In IPv4 CIDR notation, what does the number after the slash mean, and how do you convert /20 to a dotted-decimal subnet mask and back?
answer
- leading bits, not trailing ones
- eight bits per full octet
- one partial octet left over
- four leading ones make 240
basics
~20 sThe number after the slash is the prefix length: how many leading bits of the 32-bit IPv4 address are network bits. /20 is twenty ones then twelve zeros, 255.255.240.0; counting the ones in 255.255.240.0 gives 20 back.
solid answer
~40 sThe prefix length counts the leading `1` bits of the mask, so it fixes which part of the address names the network and which part numbers hosts. To convert `/20`, fill whole octets first: 8 + 8 = 16 bits gives `255.255`; the remaining 4 bits make the third octet `11110000`, which is `240`; everything after is `0`. So `/20` is `255.255.240.0`. Going back, count the ones per octet: `255` is 8, `240` is 4, `0` is 0, and 8 + 8 + 4 + 0 = 20. Only nine values can ever appear in a mask octet — 0, 128, 192, 224, 240, 248, 252, 254 and 255 — because a CIDR mask is one contiguous run of ones followed by zeros (RFC 4632).
go deeper
Recall that the slash counts leading network bits and memorise the nine legal mask octet values; converting /20 to 255.255.240.0 and back should take seconds.
Explain the conversion in binary rather than as memorised pairs: whole octets of 255 first, then one partial octet worth 256 minus two to the power of its zero bits.
Show that you read masks and prefix lengths interchangeably while auditing route tables or filters, and catch a non-contiguous mask before it reaches a configuration.
Argue for one notation across plans, tooling and reviews: mixing dotted masks with slash lengths in one document breeds transcription errors that reviewers rarely catch.
## What the slash number counts An IPv4 address is 32 bits, written as four decimal **octets** of 8 bits each. In **CIDR notation** (Classless Inter-Domain Routing, specified today by RFC 4632, which obsoletes RFC 1519), a prefix is written as an address, a slash, and a decimal number between 0 and 32: `172.16.32.0/20`. That number is the **prefix length** — how many of the address's leading bits are the **network part**. The remaining bits are the **host part**, which numbers individual interfaces inside the network. A **subnet mask** says the same thing in a different shape: a 32-bit value with a `1` in every network-bit position and a `0` in every host-bit position, written in the same dotted-decimal form as an address. The two notations are interchangeable: - `/20` means "the first 20 bits are network bits". - `255.255.240.0` is `11111111.11111111.11110000.00000000` — twenty ones, then twelve zeros. - Both describe exactly the same split, so converting between them is pure bookkeeping. RFC 4632's own example is the legacy network `172.16.0.0`, whose implied mask `255.255.0.0` is written `172.16.0.0/16`: the most significant 16 bits are ones and the least significant 16 are zeros. ## Converting a prefix length to a mask Work octet by octet, left to right: 1. Divide the prefix length by 8. Each full 8 is one octet of `255`. For `/20`: 20 = 8 + 8 + 4, so two octets of `255`. 2. The remainder (here 4) is the number of leading ones in the next octet. Look its value up in the table below, or compute it as 256 minus 2 to the power of the zero bits: 256 − 2^4 = 256 − 16 = `240`. 3. Every octet after that is `0`. 4. Result: `255.255.240.0`. | Leading ones in the octet | Binary | Decimal | |---|---|---| | 0 | `00000000` | 0 | | 1 | `10000000` | 128 | | 2 | `11000000` | 192 | | 3 | `11100000` | 224 | | 4 | `11110000` | 240 | | 5 | `11111000` | 248 | | 6 | `11111100` | 252 | | 7 | `11111110` | 254 | | 8 | `11111111` | 255 | These nine values are the **only** ones a valid mask octet can hold. RFC 4632 states that the only outstanding constraint on a mask is that it "must be left contiguous", and RFC 1812 describes an architecturally correct mask as a contiguous string of ones at the most significant end, a contiguous string of zeros at the least significant end, and no intervening bits. ## Converting a mask back to a prefix length Reverse the process: 1. Every `255` octet contributes 8. 2. The first octet that is not `255` contributes its count of leading ones from the table (`240` → 4, `252` → 6, `192` → 2). 3. Every octet after it must be `0`; if one is not, the mask is invalid. 4. Add them up: `255.255.240.0` → 8 + 8 + 4 + 0 = **20**. ## Worked conversions | Prefix length | Split | Mask | |---|---|---| | `/8` | 8 | `255.0.0.0` | | `/12` | 8 + 4 | `255.240.0.0` | | `/20` | 8 + 8 + 4 | `255.255.240.0` | | `/22` | 8 + 8 + 6 | `255.255.252.0` | | `/23` | 8 + 8 + 7 | `255.255.254.0` | | `/26` | 8 + 8 + 8 + 2 | `255.255.255.192` | | `/29` | 8 + 8 + 8 + 5 | `255.255.255.248` | The two ends of the range are legal too. `/0` is the mask `0.0.0.0`: no network bits at all, so `0.0.0.0/0` covers every IPv4 address and serves as the **default route**, which RFC 4632 says all implementations must accept. `/32` is `255.255.255.255`: all bits fixed, a single address, often called a host route. ## Mistakes that show up in interviews - **Putting the partial octet in the wrong place.** `/20` is `255.255.240.0`, not `255.255.255.240`; the latter is `/28`. The partial octet always follows the run of `255`s. - **Assuming prefix lengths come in multiples of 8.** `/8`, `/16` and `/24` are only the lengths that line up with octet boundaries; any value from 0 to 32 is valid. - **Counting non-zero octets.** Reading `255.255.240.0` as `/24` because three octets are non-zero ignores that `240` holds only four ones. - **Accepting an impossible octet.** `255.255.250.0` is not a mask: `250` is `11111010`, a zero between ones, and it has no prefix-length form. The slash form is what routing tables, filters and documentation use today, because it cannot be non-contiguous by construction; the dotted form survives in host configuration screens and older tooling. Being able to move between them in your head, in both directions, is the baseline every other piece of subnetting builds on.
- Why can 255.255.250.0 never be a valid IPv4 subnet mask?Because `250` is `11111010` in binary: a zero sits between ones. A CIDR mask must be one contiguous run of ones followed by zeros, so the only legal octet values are 0, 128, 192, 224, 240, 248, 252, 254 and 255. RFC 4632 says the mask must be left contiguous, and a mask with a hole in it has no prefix-length equivalent at all.
- What do the IPv4 prefix lengths /0 and /32 mean?`/0` has the mask `0.0.0.0`: no network bits, so `0.0.0.0/0` covers every IPv4 address and is the default route, which RFC 4632 says every implementation must accept. `/32` has the mask `255.255.255.255`: all 32 bits are fixed, so it names exactly one address, a host route. RFC 4632 allows any decimal prefix length from 0 to 32.
A prefix length works like saying how many leading digits of a phone number are the area code: /20 says the first 20 bits name the network, and whatever follows names one line inside it.
saying these in an interview costs you the question
- Says the slash number counts host bits rather than network bits.
- Writes /20 as 255.255.255.240, putting the partial octet last.
- Believes any octet value, such as 250, can appear in a mask.
- Assumes prefix lengths must be multiples of eight, like /8, /16, /24.
- Reads 255.255.240.0 as /24 by counting non-zero octets.