Subnet calculator

Write something like 192.168.0.1/24 and get the first and last address of the block, how many hosts fit in it, and the netmask and wildcard. A netmask pasted in place of a prefix is read back into one. Meant for checking that ranges do not overlap before you commit a firewall rule or a security group.

Write it as `10.0.0.1/8`, or paste a netmask instead — `172.16.5.9 255.255.240.0`

Range

Network address
192.168.0.0/24
First usable
192.168.0.1
Last usable
192.168.0.254
Broadcast
192.168.0.255

Count

Addresses in block
256
Assignable to hosts
254

A /31 is a point-to-point link and uses both addresses (RFC 3021). A /32 is a single address, so no network or broadcast is set aside.

Mask

Prefix
/24
Netmask
255.255.255.0
Wildcard
0.0.0.255

In binary

11111111 11111111 11111111 00000000

This block is

Private

A private range under RFC 1918. It does not appear on the internet directly; it goes through NAT.

Accepted notations

192.168.0.1/24 is the usual form, and a netmask may stand in for the prefix — either /255.255.255.0 or after a space. A netmask must have its ones packed at the front; 255.0.255.0 has a hole and is rejected. An address with no prefix is treated as /32. Any host address will do: the block it belongs to is found from it.

Checking for overlap

Two blocks are not compared automatically. Enter each in turn, note its network and broadcast address, and compare: if one block's first address lies between the other's first and last, they overlap. The netmask written out in binary is there to show where the network part ends.

How far the special-range check goes

Only private (10/8, 172.16/12, 192.168/16), loopback (127/8), link-local (169.254/16) and multicast (224/4) are recognized; everything else is called public. So carrier-grade NAT space 100.64/10 and the documentation ranges 192.0.2.0/24 and 203.0.113.0/24 come out as public.

Frequently asked questions

Why are two addresses missing from the host count?

The first address names the network itself and the last is the broadcast, so neither can be assigned. A /24 holds 256 addresses but only 254 hosts. The exceptions are /31, a point-to-point link that uses both (RFC 3021), and /32, which is a single address.

What is the wildcard for?

It is the netmask with its bits inverted. Cisco ACLs and OSPF configuration use that notation instead of a netmask. The wildcard of 255.255.255.0 is 0.0.0.255.

Does it handle IPv6?

Not yet — IPv4 only. IPv6 addresses are 128 bits, beyond what a JavaScript number holds, and the work there is mostly compressing and expanding notation rather than arithmetic. An IPv6 address here comes back as unreadable.

How do I split a /24 into smaller blocks?

Each extra prefix bit halves the block. Splitting a /24 in four gives /26 blocks of 64 addresses and 62 hosts each. Enter them one at a time here — 192.168.0.0/26, 192.168.0.64/26 and so on, moving the first address — and each piece's range comes out.

What do I enter to open a security group to my IP only?

Append /32: 203.0.113.7/32 is that one address. Writing /24 opens all 256 addresses sharing the first three octets.