IP Subnet Calculator
Result
Network address
- Broadcast address
- 192.168.1.255
- First usable host
- 192.168.1.1
- Last usable host
- 192.168.1.254
- Usable hosts
- 254
- Addresses in the block
- 256
- Subnet mask
- 255.255.255.0
- Wildcard mask
- 0.0.0.255
This IP subnet calculator takes a CIDR block such as 192.168.1.10/24 and returns the network address, the broadcast address, the first and last usable host addresses, the subnet mask and the wildcard mask, together with the total number of addresses in the block. The number after the slash is the prefix length: /24 fixes the first 24 bits as the network part and leaves 8 bits for hosts, which is 256 addresses and 254 usable ones. Whatever the host bits were set to is cleared, so 192.168.1.10/24 belongs to the 192.168.1.0/24 network. The badge beside the result names the kind of address space — private, loopback, link local, multicast or public — and the table below lists every block IANA has reserved.
Special-purpose IPv4 blocks
| Block | Kind | Defined by |
|---|---|---|
| 0.0.0.0/8 | This network | RFC 791 §3.2 |
| 10.0.0.0/8 | Private use | RFC 1918 |
| 100.64.0.0/10 | Shared address space | RFC 6598 |
| 127.0.0.0/8 | Loopback | RFC 1122 §3.2.1.3 |
| 169.254.0.0/16 | Link local | RFC 3927 |
| 172.16.0.0/12 | Private use | RFC 1918 |
| 192.0.2.0/24 | Documentation | RFC 5737 |
| 192.168.0.0/16 | Private use | RFC 1918 |
| 198.18.0.0/15 | Benchmarking | RFC 2544 |
| 198.51.100.0/24 | Documentation | RFC 5737 |
| 203.0.113.0/24 | Documentation | RFC 5737 |
| 224.0.0.0/4 | Multicast | RFC 1112 |
| 240.0.0.0/4 | Reserved | RFC 1112 §4 |
| 255.255.255.255/32 | Limited broadcast | RFC 8190 / RFC 919 §7 |
Every block IANA lists in the IPv4 Special-Purpose Address Registry, plus the multicast range, which is registered separately. The kind names the block, and the last column is the document that defines it. An address that falls in none of them is reported as public.
Formula
network = address AND mask usable hosts = 2^(32 − prefix) − 2
- address
- The IPv4 address you type, as a 32-bit number
- mask
- The subnet mask, which is the first prefix bits set to 1
- network
- The address with every host bit cleared
- prefix
- The prefix length after the slash, 0 to 32
The first line is the whole of subnetting: the network address is the address ANDed with the mask, and the broadcast address is the same AND with every host bit set to 1 instead. Subtract those two addresses and you have the usable host count. The second line is the shortcut, and it holds for every prefix from /0 to /30. The two exceptions are the point-to-point prefixes /31 and /32, where the network and broadcast addresses are not reserved and the shortcut would undercount — this calculator applies the RFC 3021 rule for those instead.
Worked examples
A home network typed as 192.168.1.10/24
- The prefix is 24, so the mask is 24 ones followed by 8 zeros: 255.255.255.0.
- Clear the host bits of the address: 192.168.1.10 AND 255.255.255.0 = 192.168.1.0. That is the network address.
- Set the host bits instead: 192.168.1.0 OR 0.0.0.255 = 192.168.1.255. That is the broadcast address.
- The host range is everything between them: 192.168.1.1 to 192.168.1.254.
- Count: 2^8 = 256 addresses, minus the two reserved ones = 254 usable. ✓
The .10 the user typed is a host address inside the block, which is why it is not the answer to the first line — a block is identified by its network address.
A point-to-point link, 172.16.5.1/30
- A /30 leaves 2 host bits, so the block is 2^2 = 4 addresses and the mask ends in 252 (11111100).
- Network address: 172.16.5.1 AND 255.255.255.252 = 172.16.5.0.
- Broadcast: 172.16.5.0 plus the 3 host bits all set = 172.16.5.3.
- The two usable addresses are 172.16.5.1 and 172.16.5.2 — the address in the example is the router's own end. ✓
This is the smallest block that still wastes two addresses. A link between two routers needs exactly two, which is why /31 exists.
Splitting a /24 with a /26, entered as 192.168.1.130/26
- A /26 leaves 6 host bits: 2^6 = 64 addresses, mask 255.255.255.192.
- 172.16.5.1 is a different block; here 130 is 10000010 in binary, and a /26 keeps the first two of those bits: 130 AND 192 = 128.
- So the network address is 192.168.1.128, not 192.168.1.0 — a /26 sits on a multiple of 64 in the last octet.
- Broadcast: 192.168.1.128 + 63 = 192.168.1.191.
- Usable: 64 − 2 = 62 addresses, from .129 to .190. ✓
This is the calculation people get wrong by eye: the block boundaries under a /26 are 0, 64, 128 and 192, so an address of .130 is in the third quarter of the /24, not the first.
A single public host, 8.8.8.8/32
- A /32 keeps every bit as network, so the mask is 255.255.255.255 and the block is a single address.
- AND with an all-ones mask changes nothing: the network address is 8.8.8.8.
- There are no host bits to set, so the broadcast address is the same address.
- One address, and it is usable: the RFC 3021 style rule gives /32 a host count of 1 rather than 2^0 − 2 = −1. ✓
A /32 is how a single host route is written in a routing table or a firewall rule. The wildcard mask comes out as 0.0.0.0, which is exactly what a firewall needs to match one address.
Limitations
This calculator covers IPv4 only. IPv6 addresses are 128 bits wide, which does not fit in the same arithmetic and does not have the same host-count rules — a /64 has 2^64 addresses, so subtracting the network and broadcast addresses is meaningless there. An IPv6 input is rejected rather than approximated. The page also assumes the classic subnetting model: it reports the network and broadcast addresses as reserved and the host range as everything between them, which is what RFC 950 established and what almost every network still does. Other prefix-length conventions exist for special cases, and the block classification uses the IANA special-purpose registries as they stand today; those entries do change, and a block reserved after this page was written will be reported as public.
Frequently asked questions
- How do I work out the network address from a CIDR block?
- AND the address with the subnet mask. For 192.168.1.10/24 the mask is 255.255.255.0, which in binary is 24 ones followed by 8 zeros; ANDing clears the last octet, giving 192.168.1.0. The broadcast address is the same AND but with the host bits set to 1 instead of 0, so 192.168.1.255. Everything in between is the usable host range.
- How many usable hosts does a /26 have?
- 62. A /26 leaves 6 host bits, so the block is 2^6 = 64 addresses, and the network and broadcast addresses take two of them. The same rule gives 254 for a /24, 126 for a /25 and 30 for a /27. The two prefixes where it does not apply are /31, which has 2 usable addresses, and /32, which has 1.
- Which address ranges are private?
- Three blocks, all listed in RFC 1918: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. They are not routed on the public internet, so any organisation can use them freely as long as it does not need to reach another network using the same numbers. Several other blocks look similar but are not private — 100.64.0.0/10 is shared address space used inside carrier networks, and 169.254.0.0/16 is the link-local block a device self-assigns when DHCP fails.
- What is a wildcard mask, and how is it different from a subnet mask?
- It is the subnet mask inverted bit by bit. A /24 has the mask 255.255.255.0 and the wildcard 0.0.0.255. Cisco access lists and some firewall rules are written with wildcards, while interfaces are configured with the mask itself, which is why this page shows both. The two always add up to 255.255.255.255, so if you have one you have the other.
- Why does a /31 have two usable hosts instead of none?
- Because RFC 3021 changed the rule for that one prefix. A /31 has two addresses, and under the old arithmetic both would be reserved — one as the network address and one as the broadcast — leaving nothing for a link that needs exactly two endpoints. The RFC says to treat both addresses as usable hosts on point-to-point links, which is now what routers do, and what this calculator reports.
- Does this work for IPv6?
- No, and it does not pretend to. IPv6 addresses are 128 bits wide, so the same arithmetic cannot be done with the 32-bit integers used here, and the host-count rule is different in kind — a /64 contains 2^64 addresses, which is not a number you subtract two from. Entering an IPv6 prefix returns a format error rather than a wrong answer, and an IPv6 version would be a separate page with its own outputs.