Networking · Concept · 15 min read

What Is a Subnet? Masks, CIDR Notation, and How to Split a Network

A mask decides where the network ends and the host begins. Here is that split in binary, the CIDR table worth keeping, and a /24 cut into four subnets with every number worked out.

Written by Marko Ristic, Editor Updated Sep 17, 2026
32 bitsThe length of every IPv4 address
254Usable hosts in a /24
2Addresses reserved in every subnet
RFC 4632CIDR, which retired the classes
Short answer

A subnet is a range of IP addresses whose members share the same network prefix, so every device inside it reaches every other one without a router in between. A subnet mask sets the prefix by marking which bits of an address name the network and which name a host.

  • /24 is 255.255.255.0
  • A /24 holds 256 addresses
  • 254 of them are usable
  • The first and last are always reserved
  • Inside a subnet traffic is switched, between subnets it is routed
On this page

FundamentalsWhat a subnet actually is

Every IPv4 address is 32 bits long, written as four numbers between 0 and 255. On its own an address says nothing about which network it belongs to. The subnet mask supplies that missing half.

It is another 32 bit number, and wherever it has a 1 bit, the matching bit of the address belongs to the network portion. Wherever it has a 0 bit, the matching bit belongs to the host portion and identifies one device inside that network.

Take 192.168.10.37 with a mask of 255.255.255.0. In binary the mask is twenty four 1 bits followed by eight 0 bits, so the first three numbers, 192.168.10, are the network and the last number, 37, is the host.

Any other address that begins 192.168.10 is on the same subnet, and the two machines can talk directly. Change one digit in the third position, to 192.168.11.37, and the two are on different networks that need a router to exchange a single packet.

That is the whole idea, and it is worth stating plainly because the arithmetic that follows tends to bury it. If you only remember one thing about what is a subnet, remember that a subnet is a group of addresses that agree on their leading bits, and that agreement is what lets them skip the router.

The address in binary, and the decision every device makes

The four numbers in an IPv4 address are called octets, because each one is eight bits. Writing them in decimal is a convenience for people. Every device on the network works in binary, and the binary is where subnetting stops being mysterious.

192.168.10.37   11000000.10101000.00001010.00100101
255.255.255.0   11111111.11111111.11111111.00000000
network         11000000.10101000.00001010.00000000   = 192.168.10.0
host                                       00100101   = 37

Every device does this arithmetic before it sends a single packet. It takes the destination address, applies its own mask with a bitwise AND, and compares the result with its own network address.

If the two match, the destination is on the same subnet and the device sends the data straight to it. If they differ, the destination is somewhere else and the packet goes to the default gateway instead.

Two machines on one switch that disagree about their masks will each reach a different conclusion about the same address, which is why a wrong mask produces the strangest symptom in networking: traffic that works in one direction only.

It is worth following the packet a little further. When the destination is local, the device asks for the destination's hardware address with ARP and puts the data on the wire directly, and no router ever sees it.

When the destination is somewhere else, the device asks for the gateway's hardware address instead and hands the packet to the router, which reads the destination network, looks it up, and forwards the packet toward the next network on the path.

Packets crossing the internet repeat that step at every router until one of them finds the destination on a subnet it is directly attached to.

This also explains why some prefixes feel easier than others. A /8, /16 and /24 fall exactly on octet boundaries, so the split can be read straight off the dotted decimal. A /26 cuts through the middle of the fourth octet, and the boundaries have to be counted rather than seen.

Network address, broadcast address, and the two that go missing

Inside every subnet, two addresses are spoken for. The one where all host bits are 0 is the network address, which names the subnet itself and is what appears in a routing table.

The one where all host bits are 1 is the broadcast address, which reaches every host in that subnet at once. Neither can be assigned to a machine, which is why a subnet with 256 addresses offers 254 usable ones.

That subtraction of two is the source of most off by one errors in network design. A team asks for a network that holds 254 devices and is given a /24, which is exactly right. A team asks for one that holds 256 and needs a /23, because a /24 cannot do it.

Subnet masksReading a subnet mask, on its own

Subnet mask explained without the surrounding theory: the mask is a second number, the same shape as an address, that says which part of the address identifies the network and which part identifies the host. Where the mask has a 1 bit, that position belongs to the network. Where it has a 0, it belongs to the host.

address   192 . 168 .   1 .  50
mask      255 . 255 . 255 .   0
          ---------------   ----
          the network       the host

That is the whole idea. 255 in an octet means all eight bits are network bits, so that octet is fixed. 0 means all eight are host bits, so that octet varies. A mask of 255.255.255.0 fixes the first three octets and leaves the last one free, which gives 256 addresses.

The only masks that exist are the ones where the 1 bits are contiguous from the left, which is why an octet in a mask is always one of nine values and never anything else.

Octet valueBits it contributesWhy it is that number
0000000000
128110000000
192211000000
224311100000
240411110000
248511111000
252611111100
254711111110
255811111111

A mask of 255.255.255.192 is therefore 8 plus 8 plus 8 plus 2, which is a /26. Reading a mask in dotted decimal is adding up that column, and writing one is doing it backward. Any value not on that list, 255.255.255.100 for example, is not a valid mask, and a device given one will reject it or behave unpredictably depending on the platform.

The prefix and the mask are the same statement in two notations, which is why the full table below shows both, and why "a /24" and "255.255.255.0" are interchangeable in every conversation about this.

NotationCIDR notation, and the table worth bookmarking

Before CIDR, addresses came in classes

Until the mid nineties the split between network and host was fixed by the first bits of the address itself. A Class A network began 1 to 126 and reserved a full 8 bits for the network, which handed a single organization sixteen million addresses.

A Class B began 128 to 191 and used 16 bits. A Class C began 192 to 223 and used 24, so it held 254 hosts. Class D from 224 to 239 was multicast and Class E above that was reserved.

The scheme wasted addresses on a scale that is hard to overstate. A company with 300 devices was too big for a Class C and so received a Class B, and then left 65,000 addresses unused.

Classless Inter Domain Routing removed the classes and let the prefix be any length, which is the arrangement every network uses now. The classes survive only as vocabulary: when somebody calls a /24 a Class C network, they mean a network of 254 hosts, and the class itself has meant nothing for thirty years.

Writing masks in dotted decimal is legible but slow. Classless Inter Domain Routing, defined in RFC 4632, replaced it with a slash and the number of network bits. A /24 and 255.255.255.0 mean exactly the same thing.

Every prefix from /8 down to /30 follows the same arithmetic: the number of addresses is 2 raised to the power of 32 minus the prefix, and the usable count is that number minus 2.

PrefixMaskAddressesUsable hostsTypical use
/8255.0.0.016,777,21616,777,214The whole 10.x private space
/16255.255.0.065,53665,534A site allocation to carve up later
/20255.255.240.04,0964,094A large campus or a cloud VPC
/22255.255.252.01,0241,022A busy floor or a wireless pool
/23255.255.254.0512510An office that outgrew a /24
/24255.255.255.0256254The default office network
/25255.255.255.128128126Half a /24, often the server half
/26255.255.255.1926462A department or a VLAN
/27255.255.255.2243230A small branch or a DMZ
/28255.255.255.2401614A rack of appliances
/29255.255.255.24886A handful of static devices
/30255.255.255.25242A router to router link
/31255.255.255.25422A point to point link, RFC 3021
/32255.255.255.25511A single host route or a loopback

The last two rows break the minus two rule on purpose. RFC 3021 allows a /31 on a point to point link, where there is no need for a broadcast address because there is only one possible destination, so both addresses become hosts.

A /32 names exactly one address and is used for loopbacks, host routes, and firewall rules that must match a single machine.

Worked exampleReading a real subnet, start to finish

As an example, take 192.168.10.0/24 and work through every number a network engineer would need.

The network address is 192.168.10.0, because every host bit is 0. The broadcast address is 192.168.10.255, because every host bit is 1. The usable range is 192.168.10.1 through 192.168.10.254, which is 254 addresses.

Convention, not the standard, puts the default gateway at either the first usable address or the last, so 192.168.10.1 or 192.168.10.254. Pick one and use it everywhere, because the cost of mixing the two conventions across sites is paid at three in the morning.

Splitting that /24 into four

In this example, borrowing two host bits from the host portion turns one /24 into four /26 subnets. Each holds 64 addresses and 62 usable hosts, and the boundaries land every 64 addresses.

SubnetNetwork addressUsable rangeBroadcast
192.168.10.0/26192.168.10.0.1 to .62192.168.10.63
192.168.10.64/26192.168.10.64.65 to .126192.168.10.127
192.168.10.128/26192.168.10.128.129 to .190192.168.10.191
192.168.10.192/26192.168.10.192.193 to .254192.168.10.255

The pattern generalizes. Borrow one bit and you get two halves, borrow two and you get four quarters, borrow three and you get eight.

Because the subnets in a design rarely need to be the same size, most networks use variable length subnet masking, which simply means different prefixes coexist inside one allocation: a /26 for the user VLAN, a /28 for the printers, a /30 for the link to the branch.

MethodSubnetting a network, step by step

Subnetting is the act of taking one allocation and cutting it into smaller networks. Done on paper before anything is configured, it takes four steps.

1. Count what each group needs, then add room. List the groups that need to be separated and the number of devices in each, including printers, cameras, access points and anything else with an address. Add growth. A department of 40 people with 55 devices needs a subnet of 62 usable hosts, which is a /26.

2. Turn each count into a prefix. Round every requirement up to the next size in the table above. Never round down, because a subnet that fills up cannot be extended in place. It has to be renumbered, and renumbering a live network is a weekend nobody enjoys.

3. Allocate the largest first. Working from the largest subnet down keeps the boundaries aligned and avoids leaving unusable gaps. This is variable length subnet masking in practice: a /25 for the users, then a /27 for the servers, then a /28 for the printers, each starting where the previous one ended.

4. Write down the network address, the range and the broadcast for each. These three numbers per subnet are what everything else refers to: the gateway configuration, the DHCP scope, the firewall rules and the routing table. An example of the finished table is the four /26 networks above.

The reason to do this before touching a switch is that the arithmetic is unforgiving. Subnets have to start on their own boundary, so a /26 can begin at .0, .64, .128 or .192 and nowhere else. A /28 can begin every 16 addresses. Choosing a start address that is not a multiple of the subnet size produces a network that looks configured and silently drops traffic.

Why it mattersWhy anyone bothers

Three reasons account for nearly every subnet ever created.

Broadcast traffic stops at the edge. A broadcast reaches every host in its subnet and no further. On a flat network of a thousand devices, every ARP request, every discovery protocol and every misbehaving application interrupts a thousand machines. Cut that into ten subnets and each broadcast bothers a hundred.

Security improves because segmentation becomes enforceable. A firewall rule or an access control list is written against address ranges. Putting the card payment terminals in their own subnet is what makes "only these three servers may reach the payment devices" a rule a device can enforce, rather than a policy in a document.

Who counts as an allowed user is a separate question, answered by multi factor authentication. Compliance frameworks lean on this heavily, which is why an auditor asks for a network diagram with subnets on it.

Routing stays small. Addresses that share a prefix can be advertised as one route. A branch with four /26 subnets inside 192.168.10.0/24 can be advertised to the rest of the company as a single /24, and the core routers carry one entry instead of four.

Public and privateSubnets, public addresses and the internet

Everything above applies to both private and public networks, because the arithmetic does not care. What differs is where the allocation comes from and what the outside world can reach.

A private IP address is one from a block IANA reserved for private internets, which RFC 1918 lists as three ranges:

10.0.0.0 to 10.255.255.25510/8, the 24-bit block
172.16.0.0 to 172.31.255.255172.16/12, the 20-bit block
192.168.0.0 to 192.168.255.255192.168/16, the 16-bit block

There is a fourth range worth recognizing. RFC 6598 set aside 100.64.0.0/10 as Shared Address Space for service providers to use between a subscriber's router and the provider's own equipment, which is what carrier-grade NAT runs on.

An address in that range on a home or branch router usually means the connection has no public address of its own, which matters the moment somebody tries to forward a port or run a site-to-site VPN to it.

Private networks use those blocks and are free to subnet them however they like, because the addresses are not routed on the internet. A company can run 10.20.30.0/24 in every one of its offices if it wants to, and nobody outside notices.

Reaching anything public from those addresses requires network address translation on the way out, which rewrites the private source address into a public one the internet can route data back to.

Public networks are allocated, not chosen. An internet service provider assigns a prefix, usually a small one such as a /29 for a business line, and those addresses are yours to use but not to invent.

The provider advertises the larger block it holds, so the routers of the world only need to know about the block and not about your subnets inside it. That aggregation is the reason CIDR exists: without it, the global routing table would carry an entry for every network on earth rather than for the blocks they sit in.

The practical consequence is a habit worth adopting. Plan private subnets with room to spare, because the available space runs into millions of addresses and costs nothing. Plan public ones to the address, because you will be given very few.

PitfallsWhere people go wrong

The private ranges are fixed by RFC 1918 and are the only blocks reserved for internal use.

BlockRangeAddresses
10.0.0.0/810.0.0.0 to 10.255.255.25516,777,216
172.16.0.0/12172.16.0.0 to 172.31.255.2551,048,576
192.168.0.0/16192.168.0.0 to 192.168.255.25565,536

Two mistakes recur. The first is reading 172.16.0.0/12 as though it stopped at 172.16.255.255, when it actually runs to 172.31.255.255. The second is picking 192.168.1.0/24 for a company network, which is the factory default of nearly every home router and therefore guarantees an address collision the first time somebody connects from home over a VPN. Choose something no consumer router ships with.

address110000001010100000001010001001011921681037mask111111111111111111111111000000002552552550network portion, 24 bitsevery address here is 192.168.10host portion8 bits, 254 usableWherever the mask has a 1, that bit of the address belongs to the network.The device keeps those bits and zeroes the rest to find the network address, 192.168.10.0.
The same 32 bits twice. The mask decides where the network portion stops, and nothing about the address itself tells you.

ComparisonA subnet, a VLAN and a broadcast domain are three different things

CriterionSubnetVLANBroadcast domain
What layer it lives atLayer 3, addressingLayer 2, switchingA property, not a thing you configure
What defines itA prefix and a maskA tag on a switch portThe set of ports a broadcast reaches
Configured onRouter and host interfacesSwitchesNeither, it results from the other two
Can exist without the otherYes, on a flat switched networkYes, with no addresses assignedNo

These three are used interchangeably in conversation and mean different things, which causes real confusion during troubleshooting. In a normal design one VLAN carries exactly one subnet, and the two words end up describing the same group of machines.

That habit is what makes the exceptions painful: two subnets on one VLAN is legal and works, and it will confuse the next person who assumes the mapping is one to one.

FAQFrequently asked questions

What is a subnet in simple terms?

A group of IP addresses that share the same leading bits and can therefore talk to each other directly, without a router carrying the traffic between them.

What does the subnet mask do?

It marks the boundary. Every 1 bit in the mask says that the matching bit of the address belongs to the network, and every 0 bit says it identifies a host within that network.

How do I read a subnet mask?

Add up the bits each octet contributes. 255 is eight bits, 192 is two, 0 is none, so 255.255.255.192 is 26 network bits, written /26. Everything left over is the host portion.

Is 255.255.255.100 a valid subnet mask?

No. The 1 bits in a mask have to run without a gap from the left, so an octet can only be 0, 128, 192, 224, 240, 248, 252, 254 or 255. Anything else is rejected or behaves unpredictably depending on the device.

What subnet mask do I use for 50 devices?

A /26, which is 255.255.255.192 and holds 62 usable addresses. A /27 gives only 30, which is not enough, and the next size up wastes addresses you may want for another subnet later.

What is the difference between /24 and 255.255.255.0?

Nothing. They are two notations for the same mask. The slash form counts the network bits and the dotted form spells them out.

How many devices fit in a /24?

254. The subnet contains 256 addresses, and the network address and the broadcast address cannot be assigned to a device.

Why are two addresses always reserved?

The address with all host bits set to 0 names the subnet itself and appears in routing tables. The address with all host bits set to 1 reaches every host at once. Neither can belong to a single machine.

Can two devices on different subnets talk to each other?

Yes, but only through a router or a layer 3 switch. Without one they will not exchange a single packet, even if they are plugged into the same switch.

Is a VLAN the same as a subnet?

No. A VLAN is a layer 2 boundary configured on switches and a subnet is a layer 3 address range. Most designs put one subnet on one VLAN, which is why the words get swapped.

What is a /31 for?

Point to point links between two routers. RFC 3021 allows both addresses to be hosts because a link with exactly two ends has no use for a broadcast address, which saves two addresses on every link.

Which private range should I use?

Any of the three, as long as it does not collide with a network your users will connect from. Avoid 192.168.0.0/24 and 192.168.1.0/24, because consumer routers ship with them and remote workers will end up with the same range at home, which breaks the moment they connect over an IPsec VPN.

How do I know which subnet an address is in?

Apply the mask. Keep the address bits where the mask has 1s and set the rest to 0, and the result is the network address of the subnet that holds it.

What is subnetting?

Subnetting is the process of dividing one network into smaller networks by moving the boundary between the network portion and the host portion. You borrow bits from the host portion, and every bit borrowed doubles the number of subnets while halving the addresses available in each.

Do subnets improve security?

On their own, no. They make security enforceable, which is not the same thing. Putting sensitive devices on their own subnet lets a firewall or an access list control who reaches them, but the subnet does nothing until that rule exists.

Does any of this apply to IPv6?

The idea does, the arithmetic does not. IPv6 uses prefixes the same way, but addresses are 128 bits, there is no broadcast address, and the conventional subnet size is a /64 regardless of how few devices it holds.

Is there a subnetting cheat sheet for the common masks?

The short subnetting cheat sheet: /24 is 255.255.255.0 with 254 usable hosts, /25 is 255.255.255.128 with 126, /26 is .192 with 62, /27 is .224 with 30, /28 is .240 with 14, /29 is .248 with 6, and /30 is .252 with 2.

How do a subnet mask and an IP address work together?

The IP subnet mask marks which bits of the address name the network and which name the host. A device compares its own address and a destination through the mask. If the network bits match, it delivers directly. If they differ, it sends the packet to its default gateway.

Read next · Remote access What Is an IPsec VPN? A VPN is how two subnets in different buildings behave like one network. Open this next11 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.