providers to use between a subscriber's router and the provider's own equipment, which is what carrier-grade NAT runs on.
An address in that range on a home or branch router usually means the connection has no public address of its own, which matters the moment somebody tries to forward a port or run a site-to-site VPN to it.
Private networks use those blocks and are free to subnet them however they like, because the addresses are not routed on the internet. A company can run 10.20.30.0/24 in every one of its offices if it wants to, and nobody outside notices.
Reaching anything public from those addresses requires network address translation on the way out, which rewrites the private source address into a public one the internet can route data back to.
Public networks are allocated, not chosen. An internet service provider assigns a prefix, usually a small one such as a /29 for a business line, and those addresses are yours to use but not to invent.
The provider advertises the larger block it holds, so the routers of the world only need to know about the block and not about your subnets inside it. That aggregation is the reason CIDR exists: without it, the global routing table would carry an entry for every network on earth rather than for the blocks they sit in.
The practical consequence is a habit worth adopting. Plan private subnets with room to spare, because the available space runs into millions of addresses and costs nothing. Plan public ones to the address, because you will be given very few.
PitfallsWhere people go wrong
The private ranges are fixed by RFC 1918 and are the only blocks reserved for internal use.
| Block | Range | Addresses |
|---|---|---|
| 10.0.0.0/8 | 10.0.0.0 to 10.255.255.255 | 16,777,216 |
| 172.16.0.0/12 | 172.16.0.0 to 172.31.255.255 | 1,048,576 |
| 192.168.0.0/16 | 192.168.0.0 to 192.168.255.255 | 65,536 |
Two mistakes recur. The first is reading 172.16.0.0/12 as though it stopped at 172.16.255.255, when it actually runs to 172.31.255.255. The second is picking 192.168.1.0/24 for a company network, which is the factory default of nearly every home router and therefore guarantees an address collision the first time somebody connects from home over a VPN. Choose something no consumer router ships with.
ComparisonA subnet, a VLAN and a broadcast domain are three different things
| Criterion | Subnet | VLAN | Broadcast domain |
|---|---|---|---|
| What layer it lives at | Layer 3, addressing | Layer 2, switching | A property, not a thing you configure |
| What defines it | A prefix and a mask | A tag on a switch port | The set of ports a broadcast reaches |
| Configured on | Router and host interfaces | Switches | Neither, it results from the other two |
| Can exist without the other | Yes, on a flat switched network | Yes, with no addresses assigned | No |
These three are used interchangeably in conversation and mean different things, which causes real confusion during troubleshooting. In a normal design one VLAN carries exactly one subnet, and the two words end up describing the same group of machines.
That habit is what makes the exceptions painful: two subnets on one VLAN is legal and works, and it will confuse the next person who assumes the mapping is one to one.
FAQFrequently asked questions
What is a subnet in simple terms?
A group of IP addresses that share the same leading bits and can therefore talk to each other directly, without a router carrying the traffic between them.
What does the subnet mask do?
It marks the boundary. Every 1 bit in the mask says that the matching bit of the address belongs to the network, and every 0 bit says it identifies a host within that network.
How do I read a subnet mask?
Add up the bits each octet contributes. 255 is eight bits, 192 is two, 0 is none, so 255.255.255.192 is 26 network bits, written /26. Everything left over is the host portion.
Is 255.255.255.100 a valid subnet mask?
No. The 1 bits in a mask have to run without a gap from the left, so an octet can only be 0, 128, 192, 224, 240, 248, 252, 254 or 255. Anything else is rejected or behaves unpredictably depending on the device.
What subnet mask do I use for 50 devices?
A /26, which is 255.255.255.192 and holds 62 usable addresses. A /27 gives only 30, which is not enough, and the next size up wastes addresses you may want for another subnet later.
What is the difference between /24 and 255.255.255.0?
Nothing. They are two notations for the same mask. The slash form counts the network bits and the dotted form spells them out.
How many devices fit in a /24?
254. The subnet contains 256 addresses, and the network address and the broadcast address cannot be assigned to a device.
Why are two addresses always reserved?
The address with all host bits set to 0 names the subnet itself and appears in routing tables. The address with all host bits set to 1 reaches every host at once. Neither can belong to a single machine.
Can two devices on different subnets talk to each other?
Yes, but only through a router or a layer 3 switch. Without one they will not exchange a single packet, even if they are plugged into the same switch.
Is a VLAN the same as a subnet?
No. A VLAN is a layer 2 boundary configured on switches and a subnet is a layer 3 address range. Most designs put one subnet on one VLAN, which is why the words get swapped.
What is a /31 for?
Point to point links between two routers. RFC 3021 allows both addresses to be hosts because a link with exactly two ends has no use for a broadcast address, which saves two addresses on every link.
Which private range should I use?
Any of the three, as long as it does not collide with a network your users will connect from. Avoid 192.168.0.0/24 and 192.168.1.0/24, because consumer routers ship with them and remote workers will end up with the same range at home, which breaks the moment they connect over an IPsec VPN.
How do I know which subnet an address is in?
Apply the mask. Keep the address bits where the mask has 1s and set the rest to 0, and the result is the network address of the subnet that holds it.
What is subnetting?
Subnetting is the process of dividing one network into smaller networks by moving the boundary between the network portion and the host portion. You borrow bits from the host portion, and every bit borrowed doubles the number of subnets while halving the addresses available in each.
Do subnets improve security?
On their own, no. They make security enforceable, which is not the same thing. Putting sensitive devices on their own subnet lets a firewall or an access list control who reaches them, but the subnet does nothing until that rule exists.
Does any of this apply to IPv6?
The idea does, the arithmetic does not. IPv6 uses prefixes the same way, but addresses are 128 bits, there is no broadcast address, and the conventional subnet size is a /64 regardless of how few devices it holds.
Is there a subnetting cheat sheet for the common masks?
The short subnetting cheat sheet: /24 is 255.255.255.0 with 254 usable hosts, /25 is 255.255.255.128 with 126, /26 is .192 with 62, /27 is .224 with 30, /28 is .240 with 14, /29 is .248 with 6, and /30 is .252 with 2.
How do a subnet mask and an IP address work together?
The IP subnet mask marks which bits of the address name the network and which name the host. A device compares its own address and a destination through the mask. If the network bits match, it delivers directly. If they differ, it sends the packet to its default gateway.
Keep readingRelated concepts
Read next · Remote access What Is an IPsec VPN? A VPN is how two subnets in different buildings behave like one network. Open this next11 min- Identity and access · 16 min What Is MFA? Segmentation makes a firewall rule possible. Authentication decides who satisfies it.
- Containers · 14 min What Is Docker? Every container host quietly creates subnets of its own, and they collide with real ones.
- Remote access · 13 min VPN vs Proxy Ranges are what a tunnel carries between, and what a proxy never touches.
- Fundamentals · 11 min What a Node Is, and Why the Word Changes Meaning The count that decides an addressing plan.
- Routing · 12 min What Is BGP? How the blocks that BGP announces are written down and divided up.
- Addressing · 9 min What Is DHCP? How a device gets a mask and a gateway in the first place, without anybody typing them.
- Shared storage · 12 min NAS vs SAN Separating storage traffic from everything else starts with the addressing.
- Operations · 11 min Infrastructure as Code, and the File That Knows What Exists What the code still has to be correct about.
- Ports · 12 min What Is a Port Number? The other half of an endpoint, once the subnet has found the machine.
- Addressing · 11 min What Is CIDR? What the blocks you are dividing up are for, once the arithmetic makes sense.
- Switching · 11 min Spanning Tree Protocol The layer above the switching, once the loops have been dealt with.
- Addressing · 10 min Default Gateway What a device does with everything the subnet mask says is not local.
- Switching · 14 min What Is a VLAN? The layer 3 half of the same separation, and the arithmetic behind it.
- Fundamentals · 13 min ARP Explained, and the One Thing Everyone Gets Wrong About It The arithmetic that decides which of the two ARP cases applies.
- Network design · 10 min The Logical Network Diagram and the Physical One, Drawn for Different Questions The drawing an auditor asks for when segmentation has to be demonstrated.
- Switching · 9 min Inter VLAN Routing, and Why Two VLANs Cannot Talk Without It What has to exist for two of those ranges on one switch to reach each other.