IPv4 subnet cheat sheet: every mask, and the maths behind it
Usable hosts in a subnet = 2(32 − prefix) − 2. So a /24 has 254 usable addresses, /25 has 126, /26 has 62, /27 has 30, /28 has 14, /29 has 6 and /30 has 2. The two you subtract are the network and broadcast addresses.
To find which subnet an address is in, take the block size (256 minus the interesting mask octet) and count up from zero. For 10.4.7.130/26 the block size is 64, networks start at .0, .64, .128 and .192, so .130 sits in 10.4.7.128/26 with broadcast .191 and usable range .129 to .190. Or skip the maths with our subnet calculator.
The full table
| CIDR | Mask | Addresses | Usable |
|---|---|---|---|
| /8 | 255.0.0.0 | 16,777,216 | 16,777,214 |
| /16 | 255.255.0.0 | 65,536 | 65,534 |
| /20 | 255.255.240.0 | 4,096 | 4,094 |
| /21 | 255.255.248.0 | 2,048 | 2,046 |
| /22 | 255.255.252.0 | 1,024 | 1,022 |
| /23 | 255.255.254.0 | 512 | 510 |
| /24 | 255.255.255.0 | 256 | 254 |
| /25 | 255.255.255.128 | 128 | 126 |
| /26 | 255.255.255.192 | 64 | 62 |
| /27 | 255.255.255.224 | 32 | 30 |
| /28 | 255.255.255.240 | 16 | 14 |
| /29 | 255.255.255.248 | 8 | 6 |
| /30 | 255.255.255.252 | 4 | 2 |
| /31 | 255.255.255.254 | 2 | 2 (point-to-point, RFC 3021) |
| /32 | 255.255.255.255 | 1 | 1 (single host) |
Working it out without the table
Everything hangs off the block size: 256 minus the value of the interesting octet of the mask. A /27 mask ends in .224, so the block size is 32 and subnets start at .0, .32, .64 and so on. The network address is the start of the block the address falls into; the broadcast is one less than the start of the next block; everything in between is usable.
Worked example for 172.16.5.77/28: mask .240, block size 16, blocks at .64 and .80, so the network is 172.16.5.64, broadcast 172.16.5.79, usable .65 to .78.
Wildcard masks
Firewall and router ACLs often want the inverse of the mask. Subtract each octet from 255: a /26 mask of 255.255.255.192 becomes wildcard 0.0.0.63. If you can recite block sizes, the wildcard is always block size minus one.
The mistakes that cause the tickets
- Gateway outside the subnet. A device at 192.168.1.200/26 cannot reach a gateway at 192.168.1.1, which lives in the .0/26 block. Everything looks cabled and up, nothing routes.
- Overlapping site-to-site ranges. Two clients both on 192.168.1.0/24 will make every VPN between them miserable. Allocate from distinct RFC 1918 space per site while you still can.
- DHCP scope swallowing static space. Reserve a slice of every subnet for infrastructure before defining the scope.
Per-interface detail, fleet-wide.
Moorfox inventories every managed machine's interfaces with address, gateway, DNS and DHCP state, so subnet mismatches show up in a list instead of in a ticket.
Frequently asked questions
How many usable IP addresses are in a /27?
30. A /27 contains 32 addresses; subtracting the network and broadcast addresses leaves 30 usable hosts.
What prefix is the mask 255.255.255.240?
/28. It contains 16 addresses, of which 14 are usable.
When is a /31 subnet valid?
On point-to-point links, per RFC 3021. Both addresses are usable because there is no need for a broadcast address between exactly two routers. For anything with more than two hosts, /30 is the smallest workable subnet.