32-bit CIDR network map
IPv4 Subnet and CIDR Range Calculator
Turn an IPv4 address and prefix length into its canonical CIDR range, network, subnet mask, wildcard mask, broadcast address, address span, and conventional host range. A binary audit shows exactly where the leftmost network bits stop and host bits begin.
Enter address and CIDR prefix
Subnet and CIDR range map
Bit boundary audit
Address: 11000000.10101000.00001010.00100010 Mask: 11111111.11111111.11111111.11100000 Network: 11000000.10101000.00001010.00100000 Host bits: 5; block size: 32 addresses
For /27, the all-zero host value identifies the network and the all-one host value is the directed broadcast address.
What an IPv4 prefix means
An IPv4 address contains 32 bits, usually written as four decimal octets. A CIDR prefix length tells how many contiguous bits from the left identify the network. The remaining 32 minus prefix bits form the host field. Thus /27 means 27 network bits and 5 host bits.
Every address sharing those 27 leading bits belongs to the same mathematical prefix. The first value is obtained by setting all host bits to zero; the last is obtained by setting all host bits to one. In a conventional multi-access IPv4 subnet through /30, those endpoints serve as network and directed-broadcast addresses, leaving the values between them for host assignments.
CIDR is classless. The historical Class A, B, and C boundaries do not control a /27, /20, or any other modern prefix. The address’s first octet does not choose the mask. The explicit prefix is the authoritative boundary.
The subnet calculation in four moves
1. Validate four octets
Each decimal component must be an integer from 0 through 255. Leading or trailing text is rejected.
2. Build the mask
Set the leftmost prefix bits to one and the remaining host bits to zero. Convert each group of eight back to decimal.
3. Align the block
The block contains 2^(32−prefix) addresses. Floor the entered address to the nearest multiple of that block size.
4. Assign endpoint roles
Add block size minus one for the last address, then apply conventional broadcast or /31 point-to-point rules.
Worked example: 192.168.10.34/27
A /27 leaves 5 host bits, so its block size is 2⁵ = 32 addresses. In the last octet, /27 blocks begin at 0, 32, 64, 96, 128, 160, 192, and 224. The entered last octet 34 falls in the 32-through-63 block.
The network is therefore 192.168.10.32 and the directed broadcast is 192.168.10.63. The mask is 255.255.255.224 because the last mask octet is binary 11100000. Its bitwise complement, the wildcard mask, is 0.0.0.31.
Under conventional host roles, 192.168.10.33 is the first host and 192.168.10.62 is the last. Thirty of the 32 addresses are conventionally assignable. Whether an address should actually be assigned also depends on DHCP pools, gateway choices, reservations, duplicate detection, network policy, and device configuration.
Special prefixes /31 and /32
/31 point-to-point
RFC 3021 permits both addresses of a /31 on a point-to-point link, where directed broadcast is unnecessary and endpoint semantics are known. The calculator’s default /31 convention reports both values as endpoints.
Legacy /31 interpretation
Older host-count rules subtract network and broadcast from every subnet and yield zero conventional hosts for /31. Select the legacy option only when documenting that convention; it does not override device and protocol support.
/32 host route
A /32 identifies exactly one IPv4 address. It is commonly used as a host route, loopback route, or exact match. There is no address range beyond that single value.
Subnet arithmetic does not configure a network
The calculator identifies numerical ranges. It does not know a router interface, VRF, VLAN, access-control list, DHCP reservation, NAT rule, cloud-provider reservation, virtual IP, multicast scope, or routing policy. Some platforms reserve additional addresses within a subnet beyond network and broadcast.
Overlapping prefixes can cause ambiguous routing or deployment failure even when each individual calculation is correct. Before assignment, compare the new prefix with every routed, connected, VPN, container, cloud, and management range that can interact with it.
Private address space is not automatically secure. RFC 1918 ranges still require routing, filtering, authentication, segmentation, monitoring, and correct NAT policy. Public addresses require allocation authority. Do not select an apparently unused public block from a calculator output.
Subnet mask versus wildcard mask
The subnet mask has ones in network positions and zeros in host positions. The wildcard mask shown here is its 32-bit complement: zeros where the subnet mask has ones, and ones where it has zeros. For /27, 255.255.255.224 complements to 0.0.0.31.
Wildcard masks are used in some access-control and routing syntaxes, but vendor semantics can vary. A wildcard may mean “ignore these bit positions,” not a standalone subnet mask. Read the command documentation rather than pasting the value into an unfamiliar field.
Contiguous CIDR masks are the scope of this calculator. Noncontiguous masks and arbitrary wildcard match patterns can describe sets that are not one CIDR prefix. The prefix input intentionally prevents such patterns.
Planning address capacity
Total mathematical address count doubles whenever the prefix becomes one bit shorter. A /24 has 256 addresses, /25 has 128, /26 has 64, and /27 has 32. Conventional usable counts through /30 subtract two, but platform-specific reservations can reduce deployable capacity further.
Capacity planning should include gateways, high availability, static infrastructure, DHCP exclusions, growth, temporary devices, monitoring, and operational margin. Avoid creating a subnet that is exactly full on launch. Conversely, needlessly large broadcast domains can increase operational scope and reduce address-plan clarity.
Summarization works when adjacent equal-size prefixes align on the correct boundary. Two /27 prefixes can form a /26 only if their combined 64-address range begins at a /26 boundary. Similar-looking strings are not enough; compare the binary prefix.
Manual verification checklist
Convert the mask’s octets to binary and count contiguous one bits. Confirm that the remaining zero count equals host bits. Add one to the numerical difference between broadcast and network to recover total addresses. For ordinary /0 through /30, first host should equal network plus one and last host broadcast minus one.
Verify that the entered address lies between the calculated first and last mathematical addresses, inclusive. ANDing the address with the mask should reproduce the network. ORing the network with the wildcard should reproduce the last address. These are strong arithmetic checks but do not prove the deployment is authorized or conflict-free.
Record prefixes in address/prefix notation, not as an isolated mask. “192.168.10.32/27” communicates the block; “255.255.255.224” alone does not identify which block.
Build an auditable IPv4 address plan
Give every allocation a canonical network/prefix, purpose, routing domain, VLAN or segment, location, owner, gateway convention, DHCP range, static-reservation range, and lifecycle status. Record platform-reserved addresses separately from the mathematical network and broadcast endpoints. An address management system should be the source of truth; a spreadsheet or calculator output is only useful when it is reconciled with actual routing and assignments.
Allocate on valid binary boundaries. If four consecutive /27 segments are needed, their network last octets may begin at 0, 32, 64, and 96 inside the same /24. Do not choose a visually convenient number such as 40 as a /27 network; the calculator will align an address within that span down to 32. Labeling the canonical result prevents hosts from being documented under an impossible prefix boundary.
Reserve growth space intentionally. Adjacent free blocks can allow a segment to expand or several routes to aggregate later. Scattered allocations force more-specific routes and make security review harder. However, do not advertise a summary until every address inside it is routed consistently; an aggregate can attract traffic for unassigned or differently owned subprefixes.
Overlaps, containment, and route choice
Two prefixes overlap when their numeric spans intersect. If one network address falls inside the other prefix, the ranges are either identical or one contains part of the other. A more-specific prefix has a larger slash number. For example, 192.168.10.32/27 is contained within 192.168.10.0/24.
Routers ordinarily choose the longest matching prefix, so a /27 route can override a covering /24 for its 32 addresses. That behavior is useful for controlled routing but dangerous when an unintended overlap diverts only part of a range. VPN clients, container platforms, home networks, and cloud virtual networks frequently collide in private IPv4 space.
Before deployment, compare the calculated first and last addresses against connected routes, static routes, dynamic routing advertisements, firewall objects, NAT pools, DHCP scopes, load balancers, remote-access pools, and disaster-recovery ranges. Check every operating environment, not only the local subnet. Document intentional containment and reject accidental partial overlap.
Reverse DNS and operational records
IPv4 reverse DNS uses names under in-addr.arpa and delegates naturally on octet boundaries. A /24 aligns cleanly with one reversed octet, while smaller or larger non-octet prefixes may require classless delegation techniques and coordinated CNAME records. Subnet arithmetic alone does not create reverse DNS.
Update forward and reverse DNS, IP address management, DHCP, monitoring, access controls, route filters, diagrams, and asset inventories as one change set. Test the intended network, gateway, and broadcast interpretation on the actual platform. Save pre-change routes and a rollback plan. Good address math is most valuable when the operational records agree with it.
Frequently asked questions
How many addresses are in a /24?
A /24 leaves eight host bits, so it contains 2⁸ = 256 addresses. Conventional multi-access host count is 254 before platform-specific reservations.
Is the first address always unusable?
It is the network identifier in conventional multi-access subnets, but a /32 is an exact address and /31 point-to-point links use special endpoint semantics.
Why is /31 selectable?
RFC 3021 defines use of 31-bit prefixes on point-to-point links to conserve addresses. Both addresses can identify endpoints when supported and appropriate.
Does a wildcard mask replace a subnet mask?
No. It is the complement used by particular matching syntaxes. Follow the device or application documentation for the expected field.
Can I enter 192.168.1.1/24 in one field?
This interface separates address and prefix. Enter 192.168.1.1 in the address field and 24 in the prefix field.
Does the calculator detect overlap with my network?
No. It maps one prefix. Compare its numerical span with every existing prefix in the relevant routing and security domains.
Related calculator
IPv4 host-count habits should not be carried into IPv6 unchanged.
References
The prefix model follows IETF RFC 4632, Classless Inter-domain Routing. The optional two-endpoint interpretation follows IETF RFC 3021, Using 31-Bit Prefixes on IPv4 Point-to-Point Links. Device support and operational policy still govern deployment.