CIDR Explained: The Key to Efficient IP Addressing
Learn what CIDR prefixes mean, calculate IPv4 and IPv6 block sizes, plan subnets, aggregate routes, and avoid common addressing mistakes.

CIDR (Classless Inter-Domain Routing) is a compact way to say how many leading bits of an IP address identify its network. The number after the slash is the prefix length: 192.0.2.0/24 fixes 24 of IPv4’s 32 bits as the network prefix and leaves 8 bits for addresses inside the block. A /24 therefore contains 2^(32-24) = 256 total IPv4 addresses.
That same slash notation works for IPv6, which has 128-bit addresses. An IPv6 /56 leaves 72 bits for addresses, so its mathematical block size is 2^72. CIDR replaced rigid class A, B and C assumptions with variable-size blocks that fit real network requirements and can be aggregated into fewer routes.
What the slash number means
An IP address is a binary value. CIDR divides it into a fixed-length prefix and a variable-length remainder:

| Notation | Address width | Prefix bits | Remaining bits | Total addresses |
|---|---|---|---|---|
192.0.2.0/24 |
32 | 24 | 8 | 256 |
10.0.0.0/16 |
32 | 16 | 16 | 65,536 |
2001:db8:1234:1a00::/56 |
128 | 56 | 72 | 2^72 |
For IPv4, valid prefix lengths run from /0 through /32. /0 fixes no bits and represents the entire IPv4 space; /32 fixes all bits and identifies one address. RFC 4632 defines CIDR notation and the use of variable-length prefixes for allocation and route aggregation (RFC 4632).
A longer prefix means a smaller block. Moving from /24 to /25 adds one fixed network bit and halves the address count from 256 to 128. Moving from /24 to /23 removes one fixed bit and doubles the block to 512 addresses.
How to calculate an IPv4 CIDR block
Use the address-width formula
For an IPv4 prefix /p:
total addresses = 2^(32 - p)
Examples:
/30:2^2 = 4total addresses./24:2^8 = 256total addresses./20:2^12 = 4,096total addresses./16:2^16 = 65,536total addresses.
AWS uses 10.0.0.0/16 as an example containing addresses from 10.0.0.0 through 10.0.255.255 (AWS VPC IP addressing).
Find the network and broadcast boundaries
The prefix mask keeps the first p bits and sets the rest to zero. For 192.0.2.137/24, the first 24 bits identify the network, so the network address is 192.0.2.0. Setting the remaining 8 bits to one gives the broadcast address, 192.0.2.255.
For a /26, four bits remain. Each block has 64 addresses, and the network boundaries occur every 64 values in the final octet:
192.0.2.0/26(0–63)192.0.2.64/26(64–127)192.0.2.128/26(128–191)192.0.2.192/26(192–255)
Calculate with Python
Python’s standard library handles prefix alignment, iteration and membership checks:
from ipaddress import ip_network, ip_address
network = ip_network("192.0.2.137/26", strict=False)
print("network:", network.network_address)
print("broadcast:", network.broadcast_address)
print("prefix length:", network.prefixlen)
print("total addresses:", network.num_addresses)
print("contains 192.0.2.150:", ip_address("192.0.2.150") in network)
for subnet in network.subnets(prefixlen_diff=1):
print(subnet)
strict=False accepts a host address and normalizes it to the containing network. With strict=True (the default), Python raises an error when host bits are set.
Calculate with Node.js
Node.js has no built-in CIDR module, so this small IPv4 example uses integer bit operations. It validates the prefix and reports the aligned network and broadcast addresses:
function ipv4ToInt(ip) {
const parts = ip.split('.').map(Number);
if (parts.length !== 4 || parts.some(n => !Number.isInteger(n) || n < 0 || n > 255)) {
throw new Error('Invalid IPv4 address');
}
return (((parts[0] << 24) | (parts[1] << 16) | (parts[2] << 8) | parts[3]) >>> 0);
}
function intToIpv4(value) {
return [value >>> 24, (value >>> 16) & 255, (value >>> 8) & 255, value & 255].join('.');
}
function cidrInfo(cidr) {
const [ip, prefixText] = cidr.split('/');
const prefix = Number(prefixText);
if (!Number.isInteger(prefix) || prefix < 0 || prefix > 32) throw new Error('Prefix must be 0..32');
const ipInt = ipv4ToInt(ip);
const mask = prefix === 0 ? 0 : (0xffffffff << (32 - prefix)) >>> 0;
const network = ipInt & mask;
const size = 2 ** (32 - prefix);
return { network: intToIpv4(network), broadcast: intToIpv4(network + size - 1), size };
}
console.log(cidrInfo('192.0.2.137/26'));
How many usable hosts are in a subnet?
The mathematical block size is not automatically the number of assignable hosts. In traditional IPv4 LANs, the network address and broadcast address are reserved, giving:
usable hosts = 2^(32-p) - 2
That rule applies to common subnetting examples such as a /24 with 254 conventional host addresses. It does not apply universally: a /31 is commonly used for point-to-point links, and a /32 identifies one address. Cloud platforms can reserve additional addresses or impose subnet-specific rules. AWS documents provider-specific reservations and behavior in its VPC documentation, so use the platform’s rules when planning capacity rather than subtracting two blindly.
CIDR versus a subnet mask
A dotted-decimal subnet mask expresses the same IPv4 boundary by writing one bits for the prefix and zero bits for the host portion. 172.16.0.0/16 is equivalent to 255.255.0.0; 192.168.99.0/24 is equivalent to 255.255.255.0 (RFC 4632).
| CIDR | Subnet mask | Addresses |
|---|---|---|
/8 |
255.0.0.0 |
16,777,216 |
/16 |
255.255.0.0 |
65,536 |
/24 |
255.255.255.0 |
256 |
/27 |
255.255.255.224 |
32 |
CIDR is usually clearer in APIs, firewall rules and routing tables because the prefix length is explicit and works naturally with prefixes that do not end on an octet boundary.
Subnet planning with variable-length prefixes
CIDR enables variable-length subnet masking (VLSM): allocate each subnet according to its requirement instead of giving every team the same size. Start with the largest requirement, round it up to a power-of-two block, then place smaller aligned blocks in the remaining space.
- List required hosts plus growth and platform reservations.
- Convert each requirement to the smallest suitable prefix. For example, 50 addresses require a
/26(64 total). - Allocate the largest block first and keep every network aligned to its prefix boundary.
- Record non-overlapping ranges in an IP address management system.
- Leave intentional gaps for future expansion and document ownership, region and purpose.
For example, a 10.20.0.0/24 can be divided into two /25 networks, four /26 networks, or a mixture such as one /26 plus two /27 blocks and reserved space. A subnet’s address range alone does not provide internet reachability. AWS notes that VPC connectivity also requires configured gateways and that VPC subnet ranges are not advertised to the public internet.
Route aggregation and alignment
Routers can summarize contiguous, topologically related networks with a shorter prefix. Four adjacent /24 networks can be represented as one /22 when the starting address is aligned correctly. Aggregation reduces routing-table entries and limits how much internal topology must be exposed.
Aggregation has boundaries. Prefixes must be contiguous and aligned, and the summary must not accidentally include unrelated networks. If a more-specific route exists, routers generally prefer it through longest-prefix matching. Plan address assignments around summarization points such as regions, availability zones or offices.
Does CIDR apply to IPv6?
Yes. IPv6 uses the same leftmost-contiguous-prefix idea with 128-bit addresses and prefix lengths from /0 through /128. RFC 4291 describes the IPv6 prefix as the leftmost contiguous bits (RFC 4291).
For 2001:db8:1234:1a00::/56, 56 bits are fixed and 72 remain. The block therefore contains 2^72 addresses. IPv6 subnet plans commonly use a /64 for an individual link or LAN, while an organization may receive a shorter allocation such as /48 or /56 and divide it into many /64 subnets. Follow your provider’s allocation policy and avoid treating IPv6 host capacity like IPv4’s small, subtract-two model.
Common CIDR errors and fixes
| Symptom | Cause | Fix |
|---|---|---|
| Overlapping-subnet error | Two ranges share addresses. | Convert both to network and broadcast boundaries and choose non-overlapping aligned prefixes. |
| Unexpected network address | Host bits were supplied with a prefix. | Normalize the address, or use strict validation to catch the mistake. |
| Too few cloud addresses | Provider reservations reduce assignable capacity. | Read the provider’s subnet reservation rules and add growth headroom. |
| Route summary blackholes traffic | A summary includes an unconnected or unrelated range. | Aggregate only contiguous ranges with the same routing policy; verify longest-prefix routes. |
| IPv6 parser rejects input | IPv4-only tooling or invalid compressed notation. | Use an IPv6-capable library and validate prefixes from /0 to /128. |
| Firewall rule matches too much | A short prefix was chosen accidentally. | Expand the prefix length and test representative addresses before deployment. |

Performance, reliability and cost considerations
- Routing performance: Fewer summarized routes reduce control-plane churn, but over-broad summaries can send traffic toward the wrong next hop.
- Operational reliability: Keep an authoritative inventory of allocations, owners and lifecycle state. Reserve space for growth instead of renumbering production networks later.
- Security: Treat CIDR as a match boundary, not an access-control policy by itself. Combine it with identity, ports, protocol and route controls.
- Cost: Larger cloud subnets do not necessarily cost more by address count, but unused capacity can force extra networks, NAT gateways or inter-region connectivity. Check each provider’s billing and reservation rules.
- Validation: Test both the first and last address, a neighboring address outside the range, and every route summary before rollout.
Or skip the browser setup
If you publish CIDR diagrams, subnet plans or documentation pages, ScreenshotNeo can capture a clean page image through one request. It accepts the cookie or consent banner like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture; each step can be turned off. Bot checks, blank pages, timeouts, failed loads and cache hits cost nothing, and the response identifies the result with X-Page-Verdict and X-Billed headers. An MCP server also lets Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.
See the ScreenshotNeo API documentation for all options, including full-page and element capture, device and retina settings, custom CSS and JavaScript, request blocking, headers and cookies, caching, signed links, asynchronous jobs, bulk capture and usage reporting.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
There are 1,000 screenshots per month free with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
FAQ
What does /24 mean?
It means the first 24 of an IPv4 address’s 32 bits identify the network, leaving 8 bits and 256 total addresses.
Is a /25 larger than a /24?
No. A longer prefix is smaller: /25 has 128 addresses, half of a /24.
Can CIDR describe one IP address?
Yes. An IPv4 host route is /32; an IPv6 host route is /128.
Does a VPC CIDR make services public?
No. Reachability also depends on routes, gateways, firewall rules and provider behavior.
Should I subtract two addresses in every subnet?
No. That traditional IPv4 rule has exceptions, and cloud providers may reserve additional addresses. Consult the platform documentation.