Prerequisites: network layers. Outcome: calculate a network range from a prefix and explain whether two addresses belong to the same subnet. Allow: 35 minutes, including the Python exercise.

Addresses identify interfaces

An IP address identifies an interface in an IP network. A device can have several interfaces and several addresses. A laptop can use Wi-Fi, Ethernet, a VPN, and loopback at the same time. An IPv4 address contains 32 bits, written as four decimal octets. An octet contains eight bits, so its decimal value ranges from 0 through 255. For example, 192.168.10.42 contains the octets 192, 168, 10, and 42. A port identifies a transport endpoint on that address. An address does not specify which application should receive the data. For a connection description, include the IP address, transport protocol, and port.

Read a CIDR prefix

CIDR means Classless Inter-Domain Routing. The notation 192.168.10.0/24 describes a block whose first 24 bits are fixed. The remaining eight bits vary, giving 256 addresses. See RFC 4632, section 3.1.
An interface can use 192.168.10.42/24. The canonical name of its subnet is 192.168.10.0/24. Do not interchange the interface address and the subnet address. The number of IPv4 addresses in a prefix is 2 ** (32 - prefix_length). A larger prefix length means a smaller address block. The host counts above assume a conventional IPv4 subnet that reserves its network and broadcast addresses. Cloud platforms can reserve additional addresses. A /31 point-to-point link can use both addresses under RFC 3021. A /32 identifies one IPv4 address. Do not apply “subtract two” to every prefix.

Work through a /26

Find the subnet that contains 192.168.10.77/26.
  1. Subtract 26 from 32 to obtain six host bits.
  2. Calculate 2 ** 6 to obtain 64 addresses per block.
  3. List the last-octet boundaries: 0, 64, 128, and 192.
  4. Select the block from 64 through 127, which contains 77.
The network is 192.168.10.64/26. Its broadcast address is 192.168.10.127. Its conventional host range is 192.168.10.65 through 192.168.10.126. The mask also gives the answer directly. The network address is the bitwise AND of the interface address and mask. For the last octet:
192.168.10.100 belongs to this subnet. 192.168.10.130 belongs to the next /26 block. Sharing the first three decimal octets does not imply sharing a subnet.

Divide a block into subnets

Suppose a lab receives 10.42.8.0/24 and needs four equal networks. Two extra prefix bits create four blocks, so each new prefix is /26. The ranges do not overlap, and together they cover the original block. This is an address plan, not a security policy. Routers and firewalls must separately enforce which networks can communicate.

Private addresses and special ranges

The following ranges are reserved for private IPv4 networks. They do not provide globally unique addresses on the public Internet. See RFC 1918, section 3. Only part of 172.0.0.0/8 is private under this allocation. For example, 172.20.1.4 is inside the private range; 172.32.1.4 is outside it. An address outside these three ranges is not automatically a usable public address. Other special-purpose ranges exist. 127.0.0.1 is an IPv4 loopback address: it refers to the local host. The examples in this course also use 192.0.2.0/24 and 203.0.113.0/24, which are documentation ranges. Do not use them as destinations for live connectivity checks. See the IANA special-purpose registry.

A first look at IPv6

IPv6 addresses contain 128 bits and use hexadecimal notation. 2001:db8:42:1::10/64 is an example interface address within 2001:db8:42:1::/64. The :: compresses a sequence of zero groups and can appear only once in an address. 2001:db8::/32 is reserved for documentation. A /64 fixes 64 prefix bits and leaves 64 interface-address bits. Do not apply the IPv4 broadcast calculation to IPv6; IPv6 does not use broadcast addresses. See RFC 4291 and RFC 3849.

Lab: check your calculation with Python

This lab requires Python 3.10 or later. It uses only the standard library and sends no network traffic. Save this code as cidr_lab.py:
Run python3 cidr_lab.py. On Windows, use py -3 cidr_lab.py. The expected output is:
Use ip_interface() for an interface with host bits. By default, ip_network("192.168.10.77/26") rejects those host bits instead of silently changing the input. See the Python ipaddress documentation. The script changes no network settings. Delete the file when you finish, or keep it for the next exercise.

Exercise

  1. Find the network, broadcast, and conventional host range for 10.20.30.140/27.
  2. Decide whether 10.20.30.159 is a usable host in that conventional subnet.
  3. Divide 192.168.50.0/24 into two equal subnets.
  4. Explain why changing a firewall rule from /24 to /16 can widen access.
  1. A /27 contains 32 addresses. The containing block is 10.20.30.128/27, with broadcast .159 and hosts .129 through .158.
  2. No. .159 is the broadcast address in this conventional subnet.
  3. The blocks are 192.168.50.0/25 and 192.168.50.128/25. Each contains 128 addresses.
  4. A /16 matches more addresses than a /24. The exact effect also depends on the firewall’s rule order and actions.
Completion check: calculate the /27 result before using Python to check it. Next: DNS, routing, NAT, and firewalls.