CIDR Notation Explained: What /24, /16 and /32 Mean

Learn how CIDR notation like 192.168.1.0/24 works, how to work out netmasks and usable hosts, which ranges are private, and how to split a network into subnets.

· 4 min read

You'll see CIDR notation like 10.0.0.0/16 in VPC settings, firewall rules, Kubernetes configs and Docker networks. The number after the slash tells you how big the network is. Once you can read it, sizing subnets and writing firewall rules stops being guesswork.

What the slash means

An IPv4 address is 32 bits, usually written as four numbers from 0 to 255. In CIDR notation, the number after the slash is the prefix length: how many of those 32 bits identify the network. The remaining bits identify individual hosts in that network.

192.168.1.0/24
            ^^ the first 24 bits are the network: 192.168.1
               the last 8 bits are for hosts: .0 to .255

A bigger prefix means a smaller network. Each extra bit halves the number of addresses.

Common prefixes

PrefixNetmaskAddressesUsable hostsTypical use
/8255.0.0.016,777,21616,777,214The whole 10.0.0.0 private range
/16255.255.0.065,53665,534A VPC or a large office network
/20255.255.240.04,0964,094A large cloud subnet
/24255.255.255.0256254A typical LAN or subnet
/27255.255.255.2243230A small subnet
/30255.255.255.25242A point-to-point link between two routers
/32255.255.255.25511A single host, common in firewall rules

The subnet mask cheat sheet has every prefix from /0 to /32.

Working out the numbers

Total addresses is 2 to the power of the host bits: 2^(32 − prefix). For a /24 that's 2⁸ = 256.

Usable hosts is usually two fewer, because the first address is the network address and the last is the broadcast address. In 192.168.1.0/24:

AddressRole
192.168.1.0Network address
192.168.1.1 – 192.168.1.254Usable hosts (254)
192.168.1.255Broadcast address

There are two exceptions. A /31 has two addresses and both are usable on point-to-point links (RFC 3021), and a /32 is exactly one host.

The netmask is the prefix written as 32 bits, 1s for the network part and 0s for the host part. /24 is 24 ones followed by 8 zeros, which is 255.255.255.0.

To skip the arithmetic, enter any address and prefix in the subnet calculator. It shows the network, broadcast, usable range and mask.

Cloud providers reserve more

AWS, Azure and Google Cloud keep a few extra addresses in every subnet for their own use. AWS reserves five: the network address, the next three, and the broadcast address. A /24 subnet in an AWS VPC gives you 251 usable addresses, not 254. Plan a little headroom when you size cloud subnets.

Private address ranges

RFC 1918 sets aside three ranges for private networks. They're never routed on the public internet, so every home router and VPC can reuse them:

RangeCIDRSize
10.0.0.0 – 10.255.255.25510.0.0.0/816.7 million addresses
172.16.0.0 – 172.31.255.255172.16.0.0/121 million addresses
192.168.0.0 – 192.168.255.255192.168.0.0/1665,536 addresses

A few other special ranges are worth knowing: 127.0.0.0/8 is loopback (localhost), 169.254.0.0/16 is link-local (what a machine assigns itself when DHCP fails), and 100.64.0.0/10 is used for carrier-grade NAT.

If you'll ever connect networks over VPN or VPC peering, give each one a range that doesn't overlap the others. Overlapping ranges can't be routed between each other, and renumbering a network later is painful.

Splitting a network into subnets

Adding one bit to the prefix splits a network into two halves. Adding two bits gives four quarters:

10.0.0.0/16
├── 10.0.0.0/17     (10.0.0.0   – 10.0.127.255)
└── 10.0.128.0/17   (10.0.128.0 – 10.0.255.255)

10.0.0.0/24 split into four /26 blocks:
  10.0.0.0/26    .0   – .63
  10.0.0.64/26   .64  – .127
  10.0.0.128/26  .128 – .191
  10.0.0.192/26  .192 – .255

A common VPC layout takes a /16 and carves it into /20 or /24 subnets per availability zone, with separate public and private tiers. The subnet calculator can split any block for you and show the resulting ranges.

A quick note on IPv6

IPv6 uses the same notation with 128-bit addresses, such as 2001:db8::/32. The sizes are on another scale: the standard subnet is a /64, which holds 2⁶⁴ addresses. In IPv6 you don't count usable hosts. You plan by how many /64 subnets you need.

Quick reference

  • The prefix is how many of the 32 bits belong to the network.
  • Addresses = 2^(32 − prefix). Usable hosts are usually two fewer.
  • /24 = 256 addresses, /16 = 65,536, /32 = one host.
  • Private ranges: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16.

Sizing a network? Work it out with the subnet calculator.