toolready. CIDR / Subnet Calculator

CIDR / Subnet Calculator

Decode an IPv4 CIDR block into network, range, and host count.

Network
—
Broadcast
—
First usable
—
Last usable
—
Mask
—
Wildcard
—
Total addresses
—
Usable hosts
—

What this does

Takes an IPv4 block in CIDR notation and expands it into the eight numbers you normally need: network address, broadcast address, first and last usable host, subnet mask, wildcard mask, total addresses and usable hosts. It also answers the "is this IP inside that range?" question. The arithmetic is 32-bit integer maths done in the page, so nothing about your network topology leaves the browser.

10.0.0.0/22
  network     10.0.0.0        mask       255.255.252.0
  broadcast   10.0.3.255      wildcard   0.0.3.255
  usable      10.0.0.1 – 10.0.3.254      1,022 hosts (1,024 total)

How do I read the number after the slash?

It is how many leading bits of the 32-bit address are fixed as the network portion; the remaining bits enumerate hosts. A /24 fixes 24 bits and leaves 8, giving 256 addresses. Each step smaller doubles the block: /23 is 512 addresses, /22 is 1,024. Each step larger halves it. That is the whole model — everything else on the panel falls out of it.

Why does a /24 have 254 usable hosts, not 256?

The lowest address in a block names the network itself and the highest is the broadcast address, so neither can be assigned to an interface. Two prefixes are exempt: a /31 reports both of its addresses as usable, which is the point-to-point link convention from RFC 3021, and a /32 is a single host with no broadcast at all. The calculator handles those cases rather than reporting zero or negative hosts.

What is the wildcard mask for?

It is the bitwise inverse of the subnet mask — 0.0.0.255 where the mask is 255.255.255.0. Cisco ACLs, OSPF network statements, and a few older firewall syntaxes want that inverted form instead of the mask, and hand-inverting octets is exactly where typos come from. Both are shown side by side so you can copy whichever the config wants.

Can I paste a host address instead of the network address?

Yes. 192.168.1.77/24 is accepted, and the mask is applied to find the network it belongs to — you get the same results as entering 192.168.1.0/24. That is usually what you want when you are reading an address off a server and trying to work out its subnet. Prefixes from /0 to /32 are all valid; anything else, an octet above 255, or a missing slash produces an error message rather than a silently wrong answer.

How do I check whether an IP is in a range?

Type it into the membership field under the results. It masks the address with the current prefix and compares against the network, showing in range or outside as you type — quick verification for a firewall rule, a security-group source, or a VPC subnet assignment.

Does this handle IPv6?

Not yet — this is IPv4 only. IPv6 prefixes run to /128 and the address count overflows the 32-bit integers the calculator is built on, so 2001:db8::/32 will simply be rejected as an invalid address.

Related: number base converter for reading masks in binary, user agent parser, and HTTP status codes.