skip to content

VLSM

Carving one block into subnets of different sizes, largest first so nothing overlaps. It is the realistic version of subnetting, since real networks never need every segment the same size.

on this pageshow

questions

5

In IPv4 addressing, what is VLSM, and why use it instead of giving every subnet the same mask?

level: juniorimportance: must knowfreq 55%

answer

  1. one block, many prefix lengths
  2. size each subnet to its segment
  3. one mask fits the biggest only
  4. routes must carry their length

basics

~20 s

VLSM (variable-length subnet masking) carves one IPv4 block into subnets with different prefix lengths, each sized to its segment. A single fixed mask must fit the largest segment, which wastes space on small ones and yields too few subnets.

solid answer

~50 s

VLSM means using different prefix lengths inside one address block: a `/23` for a big user LAN, a `/27` for a small segment, a `/30` or `/31` for a router-to-router link. With one fixed mask, every subnet has to be big enough for the largest segment, so a two-address link burns a LAN-sized block and the block yields fewer subnets than you need. For example, a `/22` that must hold a 300-host LAN needs a `/23` mask to fit it, which leaves room for only two subnets; with VLSM the same `/22` holds that LAN, three smaller LANs and three links, with space left over. It works because routers keep a prefix length with every route - RFC 1812 requires routers to support variable-length prefixes - and the routing protocol carries that length with each route it advertises. Hosts need nothing special.

go deeper

for a junior

Recall the definition: different prefix lengths inside one block, each subnet sized to its segment. Be ready to show why one mask cannot fit both a 300-host LAN and a two-address link.

for a middle

Explain the prerequisites: routers that store a prefix length per route, routing protocols that carry it, and hosts that decide on-link with their own mask alone.

for a senior

Show the planning consequences: sizing with growth headroom, alignment, largest-first allocation and overlap checks, and why a protocol that drops prefix lengths breaks the whole plan.

for a principal

Frame VLSM as the trade between address efficiency and simplicity: tightly sized subnets save scarce IPv4 space but cost renumbering when segments outgrow them, a pressure IPv6's fixed /64 LANs remove.

## What VLSM is **Variable-length subnet masking (VLSM)** means dividing one IPv4 address block into subnets that use **different prefix lengths**. A prefix length `/n` says how many leading bits of the 32-bit address identify the subnet; the remaining `32 - n` bits number the hosts. A `/n` subnet therefore holds `2^(32-n)` addresses, of which `2^(32-n) - 2` are usable by hosts once the **network address** (host bits all zero) and the **broadcast address** (host bits all one) are set aside. Point-to-point links numbered under RFC 3021 are the exception that matters for VLSM. Under VLSM, one block can contain a `/23` for a big LAN, a `/27` for a small one, and `/30` or `/31` prefixes for router-to-router links, all at once. Each subnet is sized to the segment it serves rather than to the largest segment in the network. ## The problem with one fixed mask Take a concrete brief: the block `10.40.4.0/22` (1,024 addresses of RFC 1918 private space) must hold LANs of about 300, 120, 50 and 20 hosts plus three point-to-point links - seven segments in all. | Scheme | Each subnet | Subnets in the /22 | Fits the 300-host LAN? | Fits all seven segments? | |---|---|---|---|---| | Fixed `/23` everywhere | 512 addresses, 510 usable | 2 | yes | no | | Fixed `/24` everywhere | 256 addresses, 254 usable | 4 | no | no | | Fixed `/27` everywhere | 32 addresses, 30 usable | 32 | no | no | | VLSM: `/23`, `/25`, `/26`, `/27`, three `/30` | sized per segment | 7 used | yes | yes, 276 addresses spare | With one mask, the mask has to be short enough for the biggest LAN, which leaves too few subnets; make it long enough to yield many subnets and the big LAN no longer fits. A fixed mask also wastes space at the small end: a point-to-point link that needs two addresses would consume 512 under the fixed `/23` scheme. VLSM removes both problems because each segment gets its own size. ## What has to be true for VLSM to work - **Routers** must store a prefix length with every interface address and every route. RFC 1812 (router requirements, section 4.2.3.4) says routers MUST support variable length network prefixes in both their interface configurations and their routing databases, and SHOULD treat each route as a generalized network prefix. - **Routing protocols** must carry the prefix length with each route they advertise. A protocol that sends only network numbers forces every router to assume one mask per network, which is exactly the fixed-mask world. RFC 3021 already observed in 2000 that most deployed routing protocols were designed for classless routing. - **Forwarding** picks the most specific matching route - the longest matching prefix - so different lengths coexist in one table without ambiguity. - **Hosts** need nothing special. A host knows only its own address and prefix length; RFC 1122 section 3.3.1.1 has it mask the destination with its own mask, compare the result with its own network bits, and either deliver directly or hand the packet to a gateway. The prefix lengths used on other segments never enter that decision. ## The rules that keep a VLSM plan valid 1. **Size each segment to the smallest subnet whose usable hosts cover it**, counting the router's own interface address and some room to grow. 2. **Start every subnet on a multiple of its own size** - a `/26` on a multiple of 64 in the last octet, a `/23` on an even third octet. That is what "on a bit boundary" means. 3. **Allocate the largest subnets first**, so each next subnet can start at the next free address and no gaps open between them. 4. **Never let two subnets overlap.** Two CIDR prefixes are either disjoint or one contains the other, so overlap is easy to test once the plan is written down. ## Where the idea stops VLSM is an allocation discipline, not a protocol: nothing on the wire says "this is a VLSM network". Splitting a block into equal pieces is ordinary fixed-length subnetting, and combining finished subnets into one shorter route is summarisation - related skills with their own rules. In IPv6 the pressure that motivated VLSM mostly disappears. An ordinary LAN gets a `/64`, because stateless address autoconfiguration builds addresses from a 64-bit interface identifier (RFC 4291, RFC 4862), and only inter-router links commonly get something longer, such as the `/127` that RFC 6164 requires routers to support. VLSM remains an everyday IPv4 skill because IPv4 space is scarce and every wasted block is felt.

  • Does an IPv4 host need any special support to live in a network that uses VLSM?
    No. A host only knows its own address and prefix length. Under RFC 1122 section 3.3.1.1 it masks the destination with its own mask and compares that with its own network bits: a match means deliver directly on the link, anything else goes to a gateway. The prefix lengths used on other segments never enter that decision, so only routers and the routing protocol must handle variable lengths.
  • Is VLSM practised the same way in IPv6?
    Not for LANs. An IPv6 LAN normally gets a `/64`, because stateless autoconfiguration builds addresses from a 64-bit interface identifier (RFC 4291, RFC 4862), and address space is not scarce. Varying the length still happens on inter-router links: RFC 6164 says routers MUST support `/127` prefixes on point-to-point inter-router links, partly to avoid neighbor-cache exhaustion attacks on a `/64` link.

saying these in an interview costs you the question

  • VLSM just means splitting a block into equal-sized subnets.
  • Every host needs special VLSM support or configuration to work.
  • Any routing protocol can carry a VLSM plan, even one without prefix lengths.
  • With VLSM, subnets of different sizes are allowed to overlap.
  • A point-to-point link needs a /24 like any other subnet.
open as a page

Using VLSM, how would you carve the IPv4 block 10.40.4.0/22 into subnets for 300, 120, 50 and 20 hosts plus three point-to-point links?

level: middleimportance: must knowfreq 62%

basics

~10 s

Size each segment, then place largest first: 10.40.4.0/23 (300), 10.40.6.0/25 (120), 10.40.6.128/26 (50), 10.40.6.192/27 (20), then 10.40.6.224/30, .228/30 and .232/30 for the links, leaving 10.40.6.236 to 10.40.7.255 free.

open as a page

In IPv4 VLSM planning, why do you allocate the largest subnets first, and what does a subnet's bit boundary have to do with it?

level: middleimportance: should knowfreq 42%

basics

~20 s

Every IPv4 subnet must start on a multiple of its own size. Allocating largest first keeps each next start aligned, so blocks pack without gaps; other orders leave alignment holes or can occupy a large subnet's only valid starts.

open as a page

For IPv4 point-to-point links in a VLSM plan, when would you use a /30 and when a /31, and what did RFC 3021 change?

level: middleimportance: should knowfreq 35%

basics

~20 s

A /30 has four IPv4 addresses: network, two hosts and broadcast. RFC 3021 lets both addresses of a /31 be hosts on a point-to-point link, halving the cost. Use /31 where both ends support it, /30 where one does not.

open as a page

An IPv4 VLSM plan gives 10.40.4.0/23 to one LAN and 10.40.5.128/26 to another; what breaks, and how would you catch such overlaps before deployment?

level: seniorimportance: should knowfreq 24%

basics

~20 s

The /26 is nested in the /23: routers send 10.40.5.128 to .191 to the /26 by longest match, while /23 hosts treat those addresses as on-link. Sort the plan by start and flag any start at or below an earlier end.

open as a page