Why split addresses into networks?
A postal address has two parts: the street gets the letter to the right neighbourhood, and the house number picks one door. IP addresses work the same way. The first part says which network a device is on, and the rest says which host (device) inside that network.
Routers only care about the network part. A router in Mumbai does not need to know every phone in a Delhi office. It only needs to know “anything in 192.168.10.x goes that way”. Splitting addresses into networks is what keeps the routing tables of the internet small.
An IPv4 address is 32 bits
We write IPv4 addresses as four numbers from 0 to 255, like 192.168.10.77. Each number is one octet: 8 bits. The computer sees all 32 bits in a row:
| Octet | 192 | 168 | 10 | 77 |
|---|---|---|---|---|
| Binary | 11000000 |
10101000 |
00001010 |
01001101 |
The prefix and the subnet mask (CIDR)
The number after the slash in 192.168.10.77/26 is the prefix length. It means: the first 26 bits are the network, the remaining 6 bits are the host. This way of writing it is called CIDR (Classless Inter-Domain Routing).
The subnet mask says the same thing as a 32-bit pattern: n ones followed by 32 − n zeros. For /26 that is 11111111.11111111.11111111.11000000 = 255.255.255.192.
| Prefix | Subnet mask | Addresses | Usable hosts |
|---|---|---|---|
| /8 | 255.0.0.0 | 16,777,216 | 16,777,214 |
| /16 | 255.255.0.0 | 65,536 | 65,534 |
| /24 | 255.255.255.0 | 256 | 254 |
| /25 | 255.255.255.128 | 128 | 126 |
| /26 | 255.255.255.192 | 64 | 62 |
| /27 | 255.255.255.224 | 32 | 30 |
| /28 | 255.255.255.240 | 16 | 14 |
| /29 | 255.255.255.248 | 8 | 6 |
| /30 | 255.255.255.252 | 4 | 2 |
Worked example: 192.168.10.77/26
Only the last octet matters here, because the first three are all network bits.
- Network address = IP AND mask.
01001101(77) AND11000000(192) =01000000= 64. The network is 192.168.10.64. - Broadcast address: keep the network bits and set all host bits to 1:
01111111= 127. The broadcast is 192.168.10.127. - Hosts: 6 host bits give 2⁶ = 64 addresses. Without the network and broadcast addresses, 62 are usable: 192.168.10.65 – 192.168.10.126.
In the 3D model you can watch every bit: the mask row lines up under the IP, the network row drops out of the IP row with its host bits switched off, and the floor shows the whole range of addresses with your IP marked.
The fast way: block size
You rarely need full binary in an exam. Find the interesting octet (the one where the mask is neither 255 nor 0) and compute:
block size = 256 − mask value in that octet
For /26 the mask octet is 192, so the block size is 256 − 192 = 64. Subnets start at 0, 64, 128 and 192. 77 lies between 64 and 127, so the network is .64 and the broadcast is .127 (one less than the next block).
Splitting a network into subnets
Suppose you own 192.168.1.0/24 and need 4 separate networks, one for each floor of a building. You borrow bits from the host part:
- 4 subnets need 2 bits (2² = 4), so the prefix grows from /24 to /26.
- Each subnet keeps 6 host bits: 64 addresses, 62 usable.
| Subnet | Borrowed bits | Network | Usable hosts | Broadcast |
|---|---|---|---|---|
| 0 | 00 |
192.168.1.0/26 | .1 – .62 | .63 |
| 1 | 01 |
192.168.1.64/26 | .65 – .126 | .127 |
| 2 | 10 |
192.168.1.128/26 | .129 – .190 | .191 |
| 3 | 11 |
192.168.1.192/26 | .193 – .254 | .255 |
Every borrowed bit doubles the number of subnets and halves the hosts in each one.
Code
Python has subnetting built in, in the ipaddress module:
import ipaddress
net = ipaddress.ip_interface("192.168.10.77/26").network
print(net) # 192.168.10.64/26
print(net.netmask) # 255.255.255.192
print(net.broadcast_address) # 192.168.10.127
hosts = list(net.hosts())
print(hosts[0], hosts[-1], len(hosts)) # 192.168.10.65 192.168.10.126 62
# Split a /24 into 4 subnets (borrow 2 bits)
for sub in ipaddress.ip_network("192.168.1.0/24").subnets(prefixlen_diff=2):
print(sub) # 192.168.1.0/26, .64/26, .128/26, .192/26
The same thing with plain bit operations:
#include <cstdint>
#include <cstdio>
void show(const char* name, uint32_t a) {
printf("%-10s %u.%u.%u.%u\n", name, a >> 24, (a >> 16) & 255, (a >> 8) & 255, a & 255);
}
int main() {
uint32_t ip = (192u << 24) | (168u << 16) | (10u << 8) | 77u;
int prefix = 26;
uint32_t mask = prefix == 0 ? 0 : 0xFFFFFFFFu << (32 - prefix);
uint32_t network = ip & mask; // host bits -> 0
uint32_t broadcast = network | ~mask; // host bits -> 1
show("mask", mask); // 255.255.255.192
show("network", network); // 192.168.10.64
show("broadcast", broadcast); // 192.168.10.127
printf("usable hosts: %u\n", (1u << (32 - prefix)) - 2); // 62
}
Special addresses worth knowing
- Private ranges (not routed on the internet, used at home and in offices):
10.0.0.0/8,172.16.0.0/12and192.168.0.0/16. - Loopback:
127.0.0.1always means “this computer”. - /30 gives exactly 2 usable hosts, which is perfect for a link between two routers. /31 is also allowed for such links (no broadcast), and /32 names a single address.
Classful addressing (the old way)
Before CIDR (1993), the first octet fixed the size of a network: Class A (1–126) used /8, Class B (128–191) used /16 and Class C (192–223) used /24. This wasted huge numbers of addresses. A company needing 300 hosts had to take a whole Class B with 65,534. CIDR lets the prefix be any length, which is why exam questions now give you the /n directly.
Common mistakes
- Forgetting to subtract the 2 reserved addresses: usable hosts = 2^h − 2, not 2^h.
- Assuming every subnet starts at
.0. It starts at a multiple of the block size, like .64 or .192. - Mixing up the mask value with the block size: for /26 the mask octet is 192 but the block size is 64.
- Borrowing bits from the network part. Subnet bits always come from the host part, so the prefix gets longer.
Complexity at a glance
| Case / operation | Time | Why |
|---|---|---|
| Addresses in a /n network | 2^(32 − n) | Every extra host bit doubles the size. |
| Usable hosts in a /n network | 2^(32 − n) − 2 | The network and broadcast addresses are reserved. |
| Find network or broadcast address | O(1) | One bitwise AND (or OR) on 32 bits. |
| Subnets after borrowing b bits | 2^b | Each one has 2^(32 − n − b) addresses. |
Quick check
Test yourself — pick an answer to see if you got it.
1. What is the subnet mask for a /26 prefix?
26 ones are 255.255.255 (24 ones) followed by 11000000 = 192 in the last octet.
2. How many usable host addresses does a /27 subnet have?
A /27 leaves 5 host bits, so 2^5 = 32 addresses. Two are reserved (network and broadcast), leaving 30.
3. Which network does 172.16.45.200/20 belong to?
The /20 mask is 255.255.240.0, so the third octet counts in blocks of 256 − 240 = 16 — 0, 16, 32, 48… 45 falls in the block that starts at 32.
4. You split 192.168.5.0/24 into 4 equal subnets. What prefix does each subnet get?
4 subnets need 2 borrowed bits (2² = 4), so the prefix grows from /24 to /26 — 64 addresses each.