ToyTools Guide
How CIDR Notation and Subnet Masks Work
What CIDR notation means, how a subnet mask carves a network from an IPv4 address, and why /31 and /32 do not use the minus-two host rule.
Quick Answer
A CIDR calculator turns an IPv4 prefix into the numbers a firewall, a VPC, or an ACL actually wants. Paste 192.168.1.0/24, or an address and mask like 10.0.0.1 255.255.0.0, and you get the network address, the broadcast, the usable host range, the subnet mask, and the wildcard mask. This page is a subnet calculator and a subnet mask calculator: CIDR versus dotted subnet mask is two writings of the same prefix, so convert CIDR to IP range and you get the same block either way. For example, 192.168.1.0/24 has 256 addresses, 254 usable hosts from 192.168.1.1 to 192.168.1.254, mask 255.255.255.0, and wildcard 0.0.0.255. That cidr to ip range is what a security group wants.
Try The CIDR Calculator →How CIDR Notation Works
CIDR notation writes the address and the prefix length together. The number after the slash is how many leading bits identify the network. A /24 keeps the first 24 bits and leaves 8 bits for hosts, which is 256 addresses. A /16 leaves 16 host bits, which is 65,536 addresses. The subnet mask is the same fact written as four octets: /24 is 255.255.255.0, /16 is 255.255.0.0. To get the network address, AND the typed address with that mask. Host bits that were set in what you pasted drop out, which is why 192.168.1.50/24 still describes the 192.168.1.0/24 network.
Examples
A home /24. 192.168.1.0/24 has mask 255.255.255.0, broadcast 192.168.1.255, and usable hosts 192.168.1.1 through 192.168.1.254.
A host in a /24. 192.168.1.50/24 is still the 192.168.1.0/24 network. A firewall rule that lists 192.168.1.50/24 as if it were the network is listing one host. Use the network address the calculator offers.
A /31 link. 10.0.0.0/31 has two addresses and no broadcast. Both 10.0.0.0 and 10.0.0.1 are usable, per RFC 3021. Subtracting two hosts here would leave an empty subnet. That is the /31 versus /32 host counts difference: /32 is one host, /31 is two, and neither uses the minus-two rule.
Why /31 and /32 Break the Minus-Two Rule
The textbook usable-host formula is 2 to the power of host bits, minus two. The minus two removes the network address and the broadcast address. That formula is right for /0 through /30 and wrong at the edges. A /32 is a host route: there is one address, and talking about a broadcast inside a single host is meaningless. A /31 is a point-to-point link. RFC 3021 says both addresses are usable, so a calculator that still subtracts two will tell you the subnet is empty. Cloud security groups and ISP interconnects use /31 for exactly this reason.
Wildcard Masks for ACLs
A wildcard mask is the inverse of the subnet mask. Bits that are 0 must match; bits that are 1 are ignored. For 255.255.255.0 the wildcard is 0.0.0.255. To find the wildcard mask for an ACL on Cisco IOS, invert the prefix rather than guessing. This page is a wildcard mask calculator for that job: it shows both so the ACL and the CIDR stay in step. A mask with a hole in the bits, like 255.0.255.0, is not a CIDR prefix and is rejected rather than rounded.
Common Questions
Is CIDR the same as a subnet calculator?
Yes for IPv4. CIDR is the notation. A subnet calculator is the same math with a dotted mask as the input. This page accepts both.
Does this handle IPv6?
No. IPv6 prefixes have no broadcast and a different host-count story. Paste an IPv4 address.
Common Mistakes
Related Tools
You May Also Need
You may also need
- What Is My IPSee the address this connection presents
- Binary ConverterRead the same address as binary
Next steps
- Hex Encoder and DecoderInspect a packet hex dump next to the prefix
- Unix Timestamp ConverterStamp the change window for a cutover