↑ ↓ select, Enter open, Esc close

Subnet Calculator

Enter an IPv4 address with a prefix or netmask. The calculator shows the network, broadcast, host range and the binary representation.

Calculate subnet

For example 192.168.1.10/24 or 192.168.1.10 255.255.255.0.

Only needed if there is no prefix on the left. Defaults to /32.

Examples

192.168.1.0/24

Network address
192.168.1.0
Broadcast
192.168.1.255
Netmask
255.255.255.0 (/24)
Wildcard
0.0.0.255
First host
192.168.1.1
Last host
192.168.1.254
Usable hosts
254 (of 256 addresses)
Class
C
Scope
private (RFC 1918)
Binary (network part / host part)
Address  11000000.10101000.00000001.00001010
Mask     11111111.11111111.11111111.00000000
Network  11000000.10101000.00000001.00000000
Matching rules for this network
# Fail2ban (jail.local, section [DEFAULT])
ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24
# ufw
ufw allow from 192.168.1.0/24 to any port 22 proto tcp
# nginx
allow 192.168.1.0/24;
# Apache 2.4
Require ip 192.168.1.0/24

What the subnet calculator computes

An IPv4 address consists of 32 bits. The prefix after the slash (CIDR notation) tells you how many bits from the left define the network. The rest addresses the individual devices. In 192.168.1.10/24, the first 24 bits are the network 192.168.1.0, and the last 8 bits allow 256 addresses.

  • Network address: all host bits set to 0. It identifies the network itself and is not assigned to devices.
  • Broadcast: all host bits set to 1. Packets sent to this address go to every device in the network.
  • Netmask: the same information as the prefix, written as four numbers. /24 equals 255.255.255.0.
  • Wildcard: the inverted mask. It is used in Cisco ACLs and some firewalls.
  • Usable hosts: all addresses minus the network address and broadcast. Exceptions: with /31, both addresses are usable according to RFC 3021 (point-to-point links), and /32 denotes exactly one single address.

The classes A, B and C date from before CIDR and no longer matter for routing. They are only shown here because they still appear in older guides.

CIDR table /8 to /32

PrefixNetmaskWildcardAddressesUsable hosts
/8255.0.0.00.255.255.25516,777,21616,777,214
/9255.128.0.00.127.255.2558,388,6088,388,606
/10255.192.0.00.63.255.2554,194,3044,194,302
/11255.224.0.00.31.255.2552,097,1522,097,150
/12255.240.0.00.15.255.2551,048,5761,048,574
/13255.248.0.00.7.255.255524,288524,286
/14255.252.0.00.3.255.255262,144262,142
/15255.254.0.00.1.255.255131,072131,070
/16255.255.0.00.0.255.25565,53665,534
/17255.255.128.00.0.127.25532,76832,766
/18255.255.192.00.0.63.25516,38416,382
/19255.255.224.00.0.31.2558,1928,190
/20255.255.240.00.0.15.2554,0964,094
/21255.255.248.00.0.7.2552,0482,046
/22255.255.252.00.0.3.2551,0241,022
/23255.255.254.00.0.1.255512510
/24255.255.255.00.0.0.255256254
/25255.255.255.1280.0.0.127128126
/26255.255.255.1920.0.0.636462
/27255.255.255.2240.0.0.313230
/28255.255.255.2400.0.0.151614
/29255.255.255.2480.0.0.786
/30255.255.255.2520.0.0.342
/31255.255.255.2540.0.0.122
/32255.255.255.2550.0.0.011

Private and special address ranges

RangeUse
10.0.0.0/8private, large internal networks
172.16.0.0/12private, used among others by Docker networks (172.17.0.0/16 and following)
192.168.0.0/16private, typical for home and office networks
100.64.0.0/10carrier-grade NAT at ISPs, also used by Tailscale
127.0.0.0/8loopback, the machine itself
169.254.0.0/16link-local, used when no DHCP server answers

Use cases on the web server

Fail2ban: never ban your own networks

With ignoreip in /etc/fail2ban/jail.local you prevent Fail2ban from locking out your office or your monitoring server. Specify whole networks in CIDR notation, multiple entries separated by spaces. Then run systemctl reload fail2ban. In Plesk you maintain the same list under Tools & Settings, IP Address Banning as trusted IP addresses.

Firewall rules

It is best to open SSH or database ports only to known networks instead of the whole world. A prefix that is too large is a common mistake: /16 instead of /24 opens 65,536 instead of 256 addresses. Check the range here in the calculator first.

ufw allow from 203.0.113.0/24 to any port 22 proto tcp
iptables -A INPUT -s 203.0.113.0/24 -p tcp --dport 22 -j ACCEPT

Plesk: restrict access to the panel

Plesk can restrict access to its interface to specific addresses or networks (under Tools & Settings, Security, Restrict Administrative Access). Networks are entered there as an address plus mask. The calculator gives you both. Be sure to add your own network first, or you will lock yourself out.

nginx and Apache

For protected areas such as /wp-admin/ or a status dashboard, the directives allow 203.0.113.0/24; and deny all; are enough in nginx, and Require ip 203.0.113.0/24 in Apache 2.4. Behind a proxy or CDN, however, you see its address, so the real client IP has to be restored first (nginx real_ip, Apache mod_remoteip).

Server is clean. Is the site?

How fast does the website really load?

GENLOC.SEO measures PageSpeed and Core Web Vitals on mobile and desktop and tells you clearly what to fix first. Free, no time limit.

by GENLOC.NETWORK, the team behind myline.de

Bookmark this page: Press Ctrl + D (Mac: ⌘ + D) to have the subnet calculator ready for your next firewall rule.

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.