skip to content

What did CIDR change compared with classful IPv4 addressing, and why must routing protocols carry an explicit prefix length?

level: middleimportance: should knowfreq 44%

answer

  1. mask implied by leading bits
  2. only three network sizes
  3. Class B ran out first
  4. RFC 4632 obsoletes RFC 1519

basics

~20 s

Classful IPv4 inferred a network's mask from its leading address bits, so only /8, /16 and /24 networks existed. CIDR (RFC 4632, obsoleting RFC 1519) makes the prefix length explicit and arbitrary, so routes and filters must carry it.

solid answer

~50 s

Under classful addressing (RFC 791), the leading bits fixed the network size: a leading `0` meant class A, an implied `/8`; `10` meant class B, `/16`; `110` meant class C, `/24`. Only three sizes existed, Class B space was running out, and every class C handed out added a routing-table entry. CIDR — RFC 1519 in 1993, now RFC 4632 — drops the inference: a prefix is an address plus a length from 0 to 32, describing any power-of-two block. Because the length can no longer be read from the address, routing protocols must carry it with every route and forwarding tables must store prefix and length together; mask-less protocols such as the original RIP cannot work in transit networks. RFC 1812 adds that routers should treat every route as a contiguous network prefix and reject anything inconsistent with that model.

go deeper

for a junior

Know that classful addressing tied network size to the first bits, giving only /8, /16 and /24, and that CIDR made the prefix length explicit.

for a middle

Explain the three problems CIDR answered and why the prefix length must now travel with every route, filter entry and forwarding-table entry.

for a senior

Recognise classful assumptions in legacy configuration and tooling, such as masks inferred from the first octet, and say what they break in a classless network.

for a principal

Frame CIDR as a trade: flexible allocation and aggregation bought at the cost of carrying lengths everywhere, which is the same bargain IPv6 adopted from the start.

## Classful addressing: the mask was implied The original IPv4 specification, **RFC 791** (1981), split every address into a network number and a "rest" field, and the split was fixed by the address's own leading bits. These were the **classes**: | Class | Leading bits | First octet | Implied network part | CIDR equivalent | |---|---|---|---|---| | A | `0` | 0–127 | 8 bits | `/8` | | B | `10` | 128–191 | 16 bits | `/16` | | C | `110` | 192–223 | 24 bits | `/24` | | D | `1110` | 224–239 | none — multicast (RFC 1112) | — | | E | `1111` | 240–255 | none — reserved | — | Because a router could read the class off the first bits, nothing had to say where the network part ended. A route for `172.16.0.0` was obviously a class B network with an implied mask of `255.255.0.0`. **Subnetting** (RFC 950, 1985) relaxed this only inside one organisation: a site could split its class A, B or C network with a locally known mask, but the rest of the internet still saw one classful network. RFC 950 even allowed the subnet bits to be non-adjacent, while recommending that they be contiguous. ## Why the class system broke RFC 4632 records the three problems the IETF identified in early 1992: 1. **Exhaustion of Class B space.** Class C allowed at most 254 hosts and was too small for a mid-sized organisation; Class B, with up to 65,534, was far too large but the only fit, so it was consumed fastest. 2. **Routing-table growth.** Organisations given many class C networks instead each added separate routes to the tables of internet routers. 3. **Eventual exhaustion** of the 32-bit IPv4 space as a whole. ## What CIDR changed CIDR was published as RFC 1519 in 1993; **RFC 4632** (2006, Best Current Practice 122) obsoletes it and is the specification to cite today. Its core move, in RFC 4632's words, is to make explicit which bits are the network number: - A prefix is written as an address, a slash and a decimal length from 0 to 32 — `172.16.0.0/16` for the old class B. - Any power-of-two block is now describable, not just three sizes, so allocations can match actual need. - Classes stop meaning anything to routing: `198.51.100.0/24` and `10.0.0.0/8` are prefixes, and neither is "a C" or "an A" to a router. - Contiguous blocks can be combined into one shorter prefix to keep tables small — the aggregation half of CIDR, a subject of its own. ## Why the prefix length must travel with the route RFC 4632 §5 states the consequence directly: with classless prefixes "it is not possible to infer the network mask from the initial bit pattern of an IPv4 address". Therefore: - **Routing protocols** must carry the mask or prefix length with every route. RFC 4632 names OSPF, IS-IS, RIPv2 and BGP-4 as protocols that do, and the original RIP, HELLO and EGP as older protocols that do not and so cannot be used in transit networks. - **Forwarding tables** must store prefix and length together; equipment organised around classful conventions "cannot be expected to work correctly" on the internet. - **Filters** must take lengths too. RFC 4632 §5.3 shows classful filter lines such as `accept 172.16.0.0` becoming `accept 172.16.0.0/16`. - **The default route** `0.0.0.0/0` is just the zero-length prefix, and RFC 4632 says every implementation must accept it. ## Contiguous masks, from RFC 950 to RFC 4632 Classless routing only works if a mask can be expressed as a length. RFC 1812 (1995) explains that arbitrary masks can make routing ambiguous — two routes with different but equally specific masks could both match one destination — which is why discontiguous subnet masks are not permitted. It says routers should treat every route as a network prefix and reject configuration inconsistent with that model. RFC 4632 adds that the only remaining constraint on a mask is that it must be contiguous. ## Classful habits that still mislead - Assuming a `10.x.x.x` address is always on a `/8`, or a `192.168.x.x` address always on a `/24`. The mask is configured, never implied. - Calling CIDR "the same thing as subnetting". Subnetting split classful networks internally; CIDR removed classes from inter-domain routing altogether. - Citing RFC 1519 as current. It has been obsolete since RFC 4632. - Expecting a route without a length to mean anything. In a classless world, `172.16.32.0` alone does not say whether the route is a `/20`, a `/24` or a single host.

  • If 192.0.2.0 were advertised by a routing protocol that carries no mask, what would the receiver assume?
    It would infer the mask from the class: the leading bits of 192 are `110`, class C, so it assumes `/24`. If the real prefix is `192.0.2.0/26`, the receiver's picture is wrong. That is why RFC 4632 says mask-less protocols such as the original RIP cannot be used in transit networks, and every classless routing protocol carries the length explicitly.
  • Is subnetting the same thing as CIDR?
    No. Subnetting (RFC 950, 1985) split one classful network internally with a mask only that organisation's routers knew; everyone else still saw one class A, B or C network. CIDR (RFC 1519 in 1993, now RFC 4632) removed classes from inter-domain routing, so any prefix length is valid everywhere and blocks can be split or combined across organisational boundaries.

saying these in an interview costs you the question

  • Says a 10.x address is always on a /8 because it is class A.
  • Treats CIDR and RFC 950 subnetting as the same mechanism.
  • Believes routers still infer a route's mask from its first octet.
  • Cites RFC 1519 as the current CIDR specification.
  • Thinks a route advertised without a length is unambiguous.