Subnet Calculator

Enter an IPv4 or IPv6 network in CIDR notation, or an IPv4 address with a dotted netmask, to see its boundaries, size, masks, address type and reverse DNS zone. You can also split it into equal subnets or check whether another address falls inside it.

Results appear here as you type, for example 192.168.10.37/22.

What it does

An IP network is written as an address plus a prefix length. The prefix length says how many leading bits are fixed for the network; the bits after them number the individual hosts. This calculator derives everything that follows from that pair, with no binary arithmetic by hand. All of the math runs in your browser.

For an IPv4 network it shows the network and broadcast addresses, the first and last usable host, the total address count and the usable host count, the netmask and its wildcard (inverse) mask, the prefix length, and a binary view of the address and mask lined up bit for bit. It labels the address type as private (RFC 1918), carrier-grade NAT (100.64.0.0/10), loopback, link-local, documentation, multicast or public, and names the in-addr.arpa zone used for reverse DNS.

For an IPv6 network it shows the network prefix, the first and last address in the range, the total count as an exact number and as a power of two, the compressed and fully expanded forms, the address type (global unicast, unique local fc00::/7, link-local fe80::/10, documentation 2001:db8::/32, multicast or loopback) and the ip6.arpa reverse zone.

How to use it

  1. Type a network into the input box. Use CIDR notation for either family, such as 192.168.10.37/22 or 2001:db8:abcd::/48, or an IPv4 address followed by a space and a dotted netmask, such as 10.1.2.3 255.255.255.0.
  2. Read the results. For 192.168.10.37/22 you get network 192.168.8.0, broadcast 192.168.11.255, usable hosts 192.168.8.1 through 192.168.11.254, 1,024 addresses with 1,022 usable, netmask 255.255.252.0 and wildcard 0.0.3.255.
  3. To split the network, choose a longer prefix. The same /22 divided into /24 gives four subnets, and into /26 gives sixteen. Each one is listed with its range, up to 256 subnets.
  4. To test membership, enter another address in the contains check. It tells you whether that address falls inside the network above.

The host bits do not need to be zero: paste an interface address straight from a config file and the calculator finds its network. The netmask form is for IPv4 only; IPv6 always takes a prefix length.

Two IPv4 sizes follow their own rules. A /31 has two addresses, and under RFC 3021 both count as usable on a point-to-point link. A /32 is a single host.

Use cases

  • Checking a firewall rule. A vendor asks you to allow 172.16.40.0/21. Enter it and test 172.16.47.200 in the contains check; the /21 runs from 172.16.40.0 to 172.16.47.255, so the address is covered.
  • Carving up a home lab. Split 192.168.50.0/24 into four /26 networks of 62 usable hosts each, one apiece for servers, virtual machines, IoT devices and guests.
  • Sizing a cloud subnet. AWS reserves five addresses in every subnet, the first four and the last, so a /24 there leaves 251 for instances rather than 254. Other cloud providers hold back a few addresses per subnet too.
  • Writing router ACLs. Cisco access lists and OSPF network statements take a wildcard mask instead of a netmask. The calculator gives you 0.0.15.255 for a /20 with no mental arithmetic.
  • Reading an IPv6 delegation. Your ISP delegates a /56 to your router. Split it into /64 and you get the 256 LAN-sized subnets you can hand out, one per VLAN.
  • Spotting carrier-grade NAT. If your router reports a WAN address such as 100.72.14.9, the calculator labels it carrier-grade NAT. Your provider translates your traffic again upstream, which is why inbound port forwards generally fail.

Reading CIDR and netmasks

An IPv4 address has 32 bits, and the number after the slash is how many belong to the network. A /24 leaves 8 host bits, and 2^8 = 256 addresses. Each step shorter doubles the block (a /23 holds 512, a /22 holds 1,024); each step longer halves it (a /25 holds 128, a /30 holds 4). In ordinary IPv4 subnets the all-zeros host value names the network and the all-ones value is the broadcast, which is why a /24 offers 254 usable hosts and a /30 offers 2.

A dotted netmask carries the same information as a run of ones followed by zeros. To turn one into a prefix, count the ones octet by octet: each 255 is 8, and a partial octet maps as 128 = 1, 192 = 2, 224 = 3, 240 = 4, 248 = 5, 252 = 6, 254 = 7.

netmask   255.255.240.0
binary    11111111.11111111.11110000.00000000
ones      8 + 8 + 4 + 0 = 20   ->  /20
wildcard  0.0.15.255   (255 minus each octet)
size      2^(32-20) = 4,096 addresses, 4,094 usable

So 10.1.2.3 255.255.240.0 is the same input as 10.1.2.3/20, and it lands in the network 10.1.0.0 to 10.1.15.255.

Sizing and aligning subnets

Size each segment from its expected head count, then round up to a power of two with room to grow. A small office might give each staff VLAN a /24, guest Wi-Fi a /23, the management network a /27 with 30 hosts, and each router-to-router link a /31. Allocate the largest blocks first, each aligned on its own size, and the smaller ones fit into the gaps without overlap.

Alignment also decides whether routes can be summarized. The four /24s from 10.20.4.0 to 10.20.7.0 collapse into one route, 10.20.4.0/22, because 4 is a multiple of 4. The four /24s from 10.20.2.0 to 10.20.5.0 cover the same amount of space but need two routes, 10.20.2.0/23 and 10.20.4.0/23.

In IPv6 a LAN segment should be a /64, because stateless address autoconfiguration expects a 64-bit interface identifier. There is no broadcast address, since one-to-many traffic uses multicast, so the calculator reports IPv6 size as a plain total. Reverse zones follow label boundaries: in-addr.arpa labels are whole octets, so a /22 spans four /24 zones, while ip6.arpa labels are single hex digits, so 2001:db8:abcd::/48 becomes d.c.b.a.8.b.d.0.1.0.0.2.ip6.arpa.

Frequently asked questions

Why does a /24 have 254 usable hosts instead of 256?

A /24 leaves 8 host bits, which gives 256 addresses. In a normal IPv4 subnet the address with every host bit set to zero identifies the network, and the one with every host bit set to one is the broadcast address, so neither is assigned to a device. That leaves 254. The same two-address deduction applies to every IPv4 prefix up to /30.

Is a /31 a valid subnet?

Yes, on point-to-point links. RFC 3021 allows both addresses of a /31 to be used by hosts, because a link with exactly two ends has no need for a network or broadcast address. That saves half the space compared with a /30, which spends two of its four addresses on overhead. The calculator follows this rule and reports two usable hosts for a /31.

Why are IPv6 networks shown without a usable host count?

IPv6 has no broadcast address, so there is no top address to remove, and the ranges are so large that subtracting one or two would change nothing in practice. The calculator shows the total number of addresses instead, both as an exact figure and as a power of two. A /64, for example, holds 2^64, or 18,446,744,073,709,551,616 addresses.

Can I use a prefix longer than /64 on an IPv6 LAN?

You can configure one, but stateless address autoconfiguration expects a 64-bit interface identifier, so hosts that rely on it will not form addresses on that segment. Keep /64 for any network with ordinary clients. Longer prefixes are reasonable on router-to-router links, where RFC 6164 recommends /127, and for loopback addresses, which are commonly given a /128.

What is a wildcard mask?

It is the netmask with every bit flipped, so 255.255.255.0 becomes 0.0.0.255. In the wildcard form a zero bit means the address must match and a one bit means it may vary. Cisco IOS access lists and OSPF network statements use it. You can derive it by subtracting each netmask octet from 255, and the calculator shows it next to the netmask.

My router shows a WAN address between 100.64.0.0 and 100.127.255.255. What does that mean?

That range is 100.64.0.0/10, set aside for carrier-grade NAT by RFC 6598. Your provider gave your router a shared internal address and translates your traffic to a public address further upstream. Outbound connections work normally, but unsolicited inbound ones, such as a port forward to a game server or a camera, generally cannot reach you unless the provider assigns you a public address.

Where does the calculation happen?

Entirely in your browser. Every result on the page, from the broadcast address to the ip6.arpa zone and the list of split subnets, is computed locally by the page itself, so the calculator does not depend on a server to answer. Separately, iseeu.cc keeps no request logs and no database of visitors, sets no cookies and shows no ads.

Calculations follow the standard CIDR rules. Cloud providers, ISPs and some operating systems reserve extra addresses inside a subnet, so check their documentation before relying on an exact host count.