How to read the result
Type an address with its prefix — 192.168.1.10/24, 10.0.0.1 255.0.0.0 or 2001:db8::/48 — and the calculator splits it into the network it belongs to. The minus and plus buttons make the network larger or smaller one bit at a time.
- Network address is the first address of the block, with every host bit set to 0. Routes and firewall rules name a network by it:
192.168.1.0/24. - Broadcast address is the last address, with every host bit set to 1. Like the network address it cannot be given to a host — except in a /31 and a /32, which have neither.
- Usable host range is everything between the two: the addresses you can assign to servers, routers and containers.
- Subnet mask and wildcard mask say the same thing as the prefix length, in the two notations older tools expect. A UFW firewall rule takes the prefix (
ufw allow from 10.0.0.0/24); a Cisco access list takes the wildcard. - Address type says whether the address is public or comes from a private, shared or reserved range — useful before you open a port to it or expect it to be reachable.
Below the details, Split into smaller subnets lists the blocks a network divides into — a /24 into four /26, a /48 into 65,536 /64 prefixes — for planning VLANs, container networks or the tunnel network of a WireGuard server.
IPv4 CIDR cheat sheet
Every prefix length from /8 to /32 with its netmask, wildcard and size.
| Prefix | Subnet mask | Wildcard | Addresses | Usable hosts |
|---|---|---|---|---|
| /8 | 255.0.0.0 | 0.255.255.255 | 16,777,216 | 16,777,214 |
| /9 | 255.128.0.0 | 0.127.255.255 | 8,388,608 | 8,388,606 |
| /10 | 255.192.0.0 | 0.63.255.255 | 4,194,304 | 4,194,302 |
| /11 | 255.224.0.0 | 0.31.255.255 | 2,097,152 | 2,097,150 |
| /12 | 255.240.0.0 | 0.15.255.255 | 1,048,576 | 1,048,574 |
| /13 | 255.248.0.0 | 0.7.255.255 | 524,288 | 524,286 |
| /14 | 255.252.0.0 | 0.3.255.255 | 262,144 | 262,142 |
| /15 | 255.254.0.0 | 0.1.255.255 | 131,072 | 131,070 |
| /16 | 255.255.0.0 | 0.0.255.255 | 65,536 | 65,534 |
| /17 | 255.255.128.0 | 0.0.127.255 | 32,768 | 32,766 |
| /18 | 255.255.192.0 | 0.0.63.255 | 16,384 | 16,382 |
| /19 | 255.255.224.0 | 0.0.31.255 | 8,192 | 8,190 |
| /20 | 255.255.240.0 | 0.0.15.255 | 4,096 | 4,094 |
| /21 | 255.255.248.0 | 0.0.7.255 | 2,048 | 2,046 |
| /22 | 255.255.252.0 | 0.0.3.255 | 1,024 | 1,022 |
| /23 | 255.255.254.0 | 0.0.1.255 | 512 | 510 |
| /24 | 255.255.255.0 | 0.0.0.255 | 256 | 254 |
| /25 | 255.255.255.128 | 0.0.0.127 | 128 | 126 |
| /26 | 255.255.255.192 | 0.0.0.63 | 64 | 62 |
| /27 | 255.255.255.224 | 0.0.0.31 | 32 | 30 |
| /28 | 255.255.255.240 | 0.0.0.15 | 16 | 14 |
| /29 | 255.255.255.248 | 0.0.0.7 | 8 | 6 |
| /30 | 255.255.255.252 | 0.0.0.3 | 4 | 2 |
| /31 | 255.255.255.254 | 0.0.0.1 | 2 | 2 |
| /32 | 255.255.255.255 | 0.0.0.0 | 1 | 1 |
Private and reserved IPv4 ranges
These blocks never appear as a public address on the internet. A server’s public interface has an address outside all of them; inside a LAN, a VPN or a container host you choose from the first three.
| Range | Used for |
|---|---|
| 10.0.0.0/8 | Private networks (RFC 1918) — large LANs, VPNs, cloud VPCs |
| 172.16.0.0/12 | Private networks (RFC 1918) — Docker's default bridge networks come from here |
| 192.168.0.0/16 | Private networks (RFC 1918) — most home and office routers |
| 100.64.0.0/10 | Carrier-grade NAT (RFC 6598): addresses an ISP gives its routers, shared by many customers |
| 127.0.0.0/8 | Loopback — the machine itself |
| 169.254.0.0/16 | Link-local — what a host gives itself when DHCP fails |
| 192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24 | Documentation and examples |
IPv6 prefixes in practice
IPv6 is calculated the same way, only with 128 bits instead of 32, which is why the calculator shows the size of a large prefix as a power of two. Three sizes come up again and again: a /64 is one network segment, because stateless autoconfiguration needs 64 bits for the interface identifier; a /56 holds 256 of those, and a /48 holds 65,536. Addresses starting with fd are unique local addresses, IPv6’s counterpart to the private IPv4 ranges, and fe80::/10 is link-local: every interface has one, and it never leaves the local link.
There is no broadcast address in IPv6 — multicast replaced it — so every address of a prefix is usable, and the calculator shows the first and the last address instead of a host range.
Frequently asked
How do I calculate the number of hosts in a subnet?
Subtract the prefix length from 32 to get the number of host bits and raise 2 to that power: a /24 has 2^8 = 256 addresses. The first is the network address and the last the broadcast address, which leaves 254 usable hosts. A /31 is the exception — RFC 3021 lets both of its addresses be used on a point-to-point link — and a /32 is a single host.
What is CIDR notation?
CIDR (Classless Inter-Domain Routing) writes a network as an address, a slash and the number of leading bits that identify the network, as in 192.168.1.0/24. It replaced the fixed class A, B and C networks in 1993 and is how routers, firewalls and server panels express address ranges today.
What is the difference between a subnet mask and a wildcard mask?
A subnet mask has a 1 for every network bit — 255.255.255.0 for a /24. A wildcard mask is its inverse, with a 1 for every bit that may vary — 0.0.0.255. Cisco-style access lists use the wildcard form; Linux, Windows and most firewalls take the prefix length or the subnet mask.
How many addresses are in an IPv6 /64, and why is it the usual subnet size?
A /64 holds 2^64 addresses, about 18.4 quintillion. Stateless address autoconfiguration (SLAAC) needs exactly 64 bits for the interface identifier, so an IPv6 LAN segment is a /64 almost by definition. Larger blocks such as a /56 or /48 exist so that one site can have 256 or 65,536 of those segments.
Is anything I enter sent to a server?
No. The calculator runs entirely in your browser. The address you enter is kept in the part of the page address after the # so that you can share the result, and browsers never send that part to the server.
Related guides
UFW firewall setup: deny by default, open what you serve
Configure UFW the safe way: allow SSH first, open only the ports you serve, restrict sensitive ports by source, and rate-limit the noise.
Initial server setup: the first ten minutes on a new VPS
A repeatable checklist for a fresh Ubuntu or Debian server: non-root user, key-only SSH, firewall, automatic security updates, hostname, timezone and swap.