What the subnet calculator computes
An IPv4 address consists of 32 bits. The prefix after the slash (CIDR notation) tells you how many bits from the left define the network. The rest addresses the individual devices. In 192.168.1.10/24, the first 24 bits are the network 192.168.1.0, and the last 8 bits allow 256 addresses.
- Network address: all host bits set to 0. It identifies the network itself and is not assigned to devices.
- Broadcast: all host bits set to 1. Packets sent to this address go to every device in the network.
- Netmask: the same information as the prefix, written as four numbers. /24 equals 255.255.255.0.
- Wildcard: the inverted mask. It is used in Cisco ACLs and some firewalls.
- Usable hosts: all addresses minus the network address and broadcast. Exceptions: with /31, both addresses are usable according to RFC 3021 (point-to-point links), and /32 denotes exactly one single address.
The classes A, B and C date from before CIDR and no longer matter for routing. They are only shown here because they still appear in older guides.
CIDR table /8 to /32
| Prefix | Netmask | Wildcard | Addresses | Usable hosts |
|---|---|---|---|---|
| /8 | 255.0.0.0 | 0.255.255.255 | 16,777,216 | 16,777,214 |
| /9 | 255.128.0.0 | 0.127.255.255 | 8,388,608 | 8,388,606 |
| /10 | 255.192.0.0 | 0.63.255.255 | 4,194,304 | 4,194,302 |
| /11 | 255.224.0.0 | 0.31.255.255 | 2,097,152 | 2,097,150 |
| /12 | 255.240.0.0 | 0.15.255.255 | 1,048,576 | 1,048,574 |
| /13 | 255.248.0.0 | 0.7.255.255 | 524,288 | 524,286 |
| /14 | 255.252.0.0 | 0.3.255.255 | 262,144 | 262,142 |
| /15 | 255.254.0.0 | 0.1.255.255 | 131,072 | 131,070 |
| /16 | 255.255.0.0 | 0.0.255.255 | 65,536 | 65,534 |
| /17 | 255.255.128.0 | 0.0.127.255 | 32,768 | 32,766 |
| /18 | 255.255.192.0 | 0.0.63.255 | 16,384 | 16,382 |
| /19 | 255.255.224.0 | 0.0.31.255 | 8,192 | 8,190 |
| /20 | 255.255.240.0 | 0.0.15.255 | 4,096 | 4,094 |
| /21 | 255.255.248.0 | 0.0.7.255 | 2,048 | 2,046 |
| /22 | 255.255.252.0 | 0.0.3.255 | 1,024 | 1,022 |
| /23 | 255.255.254.0 | 0.0.1.255 | 512 | 510 |
| /24 | 255.255.255.0 | 0.0.0.255 | 256 | 254 |
| /25 | 255.255.255.128 | 0.0.0.127 | 128 | 126 |
| /26 | 255.255.255.192 | 0.0.0.63 | 64 | 62 |
| /27 | 255.255.255.224 | 0.0.0.31 | 32 | 30 |
| /28 | 255.255.255.240 | 0.0.0.15 | 16 | 14 |
| /29 | 255.255.255.248 | 0.0.0.7 | 8 | 6 |
| /30 | 255.255.255.252 | 0.0.0.3 | 4 | 2 |
| /31 | 255.255.255.254 | 0.0.0.1 | 2 | 2 |
| /32 | 255.255.255.255 | 0.0.0.0 | 1 | 1 |
Private and special address ranges
| Range | Use |
|---|---|
| 10.0.0.0/8 | private, large internal networks |
| 172.16.0.0/12 | private, used among others by Docker networks (172.17.0.0/16 and following) |
| 192.168.0.0/16 | private, typical for home and office networks |
| 100.64.0.0/10 | carrier-grade NAT at ISPs, also used by Tailscale |
| 127.0.0.0/8 | loopback, the machine itself |
| 169.254.0.0/16 | link-local, used when no DHCP server answers |
Use cases on the web server
Fail2ban: never ban your own networks
With ignoreip in /etc/fail2ban/jail.local you prevent Fail2ban from locking out your office or your monitoring server. Specify whole networks in CIDR notation, multiple entries separated by spaces. Then run systemctl reload fail2ban. In Plesk you maintain the same list under Tools & Settings, IP Address Banning as trusted IP addresses.
Firewall rules
It is best to open SSH or database ports only to known networks instead of the whole world. A prefix that is too large is a common mistake: /16 instead of /24 opens 65,536 instead of 256 addresses. Check the range here in the calculator first.
ufw allow from 203.0.113.0/24 to any port 22 proto tcp
iptables -A INPUT -s 203.0.113.0/24 -p tcp --dport 22 -j ACCEPTPlesk: restrict access to the panel
Plesk can restrict access to its interface to specific addresses or networks (under Tools & Settings, Security, Restrict Administrative Access). Networks are entered there as an address plus mask. The calculator gives you both. Be sure to add your own network first, or you will lock yourself out.
nginx and Apache
For protected areas such as /wp-admin/ or a status dashboard, the directives allow 203.0.113.0/24; and deny all; are enough in nginx, and Require ip 203.0.113.0/24 in Apache 2.4. Behind a proxy or CDN, however, you see its address, so the real client IP has to be restored first (nginx real_ip, Apache mod_remoteip).