In the early days of ARPANET and the fledgling internet, IP addresses were handed out in rigid, wasteful chunks known as Classful Networks (Class A, B, and C). In 1993, the Internet Engineering Task Force introduced Classless Inter-Domain Routing (CIDR) via RFC 1519, revolutionizing IP allocation and preventing the premature exhaustion of the global IPv4 address space.
1. What Is CIDR Slash Notation?
You have likely encountered notation such as 192.168.1.0/24 or 10.0.0.0/16 in router configuration portals, firewall access lists, or cloud security groups (AWS, Google Cloud, Azure).
The number following the forward slash (e.g. /24) is the CIDR prefix length. It represents the exact count of continuous binary 1 bits in the 32-bit IPv4 subnet mask:
- Every IPv4 address contains exactly 32 bits (4 octets of 8 bits each).
- A prefix of
/24means the first 24 bits are dedicated to identifying the Network, while the remaining 8 bits (32 minus 24) are available to identify individual Hosts. - In dotted-decimal notation, 24 consecutive ones equals:
11111111.11111111.11111111.00000000=255.255.255.0.
Calculate Any CIDR Block Instantly
Need to calculate network boundaries, first usable IP, broadcast address, and wildcards? Use our interactive CIDR calculator.
Open CIDR Subnet Calculator →2. The Two Golden Formulas for Subnet Calculation
With just two basic mathematical formulas, you can calculate the exact properties of any subnet block without memorizing arbitrary tables:
- Total IP Addresses:
Total = 2 ^ (32 - Prefix)
For a/24subnet:2^(32 - 24) = 2^8 = 256total addresses. - Usable Host Addresses:
Usable = 2 ^ (32 - Prefix) - 2
Why minus two? Because the very first address in any subnet is reserved as the Network Address, and the very last address is reserved as the Broadcast Address. Thus, a/24provides256 - 2 = 254usable host IPs.
3. Master IPv4 CIDR Reference Cheat Sheet
| CIDR Prefix | Subnet Mask | Total IP Addresses | Usable Hosts | Typical Real-World Use Case |
|---|---|---|---|---|
| /32 | 255.255.255.255 | 1 | 1 (Host route) | Single device / VPN peer / firewall rule |
| /30 | 255.255.255.252 | 4 | 2 | Point-to-point router uplink links |
| /29 | 255.255.255.248 | 8 | 6 | Small office public IP block from ISP |
| /28 | 255.255.255.240 | 16 | 14 | Demilitarized Zone (DMZ) server subnet |
| /27 | 255.255.255.224 | 32 | 30 | Departmental VLAN / Cloud container cluster |
| /24 | 255.255.255.0 | 256 | 254 | Standard home Wi-Fi & office LAN |
| /23 | 255.255.254.0 | 512 | 510 | Medium corporate building campus |
| /16 | 255.255.0.0 | 65,536 | 65,534 | Enterprise internal network / AWS VPC |
| /8 | 255.0.0.0 | 16,777,216 | 16,777,214 | Global ISP backbone / 10.0.0.0 private block |
4. Private vs. Public Subnets (RFC 1918)
The Internet Assigned Numbers Authority (IANA) designated three specific IPv4 ranges strictly for private LAN use. These addresses are not routable on the public internet:
- 10.0.0.0/8: From
10.0.0.0to10.255.255.255(16.7 Million IPs, used by large data centers and enterprise networks). - 172.16.0.0/12: From
172.16.0.0to172.31.255.255(1 Million IPs, common in Docker container bridges). - 192.168.0.0/16: From
192.168.0.0to192.168.255.255(65,536 IPs, the standard for residential Wi-Fi routers).
5. Point-to-Point Links: RFC 3021 /31 Subnets
On traditional point-to-point serial links between two routers, a /30 was historically used, but it wastes 50% of the addresses (2 out of 4 are lost to network/broadcast). Under RFC 3021, modern network equipment allows /31 subnets (2 total addresses, 0 host bits, no broadcast address needed), saving millions of public IPv4 addresses across global telecommunication backbones.