What Is a Subnet Mask? A Complete Guide to Subnetting

Last Updated: October 2026

Key Takeaways

  • A subnet mask separates the network portion of an IP address from the host portion.
  • CIDR notation (e.g., /24) indicates how many bits are used for the network — the rest are for hosts.
  • The most common subnet mask is 255.255.255.0 (/24), providing 254 usable host addresses.
  • Usable hosts = 2host bits − 2 (subtract the network and broadcast addresses).
  • Subnetting improves security, reduces broadcast traffic, and maximizes IP address efficiency.
  • Use our Subnet Calculator to compute subnets instantly.

If you have ever configured a network device, you have encountered a subnet mask — that mysterious number like 255.255.255.0 that appears alongside every IP address configuration. While it may look confusing at first glance, the subnet mask is one of the most important concepts in networking. It determines which devices can communicate directly with each other on a local network and which traffic must be routed through a gateway.

In this guide, we will explain what a subnet mask is, how subnetting works at the binary level, how to read CIDR notation, how to calculate subnets, and how subnetting is applied in real-world networks — from home setups to enterprise data centers.

What Is a Subnet Mask?

A subnet mask is a 32-bit number that divides an IP address into two parts:

  • Network portion — identifies which network the device belongs to.
  • Host portion — identifies the specific device within that network.

The subnet mask works by performing a bitwise AND operation between itself and an IP address. The result is the network address — the identifier for the entire network segment. All devices with the same network address are on the same subnet and can communicate directly without a router.

For example, with the IP address 192.168.1.100 and the subnet mask 255.255.255.0:

  • The network portion is 192.168.1 (the first three octets, covered by 255s).
  • The host portion is .100 (the last octet, covered by 0).
  • The network address is 192.168.1.0.
  • Any device with an IP in the range 192.168.1.1 – 192.168.1.254 is on the same subnet.

How Subnetting Works: The Binary Explanation

To truly understand subnetting, you need to see it at the binary level. Every IP address and subnet mask is a 32-bit binary number. The subnet mask consists of a contiguous block of 1-bits followed by a contiguous block of 0-bits. The 1-bits mask the network portion; the 0-bits reveal the host portion.

Binary AND Operation

Let's walk through the binary AND for the IP 192.168.1.100 with mask 255.255.255.0:

  • IP address: 11000000.10101000.00000001.01100100
  • Subnet mask: 11111111.11111111.11111111.00000000
  • AND result: 11000000.10101000.00000001.00000000 = 192.168.1.0 (network address)

The broadcast address is calculated by setting all host bits to 1: 11000000.10101000.00000001.11111111 = 192.168.1.255. This address is used to send data to all devices on the subnet simultaneously.

Network Address and Broadcast Address

Every subnet reserves two addresses that cannot be assigned to devices:

  • Network address (first address) — all host bits are 0. Identifies the network itself.
  • Broadcast address (last address) — all host bits are 1. Used for network-wide broadcasts.

This is why the formula for usable host addresses is 2host bits − 2.

CIDR Notation Explained

CIDR (Classless Inter-Domain Routing) notation is a compact way to express a subnet mask. Instead of writing out the full dotted-decimal mask, you append a slash and the number of network bits to the IP address. For example:

  • 192.168.1.0/24 means the first 24 bits are the network portion (mask: 255.255.255.0).
  • 10.0.0.0/8 means the first 8 bits are the network portion (mask: 255.0.0.0).
  • 172.16.0.0/12 means the first 12 bits are the network portion (mask: 255.240.0.0).

CIDR notation replaced the older classful addressing system (Class A, B, C) and allows much more flexible allocation of IP address space.

Common Subnet Masks Reference Table

The following table lists commonly used subnet masks with their CIDR prefix, dotted-decimal notation, number of total addresses, and usable host addresses:

CIDRSubnet MaskTotal AddressesUsable HostsTypical Use
/8255.0.0.016,777,21616,777,214Large enterprise / ISP
/12255.240.0.01,048,5761,048,574Private range (172.16/12)
/16255.255.0.065,53665,534Large campus network
/20255.255.240.04,0964,094Cloud VPC subnet
/24255.255.255.0256254Home / small office (most common)
/25255.255.255.128128126Small department
/26255.255.255.1926462Small workgroup
/27255.255.255.2243230Small team / VLAN
/28255.255.255.2401614Server group / DMZ
/30255.255.255.25242Point-to-point link
/32255.255.255.25511Single host route

Why Subnetting Matters

Subnetting is not just an academic exercise — it has critical practical benefits for any network, from a home setup to a global enterprise.

Network Segmentation and Security

Subnetting divides a large network into smaller, isolated segments. This is essential for security: if an attacker compromises a device on one subnet, they cannot directly access devices on other subnets without passing through a router or firewall. For example, a typical office might place employee workstations, servers, guest Wi-Fi, and IoT devices on separate subnets, each with its own access control rules.

Reduced Broadcast Traffic

In an IP network, broadcast packets (like ARP requests and DHCP discovers) are sent to every device on the subnet. On a large, flat network with thousands of devices, broadcast traffic can consume significant bandwidth and processing power. Subnetting creates smaller broadcast domains, keeping broadcast traffic contained within each segment and improving overall network performance.

Efficient IP Address Allocation

Without subnetting, you would have to allocate entire classful networks (/8, /16, or /24) even if you only need a few addresses. Subnetting lets you create appropriately sized networks: a /30 for a point-to-point link (2 hosts), a /28 for a small server group (14 hosts), or a /24 for a department (254 hosts). This prevents wasting valuable IP address space.

How to Calculate Subnets

You can calculate subnet details manually using binary math, or use our Subnet Calculator for instant results. Here is the manual process:

Step 1: Determine the Network Address

Perform a bitwise AND between the IP address and the subnet mask. The result is the network address. For example, for 10.20.30.40/20:

  • Mask /20 = 255.255.240.0
  • IP in binary: 00001010.00010100.00011110.00101000
  • Mask in binary: 11111111.11111111.11110000.00000000
  • AND result: 00001010.00010100.00010000.00000000 = 10.20.16.0

Step 2: Determine the Broadcast Address

Set all host bits (the 0-bits in the mask) to 1 in the network address:

  • Network: 00001010.00010100.00010000.00000000
  • Broadcast: 00001010.00010100.00011111.11111111 = 10.20.31.255

Step 3: Determine the Usable Host Range

  • First usable host: Network address + 1 = 10.20.16.1
  • Last usable host: Broadcast address − 1 = 10.20.31.254
  • Total usable hosts: 212 − 2 = 4,094

VLSM (Variable Length Subnet Masking)

In traditional subnetting, all subnets within a network use the same mask size. VLSM allows you to use different mask lengths for different subnets within the same address space, allocating addresses much more efficiently.

VLSM Example

Suppose you have the network 192.168.10.0/24 and need to create subnets for:

  • Engineering department: 50 hosts
  • Sales department: 25 hosts
  • Management: 10 hosts
  • Two point-to-point router links: 2 hosts each

With VLSM, you allocate from largest to smallest:

  1. Engineering: 50 hosts → need 6 host bits (26 = 64) → 192.168.10.0/26 (62 usable, range .1–.62)
  2. Sales: 25 hosts → need 5 host bits (25 = 32) → 192.168.10.64/27 (30 usable, range .65–.94)
  3. Management: 10 hosts → need 4 host bits (24 = 16) → 192.168.10.96/28 (14 usable, range .97–.110)
  4. Router link 1: 2 hosts → need 2 host bits → 192.168.10.112/30 (2 usable, range .113–.114)
  5. Router link 2: 2 hosts → 192.168.10.116/30 (2 usable, range .117–.118)

Without VLSM, you would need to use the same mask for all subnets, wasting far more addresses.

Private IP Ranges and Their Default Masks

The three RFC 1918 private IP ranges are commonly associated with specific default subnet masks, though they can be subnetted to any size:

10.0.0.0/8 (Class A private range)
Default mask: 255.0.0.0. Provides ~16.7 million addresses. Used in large enterprises where extensive subnetting is needed. Many organizations subnet this into /16s or /24s for individual departments or sites.
172.16.0.0/12 (Class B private range)
Default mask: 255.240.0.0. Provides ~1 million addresses across 172.16.0.0 – 172.31.255.255. Often subnetted into /24s for medium-sized organizations.
192.168.0.0/16 (Class C private range)
Default mask: 255.255.0.0. Provides ~65,000 addresses across 192.168.0.0 – 192.168.255.255. Most commonly used in home and small office networks, where each network uses a /24 (e.g., 192.168.1.0/24).

Supernetting and CIDR Aggregation

Supernetting (also called CIDR aggregation or route summarization) is the opposite of subnetting. Instead of dividing a network into smaller pieces, it combines multiple contiguous networks into a single, larger network. This reduces the number of entries in routing tables, improving router performance and scalability.

How Supernetting Works

To aggregate routes, you find the common prefix among contiguous networks. For example:

  • 192.168.0.0/24
  • 192.168.1.0/24
  • 192.168.2.0/24
  • 192.168.3.0/24

These four /24 networks share the first 22 bits in common, so they can be summarized as a single 192.168.0.0/22 route. The router only needs one routing entry instead of four, and any traffic destined for addresses in the range 192.168.0.0 – 192.168.3.255 follows the same path.

Supernetting is critical for ISPs and large organizations. Without route aggregation, the global internet routing table would be orders of magnitude larger, making routing impractical.

Practical Subnetting Examples

Home Network

A typical home network uses 192.168.1.0/24. The router is at 192.168.1.1 (the default gateway), and DHCP assigns addresses from 192.168.1.2 through 192.168.1.254 to devices. With 254 usable addresses, this is more than enough for phones, laptops, smart TVs, and IoT devices. The subnet mask 255.255.255.0 means all devices see each other directly without routing.

Small Office Network

A small office with 40 employees might use 10.10.0.0/24 for workstations, 10.10.1.0/24 for servers, and 10.10.2.0/24 for guest Wi-Fi. A firewall between subnets controls access — guests can reach the internet but not internal servers. Each /24 provides 254 addresses, offering room for growth.

Data Center

Data centers use complex subnetting schemes. A cloud provider might allocate a /16 (65,534 hosts) per availability zone, then subnet into /20s for customer VPCs, /24s for individual subnets within VPCs, and /32s for individual container or VM addresses. VLSM is essential here to avoid wasting addresses across thousands of customers with varying needs.

Point-to-Point Links

Router-to-router connections (point-to-point links) only need two usable IP addresses — one for each end. A /30 subnet is traditionally used (4 addresses total, 2 usable). In modern networks, /31 subnets are also used (RFC 3021), which provides exactly 2 addresses by eliminating the network and broadcast addresses entirely.

Frequently Asked Questions

What is a subnet mask in simple terms?

A subnet mask is a number that tells a device which part of an IP address identifies the network and which part identifies the specific device. Think of it like an area code in a phone number — the subnet mask separates the "area code" (network) from the "local number" (host).

What does /24 mean in CIDR notation?

/24 means the first 24 bits of the IP address are the network portion. This equals a subnet mask of 255.255.255.0 and provides 256 total addresses (254 usable for devices). It is the most common subnet size for small networks.

What is the most common subnet mask?

255.255.255.0 (/24) is by far the most common. It is the default for home routers and small office networks, providing 254 usable host addresses — enough for most small to medium environments.

How do I calculate the number of hosts in a subnet?

Use the formula: 2(32 − prefix length) − 2. Subtract 2 for the network and broadcast addresses. For example: /24 = 28 − 2 = 254 hosts. /25 = 27 − 2 = 126 hosts. /30 = 22 − 2 = 2 hosts.

What is the difference between a network address and a broadcast address?

The network address is the first address in a subnet (all host bits set to 0) — it identifies the network itself. The broadcast address is the last address (all host bits set to 1) — it is used to send data to all devices on the subnet. Neither can be assigned to a device.

What is VLSM?

VLSM (Variable Length Subnet Masking) allows different subnets within the same network to use different prefix lengths. This lets you right-size each subnet — a /24 for a large group, a /28 for a small team, a /30 for a router link — dramatically reducing wasted addresses.

Why is subnetting important?

Subnetting provides three key benefits: security (isolates network segments so breaches are contained), performance (smaller broadcast domains mean less noise), and efficiency (right-sized subnets waste fewer IP addresses).

What is supernetting or CIDR aggregation?

Supernetting combines multiple smaller networks into one larger network for routing purposes. For example, four /24 networks can be aggregated into one /22, reducing the number of routing table entries. This is essential for internet scalability.