How to find the IP range of a subnet from CIDR notation

How to find the IP range of a subnet from CIDR notation

A block such as 192.168.0.0/22 hides its first address, its last address, and how many devices fit in it. Read the range from the prefix, check the usable hosts, then write the addresses in the form your firewall or database wants.

find the ip range of a subnet

What goes wrong when the range is guessed

CIDR notation writes a network as an address and a prefix length. An IPv4 address is 32 bits, and the prefix says how many of those bits, counted from the left, name the network. The rest number the hosts. So 192.168.1.0/24 covers 192.168.1.0 to 192.168.1.255, which is 256 addresses. Change the prefix by one and the size doubles or halves.

Guessing the range causes real mistakes. A firewall rule that ends one address too early locks out a server. An allow list that starts in the middle of a block lets in addresses you did not mean to allow. Counting every address as a device is another trap: in a normal subnet the first address is the network address and the last is the broadcast address, and neither can be given to a device. A /24 has 256 addresses but 254 usable hosts.

A range that does not line up with a power of 2 is a third problem. A CIDR block always has a size that is a power of 2 and starts on a matching boundary. A range like 10.0.0.0 to 10.0.0.5, six addresses, cannot be one block. It needs a block of 4 and a block of 2.

Read the range, check the hosts, convert the format

Start with CIDR to IP Range. On the CIDR to range tab, enter a block such as 192.168.0.0/22 and press Calculate. It returns 192.168.0.0 to 192.168.3.255, 1,024 addresses. Tick List every address to get them one per line, and copy the result or download it as a .txt file for a firewall rule. The list stops at 65,536 entries, but the count is always shown in full. The Range to CIDR tab works the other way: enter a start and an end address of the same IP version, and it returns the fewest blocks that cover them. 10.0.0.0 to 10.0.0.5 becomes 10.0.0.0/30 and 10.0.0.4/31. If you type an address that is not the start of its block, such as 10.0.0.5/30, it shows the range of the block that contains it, with a note.

When you need the network, broadcast, and host count, use the IPv4 Subnet Calculator. Enter an IP address and a mask as a prefix (/26), a netmask (255.255.255.192), or a wildcard mask (0.0.0.63). For 192.168.1.130/26 it gives network 192.168.1.128, broadcast 192.168.1.191, hosts 192.168.1.129 to 192.168.1.190, and 62 usable hosts. A /31 has 2 usable addresses and no broadcast, for point-to-point links, and a /32 is a single host. Split into smaller subnets divides a block by a count or a prefix: 192.168.1.0/24 split in 4 gives four /26 networks with 62 hosts each. A mask whose one-bits are not all on the left, such as 255.0.255.0, is rejected, and so is an octet with a leading zero.

Some tools want the address as a number. The IP Address Converter reads an IPv4 address in dotted decimal, as one integer, in hex, in binary, or as an IPv4-mapped IPv6 address, and fills in every other form. 192.168.1.1 is 3232235777 and 0xC0A80101. Storing the integer takes 4 bytes instead of up to 15 characters, and a range check becomes a simple comparison between the first and last address. A single integer must be between 0 and 4,294,967,295.

Turn a CIDR block into a usable address range

  1. Enter the block, for example 192.168.0.0/22, on the CIDR to range tab and note the first address, the last address, and the count.
  2. If you started from two addresses instead of a block, use the Range to CIDR tab to get the fewest blocks that cover them.
  3. Enter the same block in the IPv4 Subnet Calculator to see the network address, the broadcast address, and the usable host range.
  4. Give devices addresses from the usable host range only. Leave the network and broadcast addresses out, except on a /31 or /32.
  5. If a database or a log needs numbers, convert the first and last address in the IP Address Converter and compare against those two integers.

What these three tools do not handle

  • The address list stops at 65,536 entries, and the subnet split table lists up to 1,024 subnets. The counts are exact.
  • Both ends of a range must be the same IP version. Mixed IPv4 and IPv6 ranges are rejected.
  • The subnet calculator is for IPv4 only. Its class label is for reference, since routing has used CIDR since 1993.
  • The converter accepts IPv6 only as an IPv4-mapped address. Dotted input with leading zeros is read as octal only when every octet starts with 0.

Frequently asked questions

What does /24 mean in 192.168.1.0/24?

The first 24 bits are the network part, so the block covers 192.168.1.0 to 192.168.1.255, which is 256 addresses.

How many usable hosts are in a /24?

254. A /24 has 256 addresses, and two are reserved: the network address (.0) and the broadcast address (.255).

Why does one IP range need several CIDR blocks?

A CIDR block always has a power-of-2 size and starts on a matching boundary. 10.0.0.0 to 10.0.0.5 is 6 addresses, so it needs a block of 4 and a block of 2.

How do I convert an IP address to a decimal number?

Multiply the first octet by 16,777,216, the second by 65,536, the third by 256, and add the fourth. 192.168.1.1 gives 3,232,235,777.

Tools used in this guide

More from the blog

All guides