Subnet Calculator
Calculate subnet masks, network and broadcast addresses, usable host ranges and CIDR notation for IPv4. Runs entirely in your browser.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
CIDR in one paragraph
An IPv4 address is 32 bits. CIDR notation writes a prefix length after a slash: /24 means the first 24 bits identify the network and the remaining 8 identify the host. The subnet mask is the same information written as an address, so /24 equals 255.255.255.0. Shorter prefixes mean bigger networks: a /16 holds 65,536 addresses, a /24 holds 256, a /30 holds 4.
Two addresses are not usable
In a standard subnet the first address is the network identifier and the last is the broadcast address, so a /24 with 256 addresses offers 254 usable hosts. This catches people sizing networks: if you need 254 devices you need a /24, and if you need 255 you need a /23. The exception is a /31, which RFC 3021 permits on point-to-point links where both addresses are usable because broadcast is meaningless with exactly two endpoints.
Private ranges
RFC 1918 reserves three blocks for private use: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. The middle one is the one people get wrong, because /12 spans 172.16.x.x through 172.31.x.x, not 172.16 to 172.24. Also reserved: 127.0.0.0/8 for loopback, 169.254.0.0/16 for link-local addresses assigned when DHCP fails, and 100.64.0.0/10 for carrier-grade NAT.
Why subnet
Splitting a network limits broadcast traffic, since a broadcast reaches only its own subnet, and it creates boundaries where access control can be applied. A flat network with thousands of hosts wastes bandwidth on broadcast and gives an attacker who reaches any host direct reachability to all the others.
Plan for growth, but not too much
Renumbering a production network is painful, so leave headroom. The common mistake in the other direction is allocating a /16 to a subnet holding twelve devices, which fragments your address plan and makes route summarisation impossible. Size to expected growth over a few years, not to the largest number you can imagine.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
Why does a /24 have 254 usable hosts and not 256?
The first address identifies the network and the last is the broadcast address, so both are unusable for hosts. The exception is a /31 on a point-to-point link, where RFC 3021 allows both addresses because broadcast is meaningless with two endpoints.
What does the slash number mean?
The number of leading bits that identify the network. A /24 fixes the first 24 of 32 bits, leaving 8 for hosts. Smaller numbers mean larger networks: /16 holds 65,536 addresses and /24 holds 256.
Which IP ranges are private?
10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 under RFC 1918. Note the middle block spans 172.16 through 172.31, which is commonly misremembered. Loopback is 127.0.0.0/8 and link-local is 169.254.0.0/16.
What is a subnet mask?
The same information as the CIDR prefix, written in dotted-decimal form. A /24 is 255.255.255.0. The mask's binary ones mark network bits and zeros mark host bits, which is why valid masks are always a contiguous run of ones.
How big should a subnet be?
Sized to expected growth over a few years, with headroom because renumbering is painful. Avoid the opposite error of assigning a very large block to a handful of devices, which fragments the address plan and prevents route summarisation.
Privacy & Security
Runs in your browser. Nothing you enter is uploaded or stored.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.