Guides

How to Calculate CIDR Subnets and Extract IP Ranges Online

To calculate IPv4 CIDR subnets and extract usable IP address lists, perform bitwise AND operations between the IP address and its subnet mask to isolate the network address, derive the broadcast boundary from host bits, and enumerate all intermediate assignable IPs using an online CIDR and subnet extractor entirely within local browser memory.

Modern enterprise networking, cloud infrastructure deployment, and cybersecurity operations depend on Classless Inter-Domain Routing (CIDR) to allocate IP address blocks efficiently. Whether configuring an AWS Virtual Private Cloud (VPC), partitioning Azure Virtual Networks (VNets), or auditing firewall access control lists (ACLs), network engineers must routinely convert CIDR slash notation (such as 192.168.1.0/24 or 10.0.0.0/16) into precise network boundaries, usable host ranges, and individual IP lists.

Manual binary calculations are error-prone, particularly when segmenting large subnets across variable octet boundaries. Conversely, uploading proprietary corporate IP schemes to public cloud tools introduces significant security and compliance risks. Understanding the mathematical fundamentals of subnetting alongside client-side browser tools enables engineers to compute, validate, and extract network ranges instantly and securely.

Key Definitions: Classless Inter-Domain Routing (CIDR / RFC 4632), Subnet Mask, Wildcard Mask, Network Address, Broadcast Address, and Usable Host Range

Mastering IP subnetting requires a precise technical understanding of fundamental networking concepts defined by the Internet Engineering Task Force (IETF):

  • Classless Inter-Domain Routing (CIDR / RFC 4632): An IP addressing scheme that replaced legacy fixed-class allocations. CIDR uses variable-length subnet masking (VLSM) and prefix notation (e.g., /24) to allocate IP addresses based on specific size requirements rather than rigid class boundaries.
  • Subnet Mask: A 32-bit binary number that separates an IP address into network and host portions. Consecutive binary 1s denote the network prefix, while consecutive 0s represent the host space. In dotted-decimal notation, 24 network bits are expressed as 255.255.255.0.
  • Wildcard Mask: The bitwise inverse (complement) of a subnet mask, calculated by subtracting each octet from 255 (e.g., 0.0.0.255 for a /24 prefix). Wildcard masks are widely utilised in Cisco IOS Access Control Lists (ACLs) and Open Shortest Path First (OSPF) routing configurations.
  • Network Address (Base Address): The lowest numerical address within a subnet block where all host bits are set to binary 0. It uniquely identifies the network segment to upstream routers and cannot be assigned to an individual host interface.
  • Broadcast Address: The highest numerical address in a standard subnet where all host bits are set to binary 1 (e.g., 192.168.1.255 in 192.168.1.0/24). Packets transmitted to this address are received by all active hosts on the broadcast domain.
  • Usable Host Range: The inclusive sequence of assignable IP addresses between the network address and broadcast address (spanning from Network + 1 to Broadcast - 1).

Classful Networking vs CIDR: How Prefix Lengths (/24, /16, /8) Eliminated IP Address Space Exhaustion

Prior to the introduction of CIDR in 1993, the global IPv4 address space was divided into rigid, predefined classes defined in RFC 791:

  • Class A (/8): Reserved the first octet for the network (supporting 126 networks) and allocated 24 bits for hosts (yielding 16,777,214 usable addresses per network). Organisations allocated a Class A block rarely utilised millions of host addresses, resulting in massive address waste.
  • Class B (/16): Allocated 16 network bits and 16 host bits, providing 65,534 assignable host addresses across 16,384 networks. Demand for Class B blocks rapidly depleted available pools during early internet expansion.
  • Class C (/24): Allocated 24 network bits and 8 host bits, providing only 254 usable addresses per network. Organisations needing 500 to 1,000 addresses were forced to request multiple Class C blocks, causing global routing tables to inflate exponentially.
  • Class D (/4) & Class E (/4): Reserved exclusively for multicast streaming (224.0.0.0/4) and experimental research (240.0.0.0/4).

The introduction of RFC 1519 and its subsequent standardisation in RFC 4632 established Classless Inter-Domain Routing. CIDR eliminated fixed class boundaries, allowing network administrators to subdivide or aggregate (supernet) IP blocks along any bit boundary. A prefix length appended with a forward slash (such as /22 for 1,022 usable hosts or /27 for 30 usable hosts) matches exact enterprise operational needs, drastically conserving IPv4 address space and preventing global BGP routing table collapse.

Step-by-Step: How to Calculate CIDR Subnets and Extract IP Ranges in Your Browser

Calculating subnet boundaries and extracting complete lists of assignable IP addresses can be accomplished in five straightforward steps using client-side tooling:

  1. Input Your Target CIDR Block:
    Enter your base IP address and slash prefix notation (e.g., 10.50.0.0/22 or 172.16.8.0/26) into the online CIDR and subnet extractor.
  2. Validate Subnet Mask and Host Capacity:
    The tool instantly evaluates the prefix length to determine the subnet mask (255.255.252.0 for /22), wildcard mask (0.0.3.255), total addresses (1,024), and usable host capacity (1,022).
  3. Determine Network and Broadcast Boundaries:
    Review the computed network address (first IP) and broadcast address (last IP) to ensure the range aligns with your cloud VPC or on-premises routing layout.
  4. Extract Full Assignable Host Lists:
    Generate the entire sequence of usable IP addresses from start to finish. When auditing legacy network data, you can also extract IP addresses from text logs or parse server access log fields to cross-reference active endpoints against your subnet plan.
  5. Export Clean IP Formats for Firewalls:
    Copy or download the output formatted as newline-delimited lists, comma-separated values (CSV), or JSON arrays ready for immediate import into firewall rules and security groups.

Bitwise Arithmetic Behind Subnetting: AND Operations, Host Bits Calculation (2^(32-n) – 2), and Binary Masks

At the hardware and kernel level, routers and operating systems do not evaluate dotted-decimal notation; they process 32-bit binary strings. Understanding the underlying bitwise logic is vital for diagnosing routing issues and automated script generation.

1. Bitwise Logical AND Operation

To determine whether a destination IP belongs to the local subnet or requires routing via a default gateway, a network interface applies a bitwise logical AND operation between the destination IP and the local subnet mask. In bitwise logic, an output bit is 1 only if both corresponding input bits are 1:

IP Address (192.168.10.75):   11000000.10101000.00001010.01001011
Subnet Mask (/26):            11000000.11111111.11111111.11000000
------------------------------------------------------------------
Network Address (Bitwise AND): 11000000.10101000.00001010.00000000 -> 192.168.10.0

2. Calculating Total Addresses and Usable Hosts

The number of available host bits in any IPv4 subnet is given by h = 32 - n, where n represents the CIDR prefix length. Mathematical formulas dictate total capacity and assignable hosts:

  • Total Addresses: N_total = 2^(32 - n)
  • Usable Hosts (Standard Subnets): N_usable = 2^(32 - n) - 2

The subtraction of 2 accounts for the reserved network address (all host bits 0) and the broadcast address (all host bits 1). For example, a /28 subnet has 32 - 28 = 4 host bits. Total capacity is 2^4 = 16 addresses, while usable hosts equal 16 - 2 = 14 addresses.

3. Determining Subnet Increment (Magic Number)

The “magic number” represents the numerical block size in the interesting octet (the octet where the mask boundary splits). Subtracting the mask octet value from 256 yields the block increment. For a 255.255.255.224 (/27) mask in the fourth octet:

Block Size = 256 - 224 = 32
Subnet Ranges: 
  Subnet 1: 192.168.1.0   to 192.168.1.31   (Broadcast: .31)
  Subnet 2: 192.168.1.32  to 192.168.1.63   (Broadcast: .63)
  Subnet 3: 192.168.1.64  to 192.168.1.95   (Broadcast: .95)
  Subnet 4: 192.168.1.96  to 192.168.1.127  (Broadcast: .127)

CIDR Subnet Cheat Sheet Table (/0 to /32)

The following reference cheat sheet provides complete mathematical parameters, subnet masks, wildcard masks, total capacities, usable hosts, and common network engineering use cases for all IPv4 prefix lengths from /0 to /32:

Prefix Subnet Mask Wildcard Mask Total Addresses Usable Hosts Typical Use Case
/0 0.0.0.0 255.255.255.255 4,294,967,296 4,294,967,294 Default route (Internet all-traffic: 0.0.0.0/0)
/1 128.0.0.0 127.255.255.255 2,147,483,648 2,147,483,646 Global routing table half-split
/2 192.0.0.0 63.255.255.255 1,073,741,824 1,073,741,822 Major IANA top-level regional allocation
/3 224.0.0.0 31.255.255.255 536,870,912 536,870,910 Supernet aggregation block
/4 240.0.0.0 15.255.255.255 268,435,456 268,435,454 Multicast (Class D) and Future Use (Class E)
/5 248.0.0.0 7.255.255.255 134,217,728 134,217,726 Regional Internet Registry (RIR) macro-block
/6 252.0.0.0 3.255.255.255 67,108,864 67,108,862 Large RIR allocation block
/7 254.0.0.0 1.255.255.255 33,554,432 33,554,430 Tier-1 telecommunications transit block
/8 255.0.0.0 0.255.255.255 16,777,216 16,777,214 Legacy Class A / Private RFC 1918 (10.0.0.0/8)
/9 255.128.0.0 0.127.255.255 8,388,608 8,388,606 Large enterprise backbone allocation
/10 255.192.0.0 0.63.255.255 4,194,304 4,194,302 Carrier-Grade NAT / CGNAT (RFC 6598 100.64.0.0/10)
/11 255.224.0.0 0.31.255.255 2,097,152 2,097,150 National ISP customer aggregation
/12 255.240.0.0 0.15.255.255 1,048,576 1,048,574 Private RFC 1918 block (172.16.0.0/12)
/13 255.248.0.0 0.7.255.255 524,288 524,286 Metropolitan ISP distribution network
/14 255.252.0.0 0.3.255.255 262,144 262,142 Multi-region enterprise network
/15 255.254.0.0 0.1.255.255 131,072 131,070 Large cloud multi-account aggregate
/16 255.255.0.0 0.0.255.255 65,536 65,534 Legacy Class B / Standard AWS VPC / Azure VNet root
/17 255.255.128.0 0.0.127.255 32,768 32,766 Half-VPC enterprise partition
/18 255.255.192.0 0.0.63.255 16,384 16,382 Large enterprise cloud availability zone
/19 255.255.224.0 0.0.31.255 8,192 8,190 Cloud region container cluster address pool
/20 255.255.240.0 0.0.15.255 4,096 4,094 Availability zone subnet / Campus core VLAN
/21 255.255.248.0 0.0.7.255 2,048 2,046 Medium corporate data centre zone
/22 255.255.252.0 0.0.3.255 1,024 1,022 Minimum ISP routable IPv4 transfer / Kubernetes pool
/23 255.255.254.0 0.0.1.255 512 510 Multi-tier application deployment / Data centre pod
/24 255.255.255.0 0.0.0.255 256 254 Legacy Class C / Standard LAN / Cloud public/private subnet
/25 255.255.255.128 0.0.0.127 128 126 Split /24 subnet / Kubernetes worker node group
/26 255.255.255.192 0.0.0.63 64 62 Departmental VLAN / Database cluster subnet
/27 255.255.255.224 0.0.0.31 32 30 Application tier subnet / Microservice pool
/28 255.255.255.240 0.0.0.15 16 14 Small infrastructure subnet / Load balancer tier
/29 255.255.255.248 0.0.0.7 8 6 Public WAN link / Small ISP commercial gateway
/30 255.255.255.252 0.0.0.3 4 2 Legacy point-to-point router link
/31 255.255.255.254 0.0.0.1 2 2 Modern point-to-point router link (RFC 3021)
/32 255.255.255.255 0.0.0.0 1 1 Single host route / Loopback interface / Firewall target

Designing Cloud Networks: AWS VPC, Azure VNet, and GCP Subnet Allocation Best Practices

Modern cloud architecture relies heavily on CIDR subnet planning. Major cloud providers (Amazon Web Services, Microsoft Azure, and Google Cloud Platform) handle IP reservation and subnetting differently than traditional on-premises routers.

1. Cloud Provider Reserved IP Addresses

In traditional on-premises networking, only 2 IP addresses are reserved per subnet (network address and broadcast address). However, major hyperscalers reserve additional internal management IPs within every provisioned subnet:

  • AWS VPC (5 Reserved IPs per Subnet): In an AWS subnet such as 10.0.1.0/24, AWS reserves 5 addresses:
    • 10.0.1.0: Network address.
    • 10.0.1.1: Reserved by AWS for the default VPC router.
    • 10.0.1.2: Reserved by AWS for DNS resolution (AmazonProvidedDNS).
    • 10.0.1.3: Reserved by AWS for future internal use.
    • 10.0.1.255: Network broadcast address.

    Usable hosts in an AWS /24 subnet equal 251 (256 – 5).

  • Azure Virtual Network (5 Reserved IPs per Subnet): Azure similarly reserves the first 3 assignable IP addresses (x.x.x.1 default gateway, x.x.x.2/x.x.x.3 Azure DNS/management mapping) along with the x.x.x.0 network address and x.x.x.255 broadcast address.
  • Google Cloud Platform (GCP VPC): GCP VPC networks are global resources containing regional subnets. GCP reserves 4 addresses in each subnet: network address (first IP), default gateway (first usable IP), second-to-last IP (reserved for future use), and broadcast address (last IP).

2. Cloud Architecture Subnet Sizing Guidelines

When architecting a production cloud infrastructure, follow these systematic sizing recommendations:

  • VPC / VNet Root Allocation: Provision a /16 (65,536 total IPs, e.g., 10.100.0.0/16) or /20 (4,096 IPs) root block to allow non-overlapping expansion across multiple regions and accounts.
  • Availability Zone (AZ) Partitioning: Divide the root VPC block evenly across multiple availability zones. For instance, carve three /20 blocks for AZ-a, AZ-b, and AZ-c.
  • Tiered Subnet Slicing: Within each AZ, slice distinct subnets for Public Load Balancers (/24 or /26), Application Services/EKS/AKS pods (/22 or /23), and Isolated Database Backends (/26 or /27).
  • Avoid Overlapping CIDR Blocks: Ensure VPC CIDR ranges do not overlap with corporate on-premises IP spaces (e.g., via AWS DirectConnect or Azure ExpressRoute) or peered VPCs, preventing unresolvable BGP routing conflicts.

Network engineers frequently encounter specialized prefix allocations that depart from standard host calculation rules:

1. Point-to-Point Links (/31 Notation / RFC 3021)

Under traditional subnetting rules, a point-to-point router link required a /30 subnet (4 total IPs: 1 network, 1 broadcast, and 2 usable host interfaces), wasting 50% of the assigned address block. To conserve IPv4 address space on high-density core transit links, IETF RFC 3021 defined the use of /31 prefixes (2 total addresses):

Prefix: 192.0.2.0/31
Host 0: 192.0.2.0 (Assigned to Router Interface A)
Host 1: 192.0.2.1 (Assigned to Router Interface B)
Subnet Mask: 255.255.255.254
Broadcast Address: Directed broadcasts are disabled on point-to-point links.

2. Single Host Routes (/32 Prefix)

A /32 prefix designates a subnet mask of 255.255.255.255 where all 32 bits represent the network portion, leaving zero host bits. A /32 route points explicitly to a single, unique IPv4 interface. Common applications include:

  • Router Loopback Interfaces: Stable virtual interfaces used as router IDs in OSPF and BGP peering sessions.
  • Host Specific Routing Entries: Directing traffic to an individual VPN client or tunnel endpoint.
  • Firewall Ingress Targets: Restricting SSH (Port 22) or Database (Port 5432) access to a single static corporate management workstation.

3. Loopback & Special Use Address Blocks

RFC 6890 catalogued several reserved IPv4 address blocks that must never be routed across public internet transits:

  • Loopback Segment (127.0.0.0/8): Used exclusively by the local operating system kernel for internal IPC (Inter-Process Communication) and localhost development (127.0.0.1).
  • Link-Local / APIPA (169.254.0.0/16 / RFC 3927): Automatically configured when DHCP discovery fails on local ethernet segments. Hyperscalers also utilise 169.254.169.254/32 for cloud instance metadata endpoints.
  • Documentation Prefixes (TEST-NET-1, 2, 3 / RFC 5737): 192.0.2.0/24, 198.51.100.0/24, and 203.0.113.0/24 reserved specifically for documentation and technical publications.

Exporting IP Lists for Firewall Allowlists (pfSense, Cisco ACLs, and AWS Security Groups)

Network security engineers frequently need to transform CIDR blocks into explicit IP ranges or discrete host lists for firewall rule enforcement and security automation:

1. pfSense / OPNsense Alias Tables

Open-source firewalls like pfSense and OPNsense allow administrators to manage inbound and outbound filtering rules via Firewall Aliases. By extracting clean, newline-separated IP lists from an online CIDR and subnet extractor, administrators can populate URL Table Aliases or direct Host Aliases to permit trusted partner subnets without manually typing dozens of octets.

2. Cisco IOS Access Control Lists (ACLs)

Cisco hardware routers and ASA security appliances require wildcard mask notation for extended access lists rather than standard subnet masks:

! Permitting a /27 subnet (32 addresses) from 10.20.5.64 to 10.20.5.95
access-list 101 permit ip 10.20.5.64 0.0.0.31 any

! Permitting a single host (/32)
access-list 101 permit tcp host 198.51.100.14 any eq 443

3. AWS Security Groups and Network ACLs (NACLs)

AWS Security Groups are stateful firewalls applied at the Elastic Network Interface (ENI) level, whereas NACLs are stateless firewalls evaluated at the subnet boundary. AWS Security Groups accept CIDR notation directly (e.g., 203.0.113.50/32 for a single admin workstation or 10.0.2.0/24 for an application tier). When creating complex multi-IP allowlists, generating structured JSON arrays ensures clean CI/CD infrastructure-as-code automation via Terraform or AWS CloudFormation.

For organisations reviewing historic firewall logs or troubleshooting access denials, learning how to extract IPs and fields from log files provides the necessary verification bridge between firewall policies and actual network traffic patterns.

Privacy & Security: Why Proprietary Corporate Network Topologies and VPC Ranges Must Remain 100% Client-Side

Corporate IP addressing schemes, internal subnet layouts, and VPC topologies constitute confidential network architecture intelligence. Exposing internal IP maps creates severe reconnaissance advantages for malicious actors:

  • Vulnerability to Internal Reconnaissance: If an external adversary obtains an enterprise’s internal CIDR topology, they can infer high-value targets (such as dedicated database subnets, domain controller pools, and payment processing segments) without performing noisy network port scans.
  • Risk of Cloud Server Interception: Submitting corporate network schemes to server-side online calculators sends IP ranges over external HTTP APIs, exposing them to third-party web server logging, intermediate proxy inspection, and database storage.
  • Compliance & Data Governance Violations: Enterprise security standards (including ISO 27001, SOC 2 Type II, and PCI-DSS) strictly mandate that internal infrastructure topologies and host mapping schemes be shielded from unauthorized external exposure.

The online CIDR and subnet extractor operates with a 100% private, client-side execution architecture. All bitwise calculations, binary shifting, subnet boundary logic, and host list generations execute locally within your browser’s V8 JavaScript engine. No IP addresses, CIDR strings, or network parameters are ever transmitted to external servers, ensuring complete compliance with stringent corporate cybersecurity policies.

Frequently Asked Questions

What is CIDR notation and how does it work?

CIDR (Classless Inter-Domain Routing) notation represents an IP address and its associated routing prefix length separated by a slash (e.g., 192.168.1.0/24). The number following the slash indicates how many leading bits are dedicated to the network prefix, with the remaining bits allocated for individual host addresses.

How many usable host IP addresses are in a /24 subnet?

A standard /24 subnet contains 256 total IP addresses and 254 usable host addresses. The first address (.0) is reserved as the network identifier, while the last address (.255) is reserved as the broadcast address.

Why does AWS reserve 5 IP addresses in every VPC subnet?

AWS reserves 5 IP addresses per subnet for internal cloud management: the network address (first IP), the default VPC router (second IP), the Amazon DNS resolver (third IP), an address reserved for future capability (fourth IP), and the network broadcast address (last IP).

What is the difference between a subnet mask and a wildcard mask?

A subnet mask uses binary 1s to identify network bits and binary 0s for host bits (e.g., 255.255.255.0). A wildcard mask is the exact bitwise inverse, using 0s for matching network bits and 1s for wildcard host bits (e.g., 0.0.0.255), commonly used in Cisco access control lists.

What is an RFC 3021 /31 subnet and where is it used?

An RFC 3021 /31 subnet allocates exactly 2 IP addresses without dedicated network or broadcast addresses. It is used exclusively on point-to-point router links to eliminate the 50% IP address waste inherent in traditional /30 configurations.

How do I calculate the network address from an IP and CIDR prefix?

To calculate the network address, convert both the IP address and the subnet mask to 32-bit binary strings and perform a bitwise logical AND operation between them. The resulting binary string converted back into dotted-decimal notation is the network address.

Is it safe to calculate proprietary corporate subnets using online tools?

It is only safe if the tool operates 100% client-side. EasyExtract calculates all CIDR boundaries and IP address lists directly inside your web browser’s local JavaScript engine, ensuring zero data transmission to external servers.

Explore related private, browser-based extraction and networking utilities from EasyExtract:

Sources & References

This technical guide references official networking standards, RFC specifications, and cloud documentation:

  • IETF RFC 4632: Classless Inter-domain Routing (CIDR): The Internet Address Assignment and Aggregation Plan. Internet Engineering Task Force.
  • IETF RFC 1918: Address Allocation for Private Internets (Best Current Practice). Internet Engineering Task Force.
  • IETF RFC 3021: Using 31-Bit Prefixes on IPv4 Point-to-Point Links. Internet Engineering Task Force.
  • IETF RFC 6890: Special-Purpose IP Address Registries. Internet Engineering Task Force.
  • AWS VPC Subnet Sizing Documentation: Amazon Web Services official VPC and Subnet sizing and reserved IP architecture guide.

About Md Rejon M

"Md Rejon M. is a premier Data Architecture Specialist and the visionary Lead Engineer behind EasyExtract. With over a decade of hands-on expertise in automation, web scraping, and document parsing, Rejon has dedicated his career to making data extraction fast, accessible, and secure. He designed EasyExtract’s unique serverless infrastructure, ensuring that all tools run 100% locally as client-side JavaScript within the user's browser. By engineering a framework where confidential contracts, client lists, and documents never touch an external server, Rejon has set a new standard for private-by-design utility tools. His deep knowledge of regular expressions, PDF structural layout parsing, and file archive decoding ensures the platform delivers pristine, deduplicated data without compromising user privacy.

Keep reading