What this does
Takes an IPv4 block in CIDR notation and expands it into the eight numbers you normally need: network address, broadcast address, first and last usable host, subnet mask, wildcard mask, total addresses and usable hosts. It also answers the "is this IP inside that range?" question. The arithmetic is 32-bit integer maths done in the page, so nothing about your network topology leaves the browser.
10.0.0.0/22
network 10.0.0.0 mask 255.255.252.0
broadcast 10.0.3.255 wildcard 0.0.3.255
usable 10.0.0.1 – 10.0.3.254 1,022 hosts (1,024 total) How do I read the number after the slash?
It is how many leading bits of the 32-bit address are fixed as the network
portion; the remaining bits enumerate hosts. A /24 fixes 24
bits and leaves 8, giving 256 addresses. Each step smaller doubles the
block: /23 is 512 addresses, /22 is 1,024. Each
step larger halves it. That is the whole model — everything else on the
panel falls out of it.
Why does a /24 have 254 usable hosts, not 256?
The lowest address in a block names the network itself and the highest is
the broadcast address, so neither can be assigned to an interface. Two
prefixes are exempt: a /31 reports both of its addresses as
usable, which is the point-to-point link convention from RFC 3021, and a
/32 is a single host with no broadcast at all. The calculator
handles those cases rather than reporting zero or negative hosts.
What is the wildcard mask for?
It is the bitwise inverse of the subnet mask — 0.0.0.255 where
the mask is 255.255.255.0. Cisco ACLs, OSPF network
statements, and a few older firewall syntaxes want that inverted form
instead of the mask, and hand-inverting octets is exactly where typos come
from. Both are shown side by side so you can copy whichever the config
wants.
Can I paste a host address instead of the network address?
Yes. 192.168.1.77/24 is accepted, and the mask is applied to
find the network it belongs to — you get the same results as entering
192.168.1.0/24. That is usually what you want when you are
reading an address off a server and trying to work out its subnet. Prefixes
from /0 to /32 are all valid; anything else, an
octet above 255, or a missing slash produces an error message rather than a
silently wrong answer.
How do I check whether an IP is in a range?
Type it into the membership field under the results. It masks the address with the current prefix and compares against the network, showing in range or outside as you type — quick verification for a firewall rule, a security-group source, or a VPC subnet assignment.
Does this handle IPv6?
Not yet — this is IPv4 only. IPv6 prefixes run to /128 and the address
count overflows the 32-bit integers the calculator is built on, so
2001:db8::/32 will simply be rejected as an invalid address.
Related: number base converter for reading masks in binary, user agent parser, and HTTP status codes.