You'll see CIDR notation like 10.0.0.0/16 in VPC settings, firewall rules, Kubernetes configs and Docker networks. The number after the slash tells you how big the network is. Once you can read it, sizing subnets and writing firewall rules stops being guesswork.
What the slash means
An IPv4 address is 32 bits, usually written as four numbers from 0 to 255. In CIDR notation, the number after the slash is the prefix length: how many of those 32 bits identify the network. The remaining bits identify individual hosts in that network.
192.168.1.0/24
^^ the first 24 bits are the network: 192.168.1
the last 8 bits are for hosts: .0 to .255A bigger prefix means a smaller network. Each extra bit halves the number of addresses.
Common prefixes
| Prefix | Netmask | Addresses | Usable hosts | Typical use |
|---|---|---|---|---|
| /8 | 255.0.0.0 | 16,777,216 | 16,777,214 | The whole 10.0.0.0 private range |
| /16 | 255.255.0.0 | 65,536 | 65,534 | A VPC or a large office network |
| /20 | 255.255.240.0 | 4,096 | 4,094 | A large cloud subnet |
| /24 | 255.255.255.0 | 256 | 254 | A typical LAN or subnet |
| /27 | 255.255.255.224 | 32 | 30 | A small subnet |
| /30 | 255.255.255.252 | 4 | 2 | A point-to-point link between two routers |
| /32 | 255.255.255.255 | 1 | 1 | A single host, common in firewall rules |
The subnet mask cheat sheet has every prefix from /0 to /32.
Working out the numbers
Total addresses is 2 to the power of the host bits: 2^(32 − prefix). For a /24 that's 2⁸ = 256.
Usable hosts is usually two fewer, because the first address is the network address and the last is the broadcast address. In 192.168.1.0/24:
| Address | Role |
|---|---|
192.168.1.0 | Network address |
192.168.1.1 – 192.168.1.254 | Usable hosts (254) |
192.168.1.255 | Broadcast address |
There are two exceptions. A /31 has two addresses and both are usable on point-to-point links (RFC 3021), and a /32 is exactly one host.
The netmask is the prefix written as 32 bits, 1s for the network part and 0s for the host part. /24 is 24 ones followed by 8 zeros, which is 255.255.255.0.
To skip the arithmetic, enter any address and prefix in the subnet calculator. It shows the network, broadcast, usable range and mask.
Cloud providers reserve more
AWS, Azure and Google Cloud keep a few extra addresses in every subnet for their own use. AWS reserves five: the network address, the next three, and the broadcast address. A /24 subnet in an AWS VPC gives you 251 usable addresses, not 254. Plan a little headroom when you size cloud subnets.
Private address ranges
RFC 1918 sets aside three ranges for private networks. They're never routed on the public internet, so every home router and VPC can reuse them:
| Range | CIDR | Size |
|---|---|---|
| 10.0.0.0 – 10.255.255.255 | 10.0.0.0/8 | 16.7 million addresses |
| 172.16.0.0 – 172.31.255.255 | 172.16.0.0/12 | 1 million addresses |
| 192.168.0.0 – 192.168.255.255 | 192.168.0.0/16 | 65,536 addresses |
A few other special ranges are worth knowing: 127.0.0.0/8 is loopback (localhost), 169.254.0.0/16 is link-local (what a machine assigns itself when DHCP fails), and 100.64.0.0/10 is used for carrier-grade NAT.
If you'll ever connect networks over VPN or VPC peering, give each one a range that doesn't overlap the others. Overlapping ranges can't be routed between each other, and renumbering a network later is painful.
Splitting a network into subnets
Adding one bit to the prefix splits a network into two halves. Adding two bits gives four quarters:
10.0.0.0/16
├── 10.0.0.0/17 (10.0.0.0 – 10.0.127.255)
└── 10.0.128.0/17 (10.0.128.0 – 10.0.255.255)
10.0.0.0/24 split into four /26 blocks:
10.0.0.0/26 .0 – .63
10.0.0.64/26 .64 – .127
10.0.0.128/26 .128 – .191
10.0.0.192/26 .192 – .255A common VPC layout takes a /16 and carves it into /20 or /24 subnets per availability zone, with separate public and private tiers. The subnet calculator can split any block for you and show the resulting ranges.
A quick note on IPv6
IPv6 uses the same notation with 128-bit addresses, such as 2001:db8::/32. The sizes are on another scale: the standard subnet is a /64, which holds 2⁶⁴ addresses. In IPv6 you don't count usable hosts. You plan by how many /64 subnets you need.
Quick reference
- The prefix is how many of the 32 bits belong to the network.
- Addresses = 2^(32 − prefix). Usable hosts are usually two fewer.
- /24 = 256 addresses, /16 = 65,536, /32 = one host.
- Private ranges:
10.0.0.0/8,172.16.0.0/12,192.168.0.0/16.
Sizing a network? Work it out with the subnet calculator.