Addresses identify interfaces
An IP address identifies an interface in an IP network. A device can have several interfaces and several addresses. A laptop can use Wi-Fi, Ethernet, a VPN, and loopback at the same time. An IPv4 address contains 32 bits, written as four decimal octets. An octet contains eight bits, so its decimal value ranges from 0 through 255. For example,192.168.10.42 contains the octets 192, 168, 10, and 42.
A port identifies a transport endpoint on that address.
An address does not specify which application should receive the data.
For a connection description, include the IP address, transport protocol, and port.
Read a CIDR prefix
CIDR means Classless Inter-Domain Routing. The notation192.168.10.0/24 describes a block whose first 24 bits are fixed.
The remaining eight bits vary, giving 256 addresses.
See RFC 4632, section 3.1.
192.168.10.42/24.
The canonical name of its subnet is 192.168.10.0/24.
Do not interchange the interface address and the subnet address.
The number of IPv4 addresses in a prefix is 2 ** (32 - prefix_length).
A larger prefix length means a smaller address block.
The host counts above assume a conventional IPv4 subnet that reserves its network and broadcast addresses.
Cloud platforms can reserve additional addresses.
A
/31 point-to-point link can use both addresses under RFC 3021.
A /32 identifies one IPv4 address.
Do not apply “subtract two” to every prefix.
Work through a /26
Find the subnet that contains192.168.10.77/26.
- Subtract 26 from 32 to obtain six host bits.
- Calculate
2 ** 6to obtain 64 addresses per block. - List the last-octet boundaries: 0, 64, 128, and 192.
- Select the block from 64 through 127, which contains 77.
192.168.10.64/26.
Its broadcast address is 192.168.10.127.
Its conventional host range is 192.168.10.65 through 192.168.10.126.
The mask also gives the answer directly.
The network address is the bitwise AND of the interface address and mask.
For the last octet:
192.168.10.100 belongs to this subnet.
192.168.10.130 belongs to the next /26 block.
Sharing the first three decimal octets does not imply sharing a subnet.
Divide a block into subnets
Suppose a lab receives10.42.8.0/24 and needs four equal networks.
Two extra prefix bits create four blocks, so each new prefix is /26.
The ranges do not overlap, and together they cover the original block.
This is an address plan, not a security policy.
Routers and firewalls must separately enforce which networks can communicate.
Private addresses and special ranges
The following ranges are reserved for private IPv4 networks. They do not provide globally unique addresses on the public Internet. See RFC 1918, section 3.
Only part of
172.0.0.0/8 is private under this allocation.
For example, 172.20.1.4 is inside the private range; 172.32.1.4 is outside it.
An address outside these three ranges is not automatically a usable public address.
Other special-purpose ranges exist.
127.0.0.1 is an IPv4 loopback address: it refers to the local host.
The examples in this course also use 192.0.2.0/24 and 203.0.113.0/24, which are documentation ranges.
Do not use them as destinations for live connectivity checks.
See the IANA special-purpose registry.
A first look at IPv6
IPv6 addresses contain 128 bits and use hexadecimal notation.2001:db8:42:1::10/64 is an example interface address within 2001:db8:42:1::/64.
The :: compresses a sequence of zero groups and can appear only once in an address.
2001:db8::/32 is reserved for documentation.
A /64 fixes 64 prefix bits and leaves 64 interface-address bits.
Do not apply the IPv4 broadcast calculation to IPv6; IPv6 does not use broadcast addresses.
See RFC 4291 and RFC 3849.
Lab: check your calculation with Python
This lab requires Python 3.10 or later. It uses only the standard library and sends no network traffic. Save this code ascidr_lab.py:
python3 cidr_lab.py. On Windows, use py -3 cidr_lab.py.
The expected output is:
ip_interface() for an interface with host bits.
By default, ip_network("192.168.10.77/26") rejects those host bits instead of silently changing the input.
See the Python ipaddress documentation.
The script changes no network settings. Delete the file when you finish, or keep it for the next exercise.
Exercise
- Find the network, broadcast, and conventional host range for
10.20.30.140/27. - Decide whether
10.20.30.159is a usable host in that conventional subnet. - Divide
192.168.50.0/24into two equal subnets. - Explain why changing a firewall rule from
/24to/16can widen access.
Worked answers
Worked answers
- A
/27contains 32 addresses. The containing block is10.20.30.128/27, with broadcast.159and hosts.129through.158. - No.
.159is the broadcast address in this conventional subnet. - The blocks are
192.168.50.0/25and192.168.50.128/25. Each contains 128 addresses. - A
/16matches more addresses than a/24. The exact effect also depends on the firewall’s rule order and actions.
/27 result before using Python to check it.
Next: DNS, routing, NAT, and firewalls.