What this CIDR calculator does
Planning a VPC, writing firewall rules or debugging why a container can't reach a database all come down to the same question: which addresses does this CIDR block contain? Enter any IPv4 or IPv6 address with a prefix length, like 10.0.0.0/16 or 2001:db8::/48, and the calculator shows the network address, broadcast address (IPv4), first and last usable host, netmask and wildcard mask, total addresses and usable hosts, address class and scope (private, public, loopback, documentation and more). It can split the network into smaller subnets and check whether a given IP falls inside the range.
How to use it
- Type an address with a prefix, e.g.
192.168.1.10/24. A bare IPv4 address defaults to/32. - Read the results table; the binary view shows which bits belong to the network and which to hosts.
- Choose a new prefix under split into subnets to list the resulting blocks, such as four
/26subnets inside a/24. - Enter an IP under is an IP in range? to check membership instantly.
Quick reference
- /32 – a single IPv4 host; /128 for IPv6.
- /31 – point-to-point link with 2 usable addresses (RFC 3021).
- /30 – 4 addresses, 2 usable hosts.
- /24 – 256 addresses, 254 hosts, netmask
255.255.255.0. - /16 – 65,536 addresses, a common VPC size.
- /64 – the standard IPv6 subnet size; SLAAC requires it.
- /48 – a typical IPv6 site allocation, room for 65,536 /64 subnets.
Private and special ranges
10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 are private (RFC 1918). 100.64.0.0/10 is carrier-grade NAT. 169.254.0.0/16 is link-local. In IPv6, fc00::/7 is unique local, fe80::/10 is link-local and 2001:db8::/32 is reserved for documentation.
Tips
- AWS reserves 5 addresses in every subnet, Azure 5 and GCP 4, so usable hosts in the cloud are slightly fewer.
- Avoid overlapping ranges between VPCs, VPNs and Docker's default
172.17.0.0/16if networks will ever be connected. - The wildcard mask is the inverse of the netmask and is used in Cisco ACLs and OSPF.