CIDR, Classless Inter Domain Routing, decides how IP addresses are divided up and handed out on the internet. It replaced fixed address classes with a prefix of any length, so a network can be exactly the size it needs. The notation is the small half. The large half is aggregation: because blocks nest, one route can cover thousands of networks.
- A block is a start address and a prefix length, nothing more
- Blocks nest exactly, which is what makes summarizing possible
- A more specific route always wins, everywhere
- Splitting a block between two owners is permanent
- Your public addresses almost certainly belong to your provider
On this page
The blockWhat a CIDR block actually is
A CIDR block is two things joined by a slash: a starting network address, and a number saying how many of the leading bits are fixed. That number is the prefix length, and it does the same job the subnet mask does in the older dotted decimal notation.
For example, in 192.0.2.0/24 the 24 says the first 24 bits identify the network and the remaining 8 vary across hosts. That leaves 256 addresses, from 192.0.2.0 to 192.0.2.255, which is the same network a mask of 255.255.255.0 describes. In 192.0.2.0/26 the first 26 bits are fixed, only 6 vary, and the block holds 64 addresses.
The arithmetic never changes. A block holds 2 raised to the power of 32 minus the prefix, so every step up in the prefix halves the network and every step down doubles it.
That doubling is what makes the whole scheme work, because subnets nest perfectly: two adjacent /25 subnets are exactly one /24, four /26 subnets are exactly one /24, and nothing is ever left over.
The host arithmetic, the subnet mask for every prefix, and the table from /8 to /32 are covered in full on the subnetting page. This page is about what CIDR blocks are for once you can read them.
Before CIDRWhy the classes had to go
Before 1993, classful addressing decided the split between network and host from the first bits of the address itself. A Class A network gave one organization 16 million addresses. Class B gave 65,536. Class C gave 254 hosts. There was nothing in between.
That produced two failures at once, and the second one is the one people forget.
Addresses were wasted. A company with 400 devices was too large for a Class C and therefore received a Class B, leaving 65,000 addresses unused. The address space was being consumed far faster than the number of connected machines justified.
The routing table was exploding. Every classful Class C network was its own route, and there were two million of them. Backbone routers had to hold an entry for each, and the table was growing faster than router memory could follow. This was the more urgent problem in 1993, and it is the one CIDR was actually designed to solve.
Classless addressing fixed both. A prefix of any length means a network can be sized to the requirement. And because subnets nest, a provider holding a large block advertises one route for all of it rather than one route per customer.
The classes survive only as vocabulary. When somebody calls a /24 a Class C, they mean a network of 254 hosts. The class itself has meant nothing for thirty years.
AggregationAggregation, which is the whole point
This is what CIDR is for, and it is the part most explanations skip.
For example, an internet provider holds a block, say 203.0.113.0/24. It divides that into subnets among customers: one gets a /28, another a /27, a third a /26. Each customer has their own network and their own host addresses.
What the provider advertises to the rest of the internet is one route: 203.0.113.0/24. Not sixteen routes for sixteen customer networks. Every router on the internet holds one entry, and data for any customer inside that block follows it to the provider, which then knows which subnet to send it to.
That is route aggregation, also called supernetting, and it scales the other way too. A provider holding sixteen adjacent /24 blocks advertises one /20 instead of sixteen /24s.
The saving is enormous and it is also fragile. Aggregation only works while the blocks are adjacent and held by the same party. Two consequences follow.
Fragmentation is permanent. A block split and sold to two different organizations can never be aggregated again, and both halves are advertised separately forever. Every transfer of address space between organizations adds a route the whole internet has to carry.
A more specific route always wins. Routers prefer the longest matching prefix, so a /25 announcement beats the /24 that contains it, everywhere. That is a useful feature for steering traffic between two links, and it is also the mechanism behind route hijacking, where a network announces a more specific block it does not own.
AllocationHow addresses actually reach you
The chain is worth knowing, because it explains why a small organization cannot simply request address space.
IANA holds the top of the space and allocates large blocks, typically /8, to the regional registries.
Five regional internet registries cover the world: ARIN for North America, RIPE NCC for Europe and the Middle East, APNIC for the Asia Pacific, LACNIC for Latin America, and AFRINIC for Africa. They allocate to providers and to organizations that qualify.
Providers receive a block and divide it among customers. Address space that comes to you this way is provider aggregatable: it is part of their block, it summarizes into their route, and you give it back when you leave.
Organizations that qualify can hold provider independent space directly from a registry. That space is yours, it moves with you between providers, and it needs its own route in the global table, which is exactly why registries do not hand it out casually.
| Level | Holds | Typical block | Hands out to |
|---|---|---|---|
| IANA | The whole IPv4 space | /8 and larger | The five registries |
| Regional registry | A continent | /8 to /12 | Providers, and members |
| Internet provider | Its own allocation | /16 to /20 | Customers |
| A business | What the provider lent | /29 to /24 | Its own subnets |
| A single connection | One public address | /32 | Nothing, NAT sits behind it |
Read the last two rows together. Almost every business sits on the fourth line with a handful of addresses that belong to the provider, and most sit on the fifth with exactly one. That is why NAT is everywhere and why changing provider means renumbering.
The practical consequence for a normal business: the addresses on your internet connection almost certainly belong to your provider, and changing provider means renumbering. Provider independent space plus BGP is what avoids that, and it is a real project rather than a request.
ExhaustionIPv4 exhaustion, and what CIDR could not fix
CIDR bought time. It did not create addresses.
Every regional registry has now exhausted its general IPv4 pool. ARIN reached that point in 2015, RIPE in 2019. What remains is a transfer market, where address space is bought from organizations that hold more than they need, at prices that have risen steadily.
Three responses followed, and all three are in use today.
Network address translation lets a whole private network share one public address, which is why almost every office and home has a private subnet inside and one public address outside. It works, and it breaks anything that needs to be reached from outside without a forwarding rule.
Carrier grade NAT does the same thing one level up, at the provider, so even the address on your router may be shared with other customers. It saves addresses and it makes several things harder, hosting anything among them.
IPv6 is the actual answer, with 128 bit addresses and enough space that allocation stops being a constraint. Adoption passed 40 percent of traffic to the largest providers and continues to climb, and CIDR notation carries over unchanged: a /64 subnet in IPv6 means exactly what a slash and a number mean in IPv4.
PitfallsWhere people go wrong
Reading a prefix backward. A larger number is a smaller network. A /26 is smaller than a /24, because more fixed bits leave fewer host bits. This trips people up constantly and it is worth saying out loud until it sticks.
Assuming any two blocks can merge. Aggregation needs blocks that are adjacent and correctly aligned. 192.0.2.0/25 and 192.0.2.128/25 combine into a /24. 192.0.2.128/25 and 192.0.3.0/25 do not combine into anything.
Choosing a cloud VPC range that overlaps something. Every cloud provider asks for a CIDR block when you create a virtual network, and 10.0.0.0/16 is the default everybody accepts.
It looks fine until that cloud network has to reach an office already using the same range. Overlapping private subnets cannot be routed together, and the fix is renumbering one side. Pick from a documented plan before you create the first one.
Sizing a block for today. Growing a network means renumbering every host in it, and renumbering is the work everybody postpones. Allocate a larger block and create subnets inside part of it.
Treating provider addresses as yours. They are lent, they summarize into the provider's route, and they go back at the end of the contract. Anything hard coded to them is a renumbering job waiting to happen.
Announcing a more specific route without meaning to. Splitting a block and advertising both halves separately adds two routes where one would do, and every router on the internet carries the cost.
ComparisonProvider address space against your own, on what each one costs you
| Criterion | Provider aggregatable | Provider independent |
|---|---|---|
| Comes from | Your provider | A regional registry |
| Survives changing provider | No | Yes |
| Needs its own route in the global table | No | Yes |
| Qualification required | None | Yes, and a justification |
| Annual cost | None, it is in the circuit | A registry membership |
| Needs BGP to use properly | No | Yes |
| Right for a single site office | Yes | No |
| Right for multihoming to two providers | No | Yes |
The last two rows decide it. If you have one internet connection, provider addresses are correct and cost nothing. If you need the same addresses reachable through two providers, only independent space does that, and you need BGP to announce it.
FAQFrequently asked questions
What does CIDR stand for?
Classless Inter Domain Routing. Classless because it replaced the fixed address classes, inter domain because its purpose was routing between networks.
What is a CIDR block?
A starting network address and a prefix length, written with a slash, such as 192.0.2.0/24. The prefix says how many leading bits are fixed, and the rest identify hosts.
What does the number after the slash mean?
The count of fixed leading bits. A higher number means more bits fixed, fewer left for hosts, and therefore a smaller block.
Is a /24 bigger or smaller than a /16?
Smaller. A /16 holds 65,536 addresses and a /24 holds 256. The larger the prefix number, the smaller the block.
What is route aggregation?
Advertising one route that covers many smaller blocks inside it, instead of a route for each. It is why the internet routing table is a size a router can hold.
What is supernetting?
The same idea from the other direction: combining adjacent blocks into one larger block. Two adjacent /25 blocks supernet into a /24.
Why did classful addressing disappear?
It wasted address space and made the routing table grow faster than router memory. Classless addressing fixed both at once.
Can any two blocks be combined?
No. They must be adjacent and aligned on the right boundary. Two blocks that merely sit near each other cannot be summarized.
What is provider independent address space?
Address space allocated to your organization directly by a regional registry, which stays with you when you change provider. It requires justification and it needs BGP to use.
Has IPv4 run out?
The registries have exhausted their general pools. Space still changes hands through a transfer market at rising prices, and NAT and IPv6 are the two real responses.
Does CIDR apply to IPv6?
Yes, unchanged. A /64 or a /48 subnet in IPv6 means the same thing: the number of leading bits that are fixed.
What size block should I request?
Larger than today's requirement, because growing means renumbering every host. For private space, plan the whole allocation and the subnets inside it before the first network exists, rather than adding ranges as you go.
What happened to network classes?
Network classes were the original scheme: class A used an 8 bit network prefix, class B 16 bits and class C 24 bits, chosen by the first bits of the address. CIDR replaced them in 1993 with prefixes of any length. The class names survive only as shorthand for /8, /16 and /24.
Keep readingRelated concepts
Read next · Addressing What Is a Subnet? The host arithmetic, the mask for every prefix, and the table from /8 to /32. Open this next15 min- Routing · 12 min What Is BGP? Aggregated routes are announced with BGP, and a more specific announcement is how a hijack works.
- Addressing · 9 min What Is DHCP? Once a block is divided into subnets, this is what hands the addresses inside them to devices.