Skip to content
RU
← All articles

Subnet Mask Cheat Sheet: /8–/32 Table and How to Calculate It

A subnet mask is a 32-bit value that splits an IPv4 address into a network part and a host part. 255.255.255.0 and /24 are the same mask written two ways: the first 24 bits identify the network, the last 8 identify devices. A /24 holds 256 addresses, of which 254 are usable hosts.

What a subnet mask actually does

An IPv4 address is 32 bits, written as four numbers for convenience: 192.168.10.25. The address alone does not say where the "street" ends and the "house number" begins. The mask draws that line.

A mask is 32 bits too, but strictly ordered: ones first, then zeros, never mixed. Ones mark network bits, zeros mark host bits. Hence two equivalent notations:

  • Prefix (CIDR) notation: 192.168.10.25/24 — "the first 24 bits are the network".
  • Dotted-decimal notation: mask 255.255.255.0 — the same 24 ones, spelled out per octet.

The practical consequence is singular: devices sharing the network part talk directly, everything else goes through the gateway. Before sending a packet, a host performs a bitwise AND of its own address with its mask, does the same for the destination, and compares the two results. Equal results mean "same subnet, deliver locally via ARP"; different results mean "hand it to the default gateway". Get the mask wrong and two machines sitting next to each other stop seeing one another.

  192.168.10.25   = 11000000.10101000.00001010.00011001
  255.255.255.0   = 11111111.11111111.11111111.00000000
  AND             = 11000000.10101000.00001010.00000000  → 192.168.10.0 (network)
Diagram: 32 address bits split by the mask into a network part and a host part, mask ones on the left, zeros on the right
The mask is a boundary inside the address: network bits to the left, host bits to the right. Mask ones are always contiguous and always leftmost.

Subnet mask table: /8 to /32 (cheat sheet)

This is the table most people came for — a subnet mask list you can keep open while writing a config. "Addresses" is the total in the subnet; "hosts" is how many you can actually assign to devices.

PrefixMaskAddressesHostsWhere you meet it
/8255.0.0.016,777,21616,777,214The whole 10.0.0.0/8 private range
/12255.240.0.01,048,5761,048,574The 172.16.0.0/12 private range
/16255.255.0.065,53665,534The 192.168.0.0/16 private range
/20255.255.240.04,0964,094An ISP or data-center segment
/22255.255.252.01,0241,022A large office network
/23255.255.254.0512510Two consecutive /24 subnets
/24255.255.255.0256254The typical office and home network
/25255.255.255.128128126Half of a /24
/26255.255.255.1926462A quarter of a /24, one department
/27255.255.255.2243230A small group of devices
/28255.255.255.2401614A rack or a set of servers
/29255.255.255.24886An access point, a tiny segment
/30255.255.255.25242A point-to-point link, the classic choice
/31255.255.255.25422A point-to-point link per RFC 3021
/32255.255.255.25511A single address: firewall rule, host route

Note the last two rows breaking the "minus two" rule. That is not a typo — see below. The prefixes skipped here follow the same pattern: every step of one bit doubles or halves the block, so /17 is 255.255.128.0 with 32,768 addresses and /21 is 255.255.248.0 with 2,048.

The only eight numbers a mask octet can hold

Because mask bits are contiguous, a single octet of a valid mask can only take nine values: 0 plus the eight below. Memorize this row and you can convert any prefix to dotted-decimal in your head: count how many full octets of 255 you have, then take the leftover bits from this table.

Bits set in the octetBinaryDecimalBlock size (256 − value)
110000000128128
21100000019264
31110000022432
41111000024016
5111110002488
6111111002524
7111111102542
8111111112551

Example: /19 = two full octets (16 bits) + 3 bits = 255.255.224.0. And anything outside this list — 255.255.255.100, 255.0.255.0 — is not a valid subnet mask at all; operating systems and routers reject it.

Is 255.255.255.0 the same as /24?

Yes, exactly the same. Write out 255.255.255.0 in binary and you get three octets of eight ones followed by eight zeros: 8 + 8 + 8 = 24 network bits. The /24 suffix is simply the count of those ones. The prefix form is shorter and standard in configuration files, cloud consoles and documentation; the dotted-decimal form survives in operating-system dialogs, DHCP settings and router web interfaces. When a form asks for a "netmask" and you only know the prefix, the table above is the translation.

One trap: /24 is a property of the network, not of the address. 192.168.1.0/24, 10.20.30.0/24 and 203.0.113.0/24 all use the same 255.255.255.0 mask and have nothing else in common.

What is a 255.255 subnet?

"A 255.255 subnet" is usually shorthand for 255.255.0.0, which is a /16: the first two octets are the network, the last two are hosts. That gives 65,536 addresses and 65,534 usable hosts — for example 172.20.0.0 through 172.20.255.255. Before CIDR it was called the default "Class B" mask.

People also say "255.255" when they mean a mask that starts with 255.255 — anything from /16 to /32. The third octet then tells you the real size: 255.255.255.0 is a /24, 255.255.252.0 a /22, 255.255.0.0 a /16. A /16 on a home or small-office LAN is almost always a mistake: every broadcast (ARP, DHCP discovery, mDNS) is flooded across a domain sized for tens of thousands of devices, and access rules written against it cover far more than intended.

Class A, B and C masks — and why they no longer define anything

Historical classFirst octetDefault maskPrefix
Class A1–126255.0.0.0/8
Class B128–191255.255.0.0/16
Class C192–223255.255.255.0/24

Classful addressing was replaced by Classless Inter-Domain Routing, described today in RFC 4632. The first octet no longer implies a mask: a 10.x address can live in a /24, and a 192.168.x address in a /16. Some operating systems still pre-fill the "class default" when you type an address into a dialog — that pre-filled value is a guess, not the truth for your network.

Why two addresses are subtracted

Every ordinary subnet reserves two addresses that are never handed to devices:

  • The network address — the very first one, all host bits zero. For 192.168.10.0/24 that is 192.168.10.0. It names the subnet itself and appears in routing tables.
  • The broadcast address — the very last one, all host bits set: 192.168.10.255. A packet sent there reaches every device in the subnet at once.

Hence the rule: hosts = 2(32 − prefix) − 2. For /24 that is 256 − 2 = 254; for /29, 8 − 2 = 6.

There are exactly two exceptions. A /31 for router-to-router links allocates neither a network nor a broadcast address — both addresses are usable, which is the point of it (RFC 3021). And a /32 is not really a subnet at all but one specific address: a host route or a firewall rule.

The classic beginner mistake is "I need 30 devices, so I'll take a /30". The prefix number is not the device count: a /30 gives two hosts, while thirty fit into a /27 — and only just, with no room for growth and no allowance for the gateway. Read the table instead of trusting intuition.

What is the subnet mask of 192.168.1.1/24?

The /24 already answers it: the mask is 255.255.255.0. Worked through fully:

FieldValue for 192.168.1.1/24
Subnet mask255.255.255.0
Network address192.168.1.0
First usable host192.168.1.1 (usually the router itself)
Last usable host192.168.1.254
Broadcast address192.168.1.255
Usable hosts254 (253 for other devices once the router takes one)
Wildcard (inverse) mask0.0.0.255

Without a prefix, the question "what is the subnet mask for 192.168.1.1?" has no single answer. Home routers ship with 255.255.255.0 by convention, but that is a default, not a property of the address: the same router can be configured for a /25 or a /23. The real value lives in the device's configuration — see the next section. If you are trying to reach the router's admin page rather than calculate its network, that is covered in 192.168.1.1 router login.

Calculating the network, broadcast and host range

Take 192.168.10.25/27 and work it through — this is the interview question and the server-configuration task in one, and a good subnet mask example because the boundary falls inside the last octet.

  1. Find the subnet step. A /27 is mask 255.255.255.224. Step = 256 − 224 = 32, so subnets start at 0, 32, 64, 96, 128, 160, 192, 224.
  2. Locate your subnet. The last octet is 25, which falls in the 0–31 block. Network address: 192.168.10.0.
  3. Broadcast is the last address of that block: 192.168.10.31.
  4. Host range is everything between: 192.168.10.1 through 192.168.10.30 — thirty addresses.

The same method works when the boundary is in the third octet. For 10.4.77.9/22 the mask is 255.255.252.0, the step in the third octet is 256 − 252 = 4, so blocks start at 0, 4, 8 … 76, 80. The value 77 lands in the 76–79 block: network 10.4.76.0, broadcast 10.4.79.255, hosts 10.4.76.1 to 10.4.79.254.

Checking by command beats checking in your head, and most systems can do it out of the box:

# Linux: show network, broadcast and range
ipcalc 192.168.10.25/27

# No ipcalc installed? The same thing with python3
python3 -c "import ipaddress as i; n=i.ip_network('192.168.10.25/27', strict=False); \
print(n, n.network_address, n.broadcast_address, n.num_addresses)"

# Is an address inside a subnet?
python3 -c "import ipaddress as i; \
print(i.ip_address('192.168.10.25') in i.ip_network('192.168.10.0/27'))"

# Convert between the two notations
python3 -c "import ipaddress as i; print(i.ip_network('0.0.0.0/255.255.255.224').prefixlen)"
python3 -c "import ipaddress as i; print(i.ip_network('0.0.0.0/27').netmask)"

Note that the ipcalc shipped by Debian/Ubuntu and the one shipped by RHEL/Fedora are different programs with different output formats; both accept the address/prefix form shown above. Python's ipaddress module behaves the same everywhere, which makes it the safer choice in scripts.

The same calculation without a terminal is what the IP calculator does: enter an address with its prefix and get the mask, network address, broadcast and host range immediately.

Calculation diagram: the last octet scale divided into blocks of 32 addresses, with network address, host range and broadcast highlighted
The calculation reduces to the subnet step: find the block the address lands in, and its edges give you the network, the host range and the broadcast.

What is my subnet mask? How to find it on any device

Your subnet mask is set on the network interface, either statically or by DHCP. It is not visible from the internet and no website can tell you what it is — a site only sees your public address. Read it locally:

SystemCommand or pathWhat you will see
Windows (Command Prompt)ipconfigSubnet Mask . . . : 255.255.255.0 under each adapter
Windows (PowerShell)Get-NetIPAddress -AddressFamily IPv4PrefixLength : 24
macOS (Terminal)ipconfig getoption en0 subnet_mask255.255.255.0 (Wi-Fi is usually en0)
macOS (Terminal)ifconfig en0netmask 0xffffff00 — the same mask in hexadecimal
macOS (GUI)System Settings → Network → your connection → Details → TCP/IPSubnet Mask field
Linuxip -4 addr showinet 192.168.1.20/24 — the prefix after the slash
iPhone / iPadSettings → Wi-Fi → (i) next to the networkSubnet Mask field
AndroidSettings → Network → Wi-Fi → the connected networkVaries by vendor; some builds show only the IP and gateway

The hexadecimal form from ifconfig converts pair by pair: ff = 255, 00 = 0, e0 = 224, so 0xffffffe0 is 255.255.255.224, a /27. For the address itself — local, router and public — see how to find an IP address.

Private ranges and addresses with special meaning

Not every address can be assigned freely. Several ranges are reserved, and they are the ones you meet in configuration files. The three private ranges are defined in RFC 1918.

RangeWhat it isIn practice
10.0.0.0/8Private networkCorporate networks, clouds, Docker environments
172.16.0.0/12Private networkFrequently the default for Docker and virtualization
192.168.0.0/16Private networkHome routers and small offices
127.0.0.0/8Loopback127.0.0.1 is the host itself; never leaves the machine
169.254.0.0/16Link-local self-assignmentSeeing one means DHCP never answered
100.64.0.0/10Carrier-grade NATYour "public" address is in fact shared with other subscribers

That last row explains the common "why does my external IP differ from what the site shows". If your ISP handed you an address from 100.64.0.0/10, you reach the internet under a shared address and inbound connections never arrive. What the outside world actually sees is shown by the IP lookup, and the difference between address families is covered in IPv4 vs IPv6.

Subnet mask vs wildcard mask

Cisco ACLs, OSPF network statements and some firewall products ask for a wildcard mask instead. It is the bitwise inverse: subtract each octet of the subnet mask from 255.

PrefixSubnet maskWildcard mask
/16255.255.0.00.0.255.255
/24255.255.255.00.0.0.255
/27255.255.255.2240.0.0.31
/30255.255.255.2520.0.0.3
/32255.255.255.2550.0.0.0

Pasting a subnet mask where a wildcard is expected is a common and quiet error: access-list 10 permit 192.168.1.0 255.255.255.0 does not match the /24 you intended. Zero bits in a wildcard mean "must match" and one bits mean "ignore", so this rule ignores the first three octets and matches every address whose last octet is 0.

Where masks matter to site owners, not just network engineers

Subnetting looks like an administrator's topic, yet /24-style notation shows up in places where nobody thinks about networks.

  • Restricting admin access. Allowing only the office means a CIDR rule, not a list of individual addresses. The Apache syntax is in the .htaccess guide, the nginx one in nginx configuration.
  • Blocking unwanted traffic. Bots rarely arrive from a single address; blocking them one by one is pointless.
  • Allow-lists from payment and mail providers. Their addresses are published as subnets and must be transferred into your config exactly.
  • SPF records. The ip4: mechanism accepts a whole subnet: ip4:203.0.113.0/24. How that affects delivery is in SPF records explained.
  • Rate limiting. Counting the limit per subnet rather than per address is a working defense against distributed brute force; approaches are in rate limiting strategies.
  • Cloud networks. AWS VPCs, Azure VNets and Google Cloud subnets are all defined in CIDR. Most of them reserve more than the classic two addresses in every subnet, so a cloud /28 gives you fewer than 14 usable hosts — check the provider's documentation before sizing tightly.
# The same office across different configurations
# nginx: admit only the office subnet to the admin area
location /admin/ {
    allow 203.0.113.0/24;
    deny  all;
}

# Apache 2.4: the same thing
<RequireAll>
    Require ip 203.0.113.0/24
</RequireAll>

# SPF: authorize the whole subnet to send mail
example.com.  IN  TXT  "v=spf1 ip4:203.0.113.0/24 -all"
A wrong mask in an access rule is more dangerous than it looks. Write /16 instead of /24 and instead of your office you have opened the admin panel to sixty-five thousand addresses, most of them strangers'. Calculate the range before saving the rule and confirm it contains what you meant.
Diagram: an access rule with a narrow subnet admits only the office, while a wide one exposes the panel to a large address space
One digit in the prefix changes the scale: /24 is an office, /16 is sixty-five thousand addresses with strangers among them.

Choosing a mask for the job

The rule is simple: take the nearest fitting subnet with a little headroom, but do not grab an enormous one "just in case" — surplus addresses complicate routing and incident analysis.

  • A link between two routers — /30 or /31. More than two addresses are never needed there.
  • A small set of servers — /28 (14 hosts) or /29 (6 hosts).
  • A department of 20–30 machines — /27 gives 30 hosts with no headroom; if growth is likely, start at /26 with 62.
  • An ordinary office network — /24: 254 hosts, familiar addresses, easy diagnostics.
  • Separation by purpose — rather than stretching one large subnet, cut several: staff, guests, printers, cameras. Safer, and far clearer in the logs.

And remember the gateway: it occupies an address from the host range too. A /29 with six addresses really leaves five devices. Before you commit, also make sure the new range does not overlap anything you already route to — a home 192.168.1.0/24 colliding with the same range on a remote office network is the most common reason a site-to-site tunnel "connects but nothing works".

Sizing diagram: a point-to-point link, a small set of servers, a department and an office network — each with its own subnet size
Subnet size follows the job: a link needs two addresses, a department thirty, an office two hundred and fifty-four.

Masks in IPv6: the same idea, shorter

IPv6 has no dotted-decimal masks at all — only prefixes. The logic is identical: /64 means the first 64 bits are the network. The difference is scale: a typical end-user /64 holds so many addresses that nobody economizes, and providers hand out entire /56 or /48 blocks. Counting hosts by hand there is pointless; the protocol comparison is in IPv4 vs IPv6.

How to check a subnet and what sits in it

  • IP calculator — mask, network address, broadcast, host range and address count from a prefix; the online equivalent of ipcalc.
  • IP lookup — which address the outside world sees, whose ISP it belongs to and which autonomous system it sits in.
  • Ping and port check — whether a host inside the chosen range answers.
  • Traceroute — which networks the traffic crosses on its way.

FAQ

What does 255.255.255.255 mean?

As a mask it is a /32 — exactly one address, used for host routes and single-address firewall rules. As a destination address it means a broadcast within the local segment.

How many devices fit in a /24?

254. There are 256 addresses, but the first is the network address and the last is the broadcast. One of the rest is almost always the gateway, leaving 253 for devices.

Why can two machines on the same network not see each other?

The classic cause is different masks behind similar-looking addresses. If one has a /24 and the other a /25, they disagree on where the network ends, and traffic goes to the gateway instead of the neighbor. Compare the masks on both machines first.

What is a 169.254.x.x address?

The device never got an address from DHCP and assigned itself a temporary one. There will be no internet on it. Look at the DHCP server, the cable or the Wi-Fi settings — not at the mask.

Is a subnet mask the same as a default gateway?

No. The mask defines which addresses are local; the gateway is the one local address that forwards everything else. Both are required, and the gateway must sit inside the subnet the mask describes.

Can I use any subnet mask I like?

Only a valid one — contiguous ones followed by zeros, built from the octet values 0, 128, 192, 224, 240, 248, 252, 254 and 255. And every device in the same subnet must use the same mask.

Subnet mask checklist

  • Prefix and dotted-decimal mask match (verified against the table).
  • Host count computed as 2(32 − prefix) − 2, with the gateway accounted for.
  • Every device in a subnet carries the same mask.
  • The chosen range does not overlap subnets already in use.
  • Point-to-point links use /30 or /31 rather than a larger subnet.
  • Prefixes in access and firewall rules were verified by calculating the range, not by eye.
  • Wildcard masks and subnet masks were not swapped in ACLs.
  • Private ranges are not confused with public ones, and no host sits on 169.254.0.0/16.
  • Subnets in SPF records and allow-lists were copied without changing the prefix.

Check your website right now

Check if your site is reachable →
More articles: Networking
Networking
Cloudflare Blocked in Russia? Why Sites Fail and How to Fix It
20.07.2026 · 2 945 views
Networking
Your Site Is Blocked in Russia: Owner's Guide
13.07.2026 · 1 143 views
Networking
ERR_CONNECTION_TIMED_OUT: Fix It in Chrome, Windows and Android
23.06.2026 · 1 041 views
Networking
IP Geolocation Accuracy: How It Works and Where It Fails
11.03.2026 · 1 019 views