skip to content

In IPv4 addressing, what is VLSM, and why use it instead of giving every subnet the same mask?

level: juniorimportance: must knowfreq 55%

answer

  1. one block, many prefix lengths
  2. size each subnet to its segment
  3. one mask fits the biggest only
  4. routes must carry their length

basics

~20 s

VLSM (variable-length subnet masking) carves one IPv4 block into subnets with different prefix lengths, each sized to its segment. A single fixed mask must fit the largest segment, which wastes space on small ones and yields too few subnets.

solid answer

~50 s

VLSM means using different prefix lengths inside one address block: a `/23` for a big user LAN, a `/27` for a small segment, a `/30` or `/31` for a router-to-router link. With one fixed mask, every subnet has to be big enough for the largest segment, so a two-address link burns a LAN-sized block and the block yields fewer subnets than you need. For example, a `/22` that must hold a 300-host LAN needs a `/23` mask to fit it, which leaves room for only two subnets; with VLSM the same `/22` holds that LAN, three smaller LANs and three links, with space left over. It works because routers keep a prefix length with every route - RFC 1812 requires routers to support variable-length prefixes - and the routing protocol carries that length with each route it advertises. Hosts need nothing special.

go deeper

for a junior

Recall the definition: different prefix lengths inside one block, each subnet sized to its segment. Be ready to show why one mask cannot fit both a 300-host LAN and a two-address link.

for a middle

Explain the prerequisites: routers that store a prefix length per route, routing protocols that carry it, and hosts that decide on-link with their own mask alone.

for a senior

Show the planning consequences: sizing with growth headroom, alignment, largest-first allocation and overlap checks, and why a protocol that drops prefix lengths breaks the whole plan.

for a principal

Frame VLSM as the trade between address efficiency and simplicity: tightly sized subnets save scarce IPv4 space but cost renumbering when segments outgrow them, a pressure IPv6's fixed /64 LANs remove.

## What VLSM is **Variable-length subnet masking (VLSM)** means dividing one IPv4 address block into subnets that use **different prefix lengths**. A prefix length `/n` says how many leading bits of the 32-bit address identify the subnet; the remaining `32 - n` bits number the hosts. A `/n` subnet therefore holds `2^(32-n)` addresses, of which `2^(32-n) - 2` are usable by hosts once the **network address** (host bits all zero) and the **broadcast address** (host bits all one) are set aside. Point-to-point links numbered under RFC 3021 are the exception that matters for VLSM. Under VLSM, one block can contain a `/23` for a big LAN, a `/27` for a small one, and `/30` or `/31` prefixes for router-to-router links, all at once. Each subnet is sized to the segment it serves rather than to the largest segment in the network. ## The problem with one fixed mask Take a concrete brief: the block `10.40.4.0/22` (1,024 addresses of RFC 1918 private space) must hold LANs of about 300, 120, 50 and 20 hosts plus three point-to-point links - seven segments in all. | Scheme | Each subnet | Subnets in the /22 | Fits the 300-host LAN? | Fits all seven segments? | |---|---|---|---|---| | Fixed `/23` everywhere | 512 addresses, 510 usable | 2 | yes | no | | Fixed `/24` everywhere | 256 addresses, 254 usable | 4 | no | no | | Fixed `/27` everywhere | 32 addresses, 30 usable | 32 | no | no | | VLSM: `/23`, `/25`, `/26`, `/27`, three `/30` | sized per segment | 7 used | yes | yes, 276 addresses spare | With one mask, the mask has to be short enough for the biggest LAN, which leaves too few subnets; make it long enough to yield many subnets and the big LAN no longer fits. A fixed mask also wastes space at the small end: a point-to-point link that needs two addresses would consume 512 under the fixed `/23` scheme. VLSM removes both problems because each segment gets its own size. ## What has to be true for VLSM to work - **Routers** must store a prefix length with every interface address and every route. RFC 1812 (router requirements, section 4.2.3.4) says routers MUST support variable length network prefixes in both their interface configurations and their routing databases, and SHOULD treat each route as a generalized network prefix. - **Routing protocols** must carry the prefix length with each route they advertise. A protocol that sends only network numbers forces every router to assume one mask per network, which is exactly the fixed-mask world. RFC 3021 already observed in 2000 that most deployed routing protocols were designed for classless routing. - **Forwarding** picks the most specific matching route - the longest matching prefix - so different lengths coexist in one table without ambiguity. - **Hosts** need nothing special. A host knows only its own address and prefix length; RFC 1122 section 3.3.1.1 has it mask the destination with its own mask, compare the result with its own network bits, and either deliver directly or hand the packet to a gateway. The prefix lengths used on other segments never enter that decision. ## The rules that keep a VLSM plan valid 1. **Size each segment to the smallest subnet whose usable hosts cover it**, counting the router's own interface address and some room to grow. 2. **Start every subnet on a multiple of its own size** - a `/26` on a multiple of 64 in the last octet, a `/23` on an even third octet. That is what "on a bit boundary" means. 3. **Allocate the largest subnets first**, so each next subnet can start at the next free address and no gaps open between them. 4. **Never let two subnets overlap.** Two CIDR prefixes are either disjoint or one contains the other, so overlap is easy to test once the plan is written down. ## Where the idea stops VLSM is an allocation discipline, not a protocol: nothing on the wire says "this is a VLSM network". Splitting a block into equal pieces is ordinary fixed-length subnetting, and combining finished subnets into one shorter route is summarisation - related skills with their own rules. In IPv6 the pressure that motivated VLSM mostly disappears. An ordinary LAN gets a `/64`, because stateless address autoconfiguration builds addresses from a 64-bit interface identifier (RFC 4291, RFC 4862), and only inter-router links commonly get something longer, such as the `/127` that RFC 6164 requires routers to support. VLSM remains an everyday IPv4 skill because IPv4 space is scarce and every wasted block is felt.

  • Does an IPv4 host need any special support to live in a network that uses VLSM?
    No. A host only knows its own address and prefix length. Under RFC 1122 section 3.3.1.1 it masks the destination with its own mask and compares that with its own network bits: a match means deliver directly on the link, anything else goes to a gateway. The prefix lengths used on other segments never enter that decision, so only routers and the routing protocol must handle variable lengths.
  • Is VLSM practised the same way in IPv6?
    Not for LANs. An IPv6 LAN normally gets a `/64`, because stateless autoconfiguration builds addresses from a 64-bit interface identifier (RFC 4291, RFC 4862), and address space is not scarce. Varying the length still happens on inter-router links: RFC 6164 says routers MUST support `/127` prefixes on point-to-point inter-router links, partly to avoid neighbor-cache exhaustion attacks on a `/64` link.

saying these in an interview costs you the question

  • VLSM just means splitting a block into equal-sized subnets.
  • Every host needs special VLSM support or configuration to work.
  • Any routing protocol can carry a VLSM plan, even one without prefix lengths.
  • With VLSM, subnets of different sizes are allowed to overlap.
  • A point-to-point link needs a /24 like any other subnet.