CIDR ranges:
what a /26 or /20 prefix really covers
Read any IPv4 prefix at a glance: how many addresses it holds, where the block starts and ends, and which prefix fits the hosts you need.
Calcylator Editorial Team
Updated · 5 min read
What the number after the slash means
A CIDR range such as 192.168.1.0/26 is a starting address plus a prefix length. The prefix length says how many of the 32 bits in an IPv4 address are fixed and shared by every host in the block. The remaining bits are free to change, and they decide how many addresses the block contains.
For a /26, 26 bits are fixed and 6 are free, so the block holds 2^6 = 64 addresses. For a /20 the free part is 12 bits, giving 4,096 addresses. A bigger prefix number means a smaller block, which is the part that trips people up at first.
The same idea is written as a dotted mask. A /26 is 255.255.255.192, which is just the 26 fixed bits written as ones and the 6 free bits as zeros. Both forms describe the same range, and CIDR notation is the shorter one to type and to read in firewall rules and cloud consoles.
The slash notation replaced the older class A, B and C system, where a network was forced to be 256, 65,536 or 16,777,216 addresses. CIDR allows any power of two in between, which made it possible to hand out address space in sensible sizes.
The 2^(32 − n) rule and usable hosts
- n:
- prefix length, the number after the slash
- 32:
- total bits in an IPv4 address
- 2:
- one network address plus one broadcast address
The first address in a block names the network itself and the last one is the broadcast address, so they are not handed to devices. That is why a /26 gives 62 hosts rather than 64. Two exceptions exist: a /31 is used for point-to-point links and a /32 identifies a single host or route.
Worked example for 192.168.1.0/26
Range
192.168.1.0/26
Free bits
32 − 26 = 6
Total addresses
2^6 = 64
Mask
255.255.255.192
Address layout
Network 192.168.1.0, hosts 192.168.1.1 to 192.168.1.62 (62 usable), broadcast 192.168.1.63
The next /26 block starts at 192.168.1.64.
The block size of 64 shows up in the last octet: blocks start at 0, 64, 128 and 192. Any address in the 192.168.1.x family belongs to whichever of those four blocks sits at or below it, which makes spot checks quick without any binary conversion.
Finding the block when the address is not on a boundary
Real addresses rarely land on the start of a block. Take 172.16.37.200/20. The prefix reaches into the third octet, so that octet is the one that changes in steps. Its step size is 256 − 240 = 16, because the third octet of a /20 mask is 240.
- Find the octet where the mask is neither 255 nor 0. For /20 that is the third octet, with mask value 240.
- Work out the block step: 256 − 240 = 16.
- Round the address value down to a multiple of the step: 37 ÷ 16 = 2.31, so 2 × 16 = 32.
- Network address is 172.16.32.0. The block runs for 16 values in that octet, so the broadcast address is 172.16.47.255.
- Total addresses are 2^12 = 4,096, with 4,094 usable.
The same method works for any prefix that is not a multiple of 8. Only one octet is partly fixed, so only one subtraction and one rounding are needed.
Prefix reference from /24 to /32
| Prefix | Mask | Total addresses | Usable hosts |
|---|---|---|---|
| /24 | 255.255.255.0 | 256 | 254 |
| /25 | 255.255.255.128 | 128 | 126 |
| /26 | 255.255.255.192 | 64 | 62 |
| /27 | 255.255.255.224 | 32 | 30 |
| /28 | 255.255.255.240 | 16 | 14 |
| /29 | 255.255.255.248 | 8 | 6 |
| /30 | 255.255.255.252 | 4 | 2 |
| /31 | 255.255.255.254 | 2 | special use |
| /32 | 255.255.255.255 | 1 | single host |
Memorising the powers of two from 2 to 256 is enough. The mask value in the interesting octet is always 256 minus the block size, so 256 − 64 = 192 and 256 − 32 = 224.
Private ranges and combining blocks
Three IPv4 ranges are set aside for private networks, and almost every home, office and cloud network you meet is built from them. Knowing their prefixes tells you at once how much room you have to work with.
| Private range | Prefix | Total addresses |
|---|---|---|
| 10.0.0.0 to 10.255.255.255 | 10.0.0.0/8 | 16,777,216 |
| 172.16.0.0 to 172.31.255.255 | 172.16.0.0/12 | 1,048,576 |
| 192.168.0.0 to 192.168.255.255 | 192.168.0.0/16 | 65,536 |
CIDR also lets adjacent blocks be summarised into one shorter prefix. The two /24 blocks 192.168.0.0/24 and 192.168.1.0/24 sit side by side and combine into 192.168.0.0/23, which is one entry in a routing table instead of two. The rule is that the blocks must be the same size and the combined block must start on a boundary for its new size.
Choosing a prefix for the hosts you need
Work backwards when you plan a subnet. Say a department needs 50 devices today and should have room to grow. Add 2 for the network and broadcast addresses to get 52, then find the smallest power of two that is at least 52. That is 64, which is 2^6, so six host bits and a prefix of 32 − 6 = /26.
A /27 holds only 30 hosts, which would fail on the first day. A /25 holds 126, which is generous but uses an address block twice as large as you need. Leave deliberate headroom rather than rounding up by accident, since renumbering a subnet later means touching every device and rule that mentions it.
Mistakes that cause overlaps and outages
- Treating a larger prefix number as a larger network. A /28 is much smaller than a /16.
- Forgetting to subtract the network and broadcast addresses when counting devices.
- Overlapping blocks, such as 10.0.0.0/16 and 10.0.4.0/22. The second sits inside the first, which breaks routing and VPN peering.
- Starting a subnet at an address that is not a multiple of its block size. 192.168.1.20/26 is not a valid network address; the block that contains it starts at 192.168.1.0.
A calculator is handy for checking a plan, especially for ranges like /19 or /21 where the boundary falls in the third octet. For routing tables and security groups, double-check the network address printed for each block before you save it.
Common questions
How many IP addresses are in a /26?
A /26 has 6 host bits, so it holds 2^6 = 64 addresses. Two are reserved by convention for the network and broadcast, which leaves 62 usable hosts. The mask is 255.255.255.192 and blocks begin every 64 addresses.
How do I calculate the number of hosts from a CIDR prefix?
Subtract the prefix from 32 to get host bits, raise 2 to that power for total addresses, then subtract 2 for the network and broadcast addresses. For /27: 32 − 27 = 5, 2^5 = 32, so 30 usable hosts.
What is the CIDR range for 255.255.255.0?
The mask 255.255.255.0 has 24 ones, so it is a /24 prefix. That block contains 256 addresses and 254 usable hosts, and it is the most familiar subnet size on home and office networks.
Why are /31 and /32 treated differently?
A /31 has only two addresses and is used for point-to-point links, so both are assigned to the two ends instead of reserving network and broadcast. A /32 is a single address, used for one host, a loopback or a precise route.
Can two CIDR ranges overlap?
Yes, and it causes problems. One block overlaps another when its address span sits wholly or partly inside it. 10.0.0.0/16 covers 10.0.0.0 to 10.0.255.255, so 10.0.4.0/22 falls entirely within it. Overlapping ranges confuse routing and VPN links.
Was this guide helpful?
Continue reading
View all blogsBase64 Size Overhead: Why It Adds a Third
Base64 turns every 3 bytes into 4 characters, so encoded length is 4 × ceil(n ÷ 3). One million bytes becomes 1,333,336 characters, about 33% more.
5 min read
Binary to Decimal Conversion, Step by Step
Convert binary to decimal by adding the place values of each 1: 101101 is 32 + 8 + 4 + 1 = 45. Includes the doubling shortcut and an IP address example.
5 min read
Decimal to Binary: Divide by 2, Read Backward
Convert any whole number to binary by halving it and reading the remainders from the bottom up. 45 becomes 101101; here is the method and a check.
5 min read




