4 · IPv4, CIDR and subnetting Network
Prefix math you can do in your head · network, broadcast, usable range · /31, /32 · longest-prefix match
Why it matters for NPE. Subnetting shows up in nearly every network screen. You must answer /26 and /28 questions without a calculator and explain why a router picks the most specific route.
Primer: a prefix is just "how many bits are fixed"
An IPv4 address is 32 bits. /24 means the first 24 bits name the network and the last 8 bits name the host, so there are 28 = 256 addresses in the block. /26 fixes 26 bits, leaving 6 host bits: 64 addresses. Everything else (mask, network ID, broadcast, usable range, "next network") falls out of the block size.
Watch
The cheat-sheet method (powers of two over the CIDR row). Watch Part 1 (8:37) and Part 2 (1:58) first; the three together are the real lesson. 0:44 example 10.1.1.55/28, 3:21 example 10.1.1.27/29.
Four worked problems. Parts 6 and 7 (/17-/24 range, /1-/16 range) cover prefixes shorter than /24.
Watch 9:19-22:27 for CIDR, usable addresses and the /31 (17:46) and /32 (20:12) edge cases interviewers probe.
11:54 route specificity (longest-prefix match). 1:56 ECMP, 4:35 metric, 8:10 administrative distance are reused in topic 12.
Drill generator: subnetipv4.com. Time yourself; stop when ten in a row take under 20 seconds each.
The mask table (write it from memory once a day until it sticks)
| Prefix | Mask (last interesting octet) | Block size | Addresses | Usable hosts | Typical use |
|---|---|---|---|---|---|
| /24 | 255.255.255.0 | 256 (whole octet) | 256 | 254 | a classic LAN |
| /25 | 255.255.255.128 | 128 | 128 | 126 | |
| /26 | 255.255.255.192 | 64 | 64 | 62 | a rack |
| /27 | 255.255.255.224 | 32 | 32 | 30 | |
| /28 | 255.255.255.240 | 16 | 16 | 14 | a small management net |
| /29 | 255.255.255.248 | 8 | 8 | 6 | |
| /30 | 255.255.255.252 | 4 | 4 | 2 | point-to-point link (old style) |
| /31 | 255.255.255.254 | 2 | 2 | 2 (RFC 3021, no broadcast) | point-to-point link (modern, used in fabrics) |
| /32 | 255.255.255.255 | 1 | 1 | 1 | loopback / host route |
| /16 | 255.255.0.0 | 256 in the 3rd octet | 65,536 | 65,534 | a site or a pod summary |
| /22 | 255.255.252.0 | 4 in the 3rd octet | 1,024 | 1,022 | |
| /20 | 255.255.240.0 | 16 in the 3rd octet | 4,096 | 4,094 |
The mask octet values are always from the set 0, 128, 192, 224, 240, 248, 252, 254, 255 (each adds the next bit). Mask octet = 256 − block size.
The 20-second method
Question: 192.0.2.130/26. Network? Broadcast? Usable range?
- Block size: 32 − 26 = 6 host bits → 64.
- Which multiple of 64 is at or below 130? 0, 64, 128, 192. So the network ID is 192.0.2.128.
- Next network is 192.0.2.192, so the broadcast is one less: 192.0.2.191.
- Usable hosts: .129 to .190 (62 of them).
When the prefix is shorter than /24 the "interesting octet" moves left. 10.37.200.5/20: 32 − 20 = 12 host bits, so the block is 16 in the third octet. Multiples of 16 at or below 200: 192. Network 10.37.192.0, broadcast 10.37.207.255, hosts 10.37.192.1 to 10.37.207.254.
Drills (do them cold, then check)
1. 172.16.5.77/27
Block 32. Multiple ≤ 77: 64. Network 172.16.5.64, broadcast .95, hosts .65 to .94.2. 10.0.0.200/28
Block 16. 192 ≤ 200. Network 10.0.0.192, broadcast .207, hosts .193 to .206.3. 192.168.1.1/30
Block 4. Network 192.168.1.0, broadcast .3, hosts .1 and .2. Classic point-to-point link; the other end is .2.4. 192.168.1.1/31
Block 2. Network 192.168.1.0; both .0 and .1 are usable, there is no broadcast on a /31. The other end is .0.5. 10.200.14.9/22
Block 4 in the third octet. 12 ≤ 14. Network 10.200.12.0, broadcast 10.200.15.255, hosts 10.200.12.1 to 10.200.15.254.6. Are 10.1.1.10/24 and 10.1.2.10/24 on the same subnet? What about with /23?
With /24 no: networks 10.1.1.0 and 10.1.2.0. With /23 the block is 2 in the third octet: 10.1.1.10 is in 10.1.0.0/23 (third octet 0-1) and 10.1.2.10 is in 10.1.2.0/23 (2-3). Still different. With /22 (block 4, octets 0-3) they are the same subnet.7. You need 50 hosts per subnet. Smallest prefix?
Need 52 addresses incl. network and broadcast → block 64 → /26.8. Split 10.10.0.0/24 into four equal subnets.
Two more bits: /26. 10.10.0.0/26, .64/26, .128/26, .192/26.9. Summarise 10.4.0.0/24 through 10.4.3.0/24 into one route.
Third octet 0-3 is a block of 4 → 10.4.0.0/22. Check: /22 fixes the top 6 bits of the third octet; 0-3 share them.10. What is 0.0.0.0/0?
The default route: matches every address because zero bits are fixed. It is the least specific route, so it is used only when nothing longer matches.Longest-prefix match: how the route table is read
$ ip route
default via 10.1.1.1 dev eth0 # 0.0.0.0/0
10.0.0.0/8 via 10.1.1.2 dev eth0
10.2.0.0/16 via 10.1.1.3 dev eth0
10.2.2.0/24 via 10.1.1.4 dev eth0
10.1.1.0/24 dev eth0 proto kernel scope link src 10.1.1.10
A packet to 10.2.2.30 matches /0, /8, /16 and /24. The router picks the /24, the longest (most specific) prefix, so the next hop is 10.1.1.3? No: 10.1.1.4. Read it again if you got that wrong; it is the classic trap. A packet to 10.2.5.1 matches /0, /8, /16 → next hop 10.1.1.3. A packet to 10.9.9.9 → the /8 → 10.1.1.2. A packet to 8.8.8.8 → default → 10.1.1.1.
Order of decisions in a router: 1. longest prefix. Only when two routes have the same prefix does it compare 2. administrative distance / protocol preference (connected 0, static 1, eBGP 20, OSPF 110, IS-IS 115, iBGP 200 on Cisco; Linux and other vendors differ) and then 3. metric within the same protocol. Equal everything → ECMP, traffic hashed across the next hops.
ip route get 10.2.2.30 on Linux prints exactly which route the kernel would use. Use it in troubleshooting answers.
Special addresses you should recognise
| Range | Meaning |
|---|---|
| 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 | RFC 1918 private; NAT'd at the edge |
| 100.64.0.0/10 | Carrier-grade NAT shared space; also used inside some data centers |
| 127.0.0.0/8 | loopback |
| 169.254.0.0/16 | link-local (APIPA); a host shows one when DHCP failed |
| 224.0.0.0/4 | multicast (224.0.0.5/.6 are OSPF, 224.0.0.9 RIP) |
| 192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24 | documentation ranges (used on this site) |
| 255.255.255.255 | limited broadcast (DHCP Discover goes here) |
Interview questions
1. What does /26 mean and how many usable hosts does it have?
26 network bits, 6 host bits, 64 addresses, 62 usable after removing network and broadcast.2. Why does a /31 have two usable addresses?
RFC 3021: on a point-to-point link there is no need for a broadcast address, so both addresses are hosts. Data-center fabrics use /31s (and IPv6 /127s) between leaves and spines to save address space.3. What is CIDR and why was it introduced?
Classless Inter-Domain Routing: prefixes of any length instead of class A/B/C. It let allocations fit demand and let routers summarise many networks into one route, slowing route-table growth.4. How does a router pick between overlapping routes?
Longest prefix first. Same prefix: lower administrative distance. Same protocol: lower metric. All equal: ECMP.5. A host has 169.254.x.x. What happened?
DHCP failed (no server reachable, relay broken, VLAN wrong) and the OS self-assigned a link-local address. Check the DHCP path, not the host's NIC.6. What is route summarisation and what is its risk?
Advertising one shorter prefix instead of many longer ones. It shrinks tables and hides flaps, but it can attract traffic for subnets that are down (black-holing) if the summary stays up while a component prefix fails.7. Two hosts on the same switch, 10.1.1.10/24 and 10.1.1.200/25. Can they talk?
Host A thinks .200 is local and ARPs for it; .200 replies, so A → B works. B (10.1.1.128/25) thinks .10 is remote and sends via its gateway. It works only if the gateway routes it back onto the same segment, and it's a misconfiguration either way. Expect "mismatched mask" questions.8. What is the broadcast address used for?
Frames to the subnet's all-ones host address reach every host on the subnet. ARP uses the layer-2 broadcast; DHCP Discover uses 255.255.255.255. Routers do not forward directed broadcasts by default.9. How many /26s fit in a /22?
2(26−22) = 16.10. What is the difference between a subnet mask and a wildcard mask?
A wildcard is the bitwise inverse of the mask (0.0.0.255 for /24), used in Cisco ACLs and OSPF network statements. Zero bits must match, one bits are "don't care".Traps
- Subtracting 2 for usable hosts on a /31 or /32.
- Forgetting that the block boundary moves to the third (or second) octet for prefixes shorter than /24.
- Picking the route with the "best" protocol instead of the longest prefix.
- Thinking a /24 "always ends in .0 to .255" when the question is about a /25 or /26 inside it.
- Confusing the mask 255.255.255.224 (/27) with 255.255.255.240 (/28). Recompute from the block size rather than recalling the number.
- Saying two addresses are on the same subnet because the first three octets match. It depends on the mask.
Scenario
A new server at 10.5.20.70 with mask 255.255.255.192 and gateway 10.5.20.1 cannot reach anything outside its rack. Servers at 10.5.20.10 work fine with the same gateway.
Expected reasoning
/26 blocks: 0-63, 64-127. The server is in 10.5.20.64/26 but its gateway 10.5.20.1 is in 10.5.20.0/26, a different subnet by the server's own mask, so the server can't ARP for its gateway. Either the mask should be /24 (like the working servers, check withip addr on one of them) or the gateway for that /26 is 10.5.20.65. Verify with ip route (the kernel may even refuse the off-subnet gateway) and ip neigh (gateway entry FAILED or absent).← 3 · Hash maps, sets, counting and grouping · all topics · 5 · File handling and log parsing →