How it works
An IP address (IPv4) is the number of a device in a network: four numbers from 0 to 255 separated by dots, e.g. 192.168.1.10. Internally it is 32 bits.
The subnet mask tells which part of the address is the network number and which part is the device number inside it. For example, mask 255.255.255.0 means the first 24 bits are the network and the last 8 bits are hosts.
The prefix (CIDR) is the same mask written briefly: the number of ones in it. /24 = 255.255.255.0, /26 = 255.255.255.192. 192.168.1.10/24 is an address together with its prefix.
The network address is the first address of the range (all host bits are 0) and names the network itself. The broadcast address is the last one (all host bits are 1); a packet sent to it reaches every device in the subnet. Addresses in between can be given to devices, so a /24 has 256 − 2 = 254 of them.
The wildcard mask is the inverted mask (0.0.0.255 for /24). It is used in ACLs and OSPF on Cisco equipment.
Special cases: in a /31 network both addresses are usable per RFC 3021, which saves addresses on point-to-point links; a /32 is exactly one address (a host route, a loopback interface).
The calculator also shows the address class (A–E, the legacy pre-CIDR scheme) and type: private (RFC 1918), loopback, link-local, CGNAT (100.64.0.0/10), multicast, reserved or public. You can also split the network into equal smaller subnets.
Where it is used
- Configuring a router and DHCP: which mask and gateway to set, which range to lease addresses from, how many devices fit.
- Are two addresses in the same subnet? Compute the network for each with the same mask: if the network addresses match, the devices reach each other directly, without a router.
- Firewall and ACL rules: a range for a rule in CIDR notation (iptables, nftables, cloud security groups) or a wildcard mask for a Cisco IOS ACL (
access-list 10 permit 192.168.1.0 0.0.0.255). - Subnet planning for an office (departments, VLANs, guest Wi-Fi) or a cloud VPC (AWS, GCP, Azure): split a large block into subnets of the right size without overlaps.
- Docker and Kubernetes: choose a bridge network subnet, Pod CIDR and Service CIDR that do not overlap with the office network and VPN.