skip to content

CIDR

Classless addressing: a prefix length instead of a class, subnet arithmetic from that one number, and aggregation that keeps routing tables small. Subnet math on paper is a standard exercise.

on this pageshow

explore

questions

24

In IPv4 CIDR notation, what does the number after the slash mean, and how do you convert /20 to a dotted-decimal subnet mask and back?

level: juniorimportance: must knowfreq 78%

answer

  1. leading bits, not trailing ones
  2. eight bits per full octet
  3. one partial octet left over
  4. four leading ones make 240

basics

~20 s

The number after the slash is the prefix length: how many leading bits of the 32-bit IPv4 address are network bits. /20 is twenty ones then twelve zeros, 255.255.240.0; counting the ones in 255.255.240.0 gives 20 back.

solid answer

~40 s

The prefix length counts the leading `1` bits of the mask, so it fixes which part of the address names the network and which part numbers hosts. To convert `/20`, fill whole octets first: 8 + 8 = 16 bits gives `255.255`; the remaining 4 bits make the third octet `11110000`, which is `240`; everything after is `0`. So `/20` is `255.255.240.0`. Going back, count the ones per octet: `255` is 8, `240` is 4, `0` is 0, and 8 + 8 + 4 + 0 = 20. Only nine values can ever appear in a mask octet — 0, 128, 192, 224, 240, 248, 252, 254 and 255 — because a CIDR mask is one contiguous run of ones followed by zeros (RFC 4632).

go deeper

for a junior

Recall that the slash counts leading network bits and memorise the nine legal mask octet values; converting /20 to 255.255.240.0 and back should take seconds.

for a middle

Explain the conversion in binary rather than as memorised pairs: whole octets of 255 first, then one partial octet worth 256 minus two to the power of its zero bits.

for a senior

Show that you read masks and prefix lengths interchangeably while auditing route tables or filters, and catch a non-contiguous mask before it reaches a configuration.

for a principal

Argue for one notation across plans, tooling and reviews: mixing dotted masks with slash lengths in one document breeds transcription errors that reviewers rarely catch.

## What the slash number counts An IPv4 address is 32 bits, written as four decimal **octets** of 8 bits each. In **CIDR notation** (Classless Inter-Domain Routing, specified today by RFC 4632, which obsoletes RFC 1519), a prefix is written as an address, a slash, and a decimal number between 0 and 32: `172.16.32.0/20`. That number is the **prefix length** — how many of the address's leading bits are the **network part**. The remaining bits are the **host part**, which numbers individual interfaces inside the network. A **subnet mask** says the same thing in a different shape: a 32-bit value with a `1` in every network-bit position and a `0` in every host-bit position, written in the same dotted-decimal form as an address. The two notations are interchangeable: - `/20` means "the first 20 bits are network bits". - `255.255.240.0` is `11111111.11111111.11110000.00000000` — twenty ones, then twelve zeros. - Both describe exactly the same split, so converting between them is pure bookkeeping. RFC 4632's own example is the legacy network `172.16.0.0`, whose implied mask `255.255.0.0` is written `172.16.0.0/16`: the most significant 16 bits are ones and the least significant 16 are zeros. ## Converting a prefix length to a mask Work octet by octet, left to right: 1. Divide the prefix length by 8. Each full 8 is one octet of `255`. For `/20`: 20 = 8 + 8 + 4, so two octets of `255`. 2. The remainder (here 4) is the number of leading ones in the next octet. Look its value up in the table below, or compute it as 256 minus 2 to the power of the zero bits: 256 − 2^4 = 256 − 16 = `240`. 3. Every octet after that is `0`. 4. Result: `255.255.240.0`. | Leading ones in the octet | Binary | Decimal | |---|---|---| | 0 | `00000000` | 0 | | 1 | `10000000` | 128 | | 2 | `11000000` | 192 | | 3 | `11100000` | 224 | | 4 | `11110000` | 240 | | 5 | `11111000` | 248 | | 6 | `11111100` | 252 | | 7 | `11111110` | 254 | | 8 | `11111111` | 255 | These nine values are the **only** ones a valid mask octet can hold. RFC 4632 states that the only outstanding constraint on a mask is that it "must be left contiguous", and RFC 1812 describes an architecturally correct mask as a contiguous string of ones at the most significant end, a contiguous string of zeros at the least significant end, and no intervening bits. ## Converting a mask back to a prefix length Reverse the process: 1. Every `255` octet contributes 8. 2. The first octet that is not `255` contributes its count of leading ones from the table (`240` → 4, `252` → 6, `192` → 2). 3. Every octet after it must be `0`; if one is not, the mask is invalid. 4. Add them up: `255.255.240.0` → 8 + 8 + 4 + 0 = **20**. ## Worked conversions | Prefix length | Split | Mask | |---|---|---| | `/8` | 8 | `255.0.0.0` | | `/12` | 8 + 4 | `255.240.0.0` | | `/20` | 8 + 8 + 4 | `255.255.240.0` | | `/22` | 8 + 8 + 6 | `255.255.252.0` | | `/23` | 8 + 8 + 7 | `255.255.254.0` | | `/26` | 8 + 8 + 8 + 2 | `255.255.255.192` | | `/29` | 8 + 8 + 8 + 5 | `255.255.255.248` | The two ends of the range are legal too. `/0` is the mask `0.0.0.0`: no network bits at all, so `0.0.0.0/0` covers every IPv4 address and serves as the **default route**, which RFC 4632 says all implementations must accept. `/32` is `255.255.255.255`: all bits fixed, a single address, often called a host route. ## Mistakes that show up in interviews - **Putting the partial octet in the wrong place.** `/20` is `255.255.240.0`, not `255.255.255.240`; the latter is `/28`. The partial octet always follows the run of `255`s. - **Assuming prefix lengths come in multiples of 8.** `/8`, `/16` and `/24` are only the lengths that line up with octet boundaries; any value from 0 to 32 is valid. - **Counting non-zero octets.** Reading `255.255.240.0` as `/24` because three octets are non-zero ignores that `240` holds only four ones. - **Accepting an impossible octet.** `255.255.250.0` is not a mask: `250` is `11111010`, a zero between ones, and it has no prefix-length form. The slash form is what routing tables, filters and documentation use today, because it cannot be non-contiguous by construction; the dotted form survives in host configuration screens and older tooling. Being able to move between them in your head, in both directions, is the baseline every other piece of subnetting builds on.

  • Why can 255.255.250.0 never be a valid IPv4 subnet mask?
    Because `250` is `11111010` in binary: a zero sits between ones. A CIDR mask must be one contiguous run of ones followed by zeros, so the only legal octet values are 0, 128, 192, 224, 240, 248, 252, 254 and 255. RFC 4632 says the mask must be left contiguous, and a mask with a hole in it has no prefix-length equivalent at all.
  • What do the IPv4 prefix lengths /0 and /32 mean?
    `/0` has the mask `0.0.0.0`: no network bits, so `0.0.0.0/0` covers every IPv4 address and is the default route, which RFC 4632 says every implementation must accept. `/32` has the mask `255.255.255.255`: all 32 bits are fixed, so it names exactly one address, a host route. RFC 4632 allows any decimal prefix length from 0 to 32.

A prefix length works like saying how many leading digits of a phone number are the area code: /20 says the first 20 bits name the network, and whatever follows names one line inside it.

saying these in an interview costs you the question

  • Says the slash number counts host bits rather than network bits.
  • Writes /20 as 255.255.255.240, putting the partial octet last.
  • Believes any octet value, such as 250, can appear in a mask.
  • Assumes prefix lengths must be multiples of eight, like /8, /16, /24.
  • Reads 255.255.240.0 as /24 by counting non-zero octets.
open as a page

Which IPv4 address blocks does RFC 1918 reserve for private networks, and why are they not routed on the public internet?

level: juniorimportance: must knowfreq 78%

basics

~10 s

RFC 1918 reserves 10.0.0.0/8, 172.16.0.0/12 (172.16.0.0 to 172.31.255.255) and 192.168.0.0/16. Anyone may reuse them without registration, so they are not unique, and routes and packets for them are kept off inter-network links.

open as a page

In IPv4, how do you work out the usable host count for a prefix length, and the smallest prefix fitting a host requirement?

level: juniorimportance: must knowfreq 76%

basics

~20 s

An IPv4 /n prefix leaves 32 - n host bits: 2^(32 - n) addresses, minus the all-zeros network and all-ones broadcast addresses. To size a subnet, pick the fewest host bits h whose 2^h - 2 covers the hosts needed.

open as a page

In IPv4 addressing, what is VLSM, and why use it instead of giving every subnet the same mask?

level: juniorimportance: must knowfreq 55%

basics

~20 s

VLSM (variable-length subnet masking) carves one IPv4 block into subnets with different prefix lengths, each sized to its segment. A single fixed mask must fit the largest segment, which wastes space on small ones and yields too few subnets.

open as a page

In IPv4, which single prefix summarises 10.1.4.0/24, 10.1.5.0/24, 10.1.6.0/24 and 10.1.7.0/24, and how do you derive it?

level: middleimportance: must knowfreq 42%

basics

~10 s

The summary is 10.1.4.0/22. The third octets 4 to 7 share their first six bits (000001), so 16 + 6 = 22 bits are common, covering exactly 10.1.4.0 to 10.1.7.255.

open as a page

How do you decide whether an IPv4 address such as 172.16.45.9 falls inside a prefix such as 172.16.32.0/20, using the mask?

level: middleimportance: must knowfreq 58%

basics

~20 s

AND the address with the prefix's mask and compare the result with the prefix's network bits. For /20 the mask is 255.255.240.0; 172.16.45.9 AND that mask is 172.16.32.0, equal to the prefix, so the address is inside.

open as a page

Given the IPv4 address 172.16.37.200/27, what are its network address, broadcast address, first and last usable hosts, and host count?

level: middleimportance: must knowfreq 80%

basics

~10 s

For 172.16.37.200/27 the mask is 255.255.255.224, blocks of 32 addresses: network 172.16.37.192, broadcast 172.16.37.223, usable hosts 172.16.37.193 to 172.16.37.222, which is 2^5 - 2 = 30 hosts.

open as a page

Using VLSM, how would you carve the IPv4 block 10.40.4.0/22 into subnets for 300, 120, 50 and 20 hosts plus three point-to-point links?

level: middleimportance: must knowfreq 62%

basics

~10 s

Size each segment, then place largest first: 10.40.4.0/23 (300), 10.40.6.0/25 (120), 10.40.6.128/26 (50), 10.40.6.192/27 (20), then 10.40.6.224/30, .228/30 and .232/30 for the links, leaving 10.40.6.236 to 10.40.7.255 free.

open as a page

In IPv4 CIDR, what is route aggregation (also called supernetting or summarisation), and why do networks do it?

level: juniorimportance: should knowfreq 36%

basics

~10 s

Route aggregation replaces several contiguous, bit-aligned IPv4 prefixes with one shorter prefix covering exactly them, such as two /24s becoming one /23, so upstream routers carry and update one route instead of many.

open as a page

In IPv4, why can't the contiguous blocks 10.1.5.0/24 through 10.1.8.0/24 be summarised as one /22, and what is the smallest exact set?

level: middleimportance: should knowfreq 24%

basics

~10 s

A /22 must start on a third octet divisible by 4, and 5 to 8 straddles the 4-7 and 8-11 boundaries. The smallest exact set is three prefixes: 10.1.5.0/24, 10.1.6.0/23 and 10.1.8.0/24.

open as a page

What did CIDR change compared with classful IPv4 addressing, and why must routing protocols carry an explicit prefix length?

level: middleimportance: should knowfreq 44%

basics

~20 s

Classful IPv4 inferred a network's mask from its leading address bits, so only /8, /16 and /24 networks existed. CIDR (RFC 4632, obsoleting RFC 1519) makes the prefix length explicit and arbitrary, so routes and filters must carry it.

open as a page

In IPv4, what do 127.0.0.1, 0.0.0.0 and 255.255.255.255 each mean, and where may each appear in a packet?

level: middleimportance: should knowfreq 42%

basics

~20 s

127.0.0.1 belongs to the 127.0.0.0/8 loopback block, which must never leave the host. 0.0.0.0 means "this host on this network", valid only as a source while a host learns its address. 255.255.255.255 is limited broadcast: destination only, never forwarded.

open as a page

Why do IPv4 /31 and /32 prefixes break the 2^n - 2 host rule, and what does RFC 3021 change for a /31?

level: middleimportance: should knowfreq 32%

basics

~20 s

The minus-two rule reserves network and broadcast addresses, which would leave a /31 with no hosts. RFC 3021 makes both /31 addresses hosts on a point-to-point link, which needs no broadcast; a /32 is one address, a host route.

open as a page

How do you split the IPv4 block 198.51.100.0/24 into four equal subnets, and what are each subnet's network, broadcast and usable range?

level: middleimportance: should knowfreq 62%

basics

~20 s

Borrow two host bits: 2^2 = 4 subnets of /26, each 64 addresses with 62 usable hosts. They start at .0, .64, .128 and .192 of 198.51.100, and each broadcast sits one below the next subnet's start, the last at .255.

open as a page

In IPv4 VLSM planning, why do you allocate the largest subnets first, and what does a subnet's bit boundary have to do with it?

level: middleimportance: should knowfreq 42%

basics

~20 s

Every IPv4 subnet must start on a multiple of its own size. Allocating largest first keeps each next start aligned, so blocks pack without gaps; other orders leave alignment holes or can occupy a large subnet's only valid starts.

open as a page

For IPv4 point-to-point links in a VLSM plan, when would you use a /30 and when a /31, and what did RFC 3021 change?

level: middleimportance: should knowfreq 35%

basics

~20 s

A /30 has four IPv4 addresses: network, two hosts and broadcast. RFC 3021 lets both addresses of a /31 be hosts on a point-to-point link, halving the cost. Use /31 where both ends support it, /30 where one does not.

open as a page

In IPv4 routing, one network advertises 192.168.16.0/20 and another advertises 192.168.17.0/24; where does traffic to 192.168.17.100 go, and when is that legitimate?

level: seniorimportance: should knowfreq 27%

basics

~20 s

Traffic to 192.168.17.100 goes to whoever advertises the /24, wherever that route is accepted, because routers forward on the longest matching prefix. That is legitimate for multihoming, moved sites and traffic engineering, and a hijack when someone else announces it.

open as a page

An IPv4 site router advertises 10.20.0.0/16 upstream to summarise its four LANs, 10.20.0.0/24 through 10.20.3.0/24; what goes wrong for the rest of that /16?

level: seniorimportance: should knowfreq 20%

basics

~20 s

The /16 attracts traffic for 65,536 addresses though only 10.20.0.0/22 exists. Unused space is dropped at the site, or loops via its default route without a discard route; others using that space lose traffic when their more-specific vanishes.

open as a page

A router access-list entry meant to match 172.16.32.0/20 was written with 255.255.240.0 where a wildcard mask belongs — what does it match, and what should it be?

level: seniorimportance: should knowfreq 24%

basics

~20 s

A wildcard mask marks bits to ignore: 0 must match, 1 is don't-care, so 172.16.32.0/20 needs 0.0.15.255. Written as 255.255.240.0, it ignores the network bits instead, matching scattered .0 addresses everywhere and only 172.16.32.0 from the intended block.

open as a page

A service fetches user-supplied URLs and must refuse internal IPv4 destinations; which reserved blocks must its address filter cover, and where do such filters usually leak?

level: seniorimportance: should knowfreq 32%

basics

~10 s

Refuse 0.0.0.0/8, 10.0.0.0/8, 100.64.0.0/10, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.0.0.0/24, 192.168.0.0/16, 198.18.0.0/15, the documentation /24s, 224.0.0.0/4 and 240.0.0.0/4, testing the resolved address of every connection, redirects included.

open as a page

On one IPv4 Ethernet segment, how do hosts 192.0.2.40/24 and 192.0.2.140/25, both using gateway 192.0.2.254, reach each other, and what breaks?

level: seniorimportance: should knowfreq 24%

basics

~20 s

The /24 host finds 192.0.2.140 inside its own network and delivers directly; the /25 host ANDs 192.0.2.40 with 255.255.255.128, gets 192.0.2.0, not its 192.0.2.128, and sends via the router - an asymmetric path that stateful filtering breaks.

open as a page

An IPv4 VLSM plan gives 10.40.4.0/23 to one LAN and 10.40.5.128/26 to another; what breaks, and how would you catch such overlaps before deployment?

level: seniorimportance: should knowfreq 24%

basics

~20 s

The /26 is nested in the /23: routers send 10.40.5.128 to .191 to the /26 by longest match, while /23 hosts treat those addresses as on-link. Sort the plan by start and flag any start at or below an earlier end.

open as a page

What does the IPv4 special-purpose address registry (RFC 6890) record about each reserved block, and how does it separate documentation, shared and private space?

level: middleimportance: nice to knowfreq 20%

basics

~20 s

For each block the registry records whether its addresses are valid as source and as destination, forwardable by routers, globally reachable and reserved by IP itself. Documentation blocks are invalid as either; RFC 1918 and 100.64.0.0/10 are forwardable but not globally reachable.

open as a page