Calculate CIDR ranges, IP subnets, host counts, and network boundaries instantly -- the subnet reference tool that fits in your pocket.
Download Free on the App StoreSubnet Calculator and all 19 tools are free. No ads, no account required.
Enter any IP address with a CIDR prefix or subnet mask and PingKit instantly calculates the full subnet details. No mental math, no binary conversion tables, no flipping between calculator apps. It handles the subnetting so you can focus on the actual network design.
Enter a CIDR prefix like /22 and see the equivalent subnet mask (255.255.252.0), or enter a dotted decimal mask and get the CIDR notation. Both directions, instantly.
See the exact first and last usable IP address in any subnet. Know at a glance that 10.0.1.0/24 runs from 10.0.1.1 through 10.0.1.254 without counting in your head.
Get the total number of addresses and usable hosts for any prefix length. A /20 gives you 4,094 usable hosts -- PingKit does the 2^n - 2 calculation for you.
Network address, broadcast address, wildcard mask, and address class are all displayed together. Everything you need for firewall rules, ACLs, and routing tables in one view.
Designing a new office network or segmenting a data center VLAN? The subnet calculator tells you exactly how many hosts each prefix supports so you can allocate ranges without waste. Plan a /25 for the engineering floor (126 hosts), a /27 for the conference rooms (30 hosts), and a /28 for management (14 hosts) -- all verified on the spot.
When you're assigning static IPs or configuring DHCP scopes, you need to know the valid range. Enter the subnet and immediately see which addresses are usable. No more accidentally assigning the network or broadcast address and wondering why the device can't communicate.
Not everyone has the CIDR table memorized. When a firewall rule says 10.0.0.0/12 and you need to know exactly what that covers, PingKit converts it instantly. Especially useful when reviewing security group rules or cloud VPC configurations on the go.
Studying for CCNA, CompTIA Network+, or AWS certifications? Use PingKit to verify your subnetting homework. Work the problem by hand first, then check your answer with the calculator. It's faster than looking up a reference chart and you can practice anywhere.
Type an IPv4 address, choose a prefix length from 0 to 32, and every derived value appears at once.
Subnet mask and wildcard mask. The mask in dotted form, and its inverse. The wildcard is the one router access lists want, and inverting a mask in your head is where mistakes happen.
Network and broadcast address. The first and last addresses in the block. Neither can be given to a device on a normal subnet, which is where the two missing hosts go.
First and last usable host. The actual range you can assign, which is what you came for when you are setting a DHCP pool or a static address.
Total and usable host counts. Total is every address in the block; usable is that minus the network and broadcast addresses. The exceptions are /31 and /32, where the calculator correctly reports every address as usable, because a point-to-point link under RFC 3021 has no broadcast address to reserve[source] and a /32 is a single host.
Class, and whether the address is private. Classes are historical and no longer govern routing, but they still appear in documentation and exam questions. The private flag is the practically useful one: it tells you immediately whether an address is routable on the internet or lives inside somebody's network.
A binary view, toggled on, showing the address and the mask bit by bit. This is the one that makes subnetting click, and there is a section on it below.
The prefix is simply how many bits from the left belong to the network[source]. Everything left over addresses hosts, so each step up the table halves the block.
| Prefix | Mask | Addresses | Usable | Typically |
|---|---|---|---|---|
/16 | 255.255.0.0 | 65,536 | 65,534 | A large flat network. Rare and usually a mistake in a LAN. |
/20 | 255.255.240.0 | 4,096 | 4,094 | A campus or a large office site. |
/22 | 255.255.252.0 | 1,024 | 1,022 | Four /24s worth. A department. |
/23 | 255.255.254.0 | 512 | 510 | Two /24s. The usual answer when a /24 is one floor too small. |
/24 | 255.255.255.0 | 256 | 254 | The default everywhere. Almost every home network. |
/25 | 255.255.255.128 | 128 | 126 | Half a /24. The first split most people make. |
/26 | 255.255.255.192 | 64 | 62 | A guest network or an IoT VLAN. |
/27 | 255.255.255.224 | 32 | 30 | A small VLAN. Cameras, printers, a rack. |
/28 | 255.255.255.240 | 16 | 14 | A handful of servers. |
/29 | 255.255.255.248 | 8 | 6 | What an ISP hands out as a small static block. |
/30 | 255.255.255.252 | 4 | 2 | The classic point-to-point link between two routers. |
/31 | 255.255.255.254 | 2 | 2 | A point-to-point link with no waste. Both addresses usable. |
/32 | 255.255.255.255 | 1 | 1 | A single host. Firewall rules and loopbacks. |
Two shortcuts are worth memorising. The usable count is always two fewer than the total, except at /31 and /32. And the last octet of the mask, subtracted from 256, gives you the block size: a /26 mask ends in 192, and 256 minus 192 is 64, so the networks are 0, 64, 128 and 192.
Turn on the binary display and the whole idea stops being arithmetic. The mask is a run of ones followed by a run of zeros, and the prefix length is just how many ones there are. A /24 is twenty-four ones and eight zeros.
Line the address up underneath it. Every bit sitting above a one is fixed: it identifies the network and is identical for every device on it. Every bit above a zero is free to vary, and those are your hosts. The network address is the one where all the free bits are zero, and the broadcast is the one where they are all one. That is the entire subject.
It also explains the rule people find arbitrary, which is that a prefix cannot fall in an odd place. The ones have to be contiguous from the left, so 255.255.255.0 is a valid mask and 255.0.255.0 is not.
And it shows why blocks have to align. A /26 can start at .0, .64, .128 or .192 and nowhere else, because those are the only values where the free bits are all zero. Starting one at .50 is not a network anyone can route.
Splitting a home network for IoT. The usual move is to carve the default /24 into two /25s, or into four /26s, and put smart devices in one and everything else in another. Calculate each block first so the DHCP ranges you type into the router do not overlap. Two overlapping pools produce duplicate addresses, which present as devices that work intermittently and never look like an addressing problem.
Sizing a network before you build it. Count the devices, add whatever growth you expect, then pick the smallest prefix that fits. A /24 for fifteen devices is fine at home and wasteful in a routed network. Remember the two reserved addresses: a /29 looks like eight and gives you six.
Working out whether two addresses can talk directly. Put in the first address and the mask, look at the network address, then do the same for the second. Same network address, same subnet, and they talk without a router. Different, and they need one, which is the answer to a surprising share of "I can ping it from here but not from there".
Reading someone else's documentation. A block written as 10.20.0.0/22 tells you nothing until you expand it. Here it takes one entry to see that it runs from 10.20.0.0 to 10.20.3.255 and holds 1,022 usable addresses.
Point-to-point links. A /30 is the traditional answer and wastes half its four addresses. A /31 does the same job with two, both usable. Most modern equipment supports it and a lot of older equipment does not, which is the whole reason /30 persists.
The usable count is two lower than expected. The network and broadcast addresses are reserved. This is the single most common surprise, and it is why a /30 gives you two hosts rather than four.
A device is configured with the network or broadcast address. It will appear to accept it and then behave strangely. Check the first and last usable host values before assigning anything by hand.
Two devices with the same mask cannot reach each other. Compare their network addresses rather than their IPs. Two addresses that look adjacent can sit either side of a boundary: with a /26, .62 and .70 are in different networks.
The mask on one device does not match the others. A device with a /24 mask on a /23 network can reach half of it and not the other half, and the failure is asymmetric, which makes it maddening to diagnose. Everything on a subnet must agree on the prefix.
The address is private and you expected it to be reachable. The private flag answers that in one glance. An address in 10.x, 172.16 to 172.31, or 192.168.x does not route on the internet, and reaching it from outside needs a VPN or port forwarding.
You needed IPv6. This calculator is IPv4 only. IPv6 subnetting works on the same principle with different arithmetic, and in practice you are almost always handed a /64 and stop thinking about it.
Subnetting doesn't happen in isolation. Once you've planned your addressing scheme, use PingKit's other tools to verify it works -- ping devices to confirm reachability, run a network scan to discover what's actually on each subnet, check DNS resolution, or trace the route between segments. Having the calculator and the diagnostic tools in the same app means fewer context switches during network configuration.
Open PingKit's Subnet Calculator, type an IPv4 address into the address field, then pick the prefix separately from the CIDR list, anything from /0 to /32. It fills in the subnet mask and wildcard mask, the network and broadcast addresses, the first and last usable host, the total and usable address counts, the class, and whether the range is private or public. A Show Binary toggle prints the address and the mask in binary, and a Common Subnets list jumps straight to /24, /27, /30 and the rest.
CIDR notation is the slash and number after an address, counting how many leading bits are the network part, so /24 means 255.255.255.0 and leaves 254 usable hosts. PingKit takes the prefix and gives you the mask: choose /22 and it prints 255.255.252.0, next to the wildcard mask that ACL and firewall syntax asks for. That conversion runs one way in the app, prefix to mask, so there is no field for pasting a dotted-decimal mask in the other direction.
256 addresses in total and 254 usable, because the first is the network address and the last is the broadcast address. PingKit shows both counts for every prefix from /0 to /32, and it handles the two edge cases properly rather than reporting zero: a /31 gives 2 usable addresses per RFC 3021, and a /32 gives the single host.
No. The calculator is IPv4 only: it parses four dotted octets and works in 32-bit arithmetic, so an IPv6 prefix is not accepted. IPv6 is not absent from the app, though. DNS Lookup queries AAAA records, and My Network shows your IPv6 address when the network hands one out.
Yes, and so are the other 18 tools: no ads, no account, nothing to unlock. The calculation itself is arithmetic on the device, with no DNS query, no probe and no server involved. Guardian is a subscription for continuous monitoring rather than for tools, and even the AI features are not locked away entirely: without subscribing you get 15 AI interactions a week, capped at 5 a day.
Download PingKit free and get instant CIDR and subnet calculations.
Download Free on the App StoreRequires iOS 17.0 or later.