Networking Concepts 23% Lesson 15 of 19

Lesson 1.7.2 — Subnetting Fundamentals & CIDR Notation

Avatar Of Asad IjazAsad Ijaz ·Sep 15, 2026 ·7 min read
79% through domain
Illustration Of Subnetting And Cidr Notation Alongside The Network+ N10-009 Lesson 1.7.2 Title Card

Domain 1.0 | Networking Concepts — 23% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain what CIDR notation means and how it maps to a subnet mask
  • Calculate the number of usable host addresses in a given subnet
  • Identify the network address, broadcast address, and usable host range for a subnet
  • Explain why organizations subnet their networks instead of using one flat address block

Key Terms

TermDefinition
CIDR (Classless Inter-Domain Routing)A notation that specifies how many bits of an address are network bits, written as a slash followed by a number, like /24
Subnet MaskA 32-bit value that marks which bits of an address are network bits and which are host bits
Network AddressThe first address in a subnet, representing the subnet itself rather than any individual device
Broadcast AddressThe last address in a subnet, used to reach every device in that subnet at once
Host BitsThe bits left over after network bits are accounted for, used to number individual devices within a subnet
SubnettingSplitting one larger network into multiple smaller ones

Explanation

Picking Up Where Classful Addressing Left Off

Lesson 1.7.1 ended on a specific complaint: classful addressing wasted a lot of address space. A Class C network gave you 254 addresses, take it or leave it. A Class B gave you over 65,000, even if you only needed a few hundred. CIDR fixed that by letting a network be exactly the size it needs, instead of one of three fixed sizes.

What CIDR Notation Actually Means

CIDR notation looks like this: 192.168.1.0/24. That slash and number — the “/24” — tells you how many bits of the address are network bits. The rest are host bits, available for numbering individual devices.

An IPv4 address is 32 bits total. So /24 means 24 network bits, leaving 8 host bits. /26 means 26 network bits, leaving just 6 host bits. More network bits means fewer host bits, and fewer host bits means fewer devices that particular subnet can hold. That trade-off is the entire game of subnetting.

CIDR notation is really just a shorthand for a subnet mask, and you’ll see both used interchangeably.

CIDRSubnet MaskHost Bits
/24255.255.255.08
/25255.255.255.1287
/26255.255.255.1926
/27255.255.255.2245
/28255.255.255.2404
/29255.255.255.2483
/30255.255.255.2522
Diagram Showing How Cidr Notation Maps To Subnet Masks And Network/Host Bits
Cidr Notation And Subnet Masks Explained

Memorizing this table cold pays off constantly, both on the exam and in real work. You’ll see /24 and /30 especially often — /24 for typical LANs, /30 for point-to-point links between routers, since a link between exactly two devices only needs two usable addresses.

Here’s the binary underneath one of those rows, so the conversion isn’t just a memorized table. Take 255.255.255.192. In binary, that last octet — 192 — is 11000000. Count the 1-bits: two of them. Add those two to the 24 bits already represented by the first three full octets (255.255.255), and you land on 26 total network bits. That’s /26. Every mask in the table above works exactly the same way — count the 1-bits across all four octets, and that count is your CIDR prefix.

Counting Hosts: The 2^n − 2 Rule

Every subnet reserves two addresses that can’t be assigned to a device. The network address — the very first address — represents the subnet itself. The broadcast address — the very last address — reaches every device in that subnet at once. Neither one can be handed out to an individual host.

That gives you a simple formula: usable hosts equals 2 raised to the number of host bits, minus 2.

A /24 has 8 host bits. 2^8 is 256. Subtract 2, and you get 254 usable addresses. A /26 has 6 host bits — 2^6 is 64, minus 2 is 62 usable addresses. Smaller subnets, predictably, hold fewer devices.

Diagram Showing Usable Host Counts For Common Cidr Prefixes From /24 To /30
Usable Host Counts By Cidr Prefix

Working Through a Real Example

Take 192.168.1.0/24. The network address is 192.168.1.0. The broadcast address is 192.168.1.255. Everything in between — 192.168.1.1 through 192.168.1.254 — is fair game for actual devices. That’s 254 usable addresses, matching the formula exactly.

Now suppose that one /24 needs to become four separate subnets — maybe for four different departments, each wanting its own segment for the security and broadcast-domain reasons covered back in Lesson 1.2.1. To make four subnets out of one, you borrow bits from the host portion. Four subnets needs 2 borrowed bits (2² = 4), turning your /24 into four /26 networks:

SubnetNetwork AddressBroadcast AddressUsable Range
1192.168.1.0192.168.1.63.1 – .62
2192.168.1.64192.168.1.127.65 – .126
3192.168.1.128192.168.1.191.129 – .190
4192.168.1.192192.168.1.255.193 – .254

Each of those four now holds 62 usable hosts instead of the original 254 — but you’ve gone from one flat network to four separate, isolated ones, each with its own network and broadcast address, each capable of enforcing its own policy at the boundary.

Diagram Showing A /24 Network Divided Into Four Equal /26 Subnets
Splitting A /24 Into Four /26 Subnets

Notice something about that four-way split: every subnet came out the exact same size, 62 hosts each. That’s fine when every department genuinely needs a similar number of addresses. It’s wasteful when they don’t — a department with 5 people and a department with 55 people would both get the same 62-host block, burning addresses on the smaller department for no reason. Fixing that unevenness is exactly what VLSM (Variable Length Subnet Masking) is for, letting different subnets use different prefix lengths sized to their actual needs. That’s the next lesson’s territory — for now, the key takeaway is that equal-sized subnetting like the example above is a starting point, not the only option.

Why Bother Subnetting at All

A few genuinely practical reasons drive this, beyond just “because the exam says so.”

Smaller broadcast domains, for one. Recall from Lesson 1.2.1 that broadcast traffic reaches every device in the domain, whether it’s wanted or not. A flat network of a thousand devices means every broadcast reaches all thousand. Split that into ten subnets of a hundred, and a broadcast in one subnet stays contained to that subnet alone — less noise, less wasted bandwidth, less unnecessary processing on every device.

Security and organization matter too. Subnets give you a natural boundary to apply firewall rules or ACLs against — the security appliances from Lesson 1.2.2 can filter traffic moving between subnets in ways that are much harder to enforce inside one flat, undivided network.

And there’s the address-efficiency point this lesson opened with. Subnetting means an organization doesn’t have to hand a whole /24 to a point-to-point link that only needs two addresses. A /30 does that job with zero waste.

A Common Mistake, Caught in the Act

Picture a technician configuring a new server on the 192.168.1.128/26 subnet from the table above. They type in 192.168.1.191 as the server’s address, and nothing works — the server can’t communicate with anything else on the network at all.

Look at the subnet again: 192.168.1.128 through 192.168.1.191 is the range, but 192.168.1.191 is the broadcast address for that specific subnet, not a usable host address. The technician picked the very last number in the range, assuming it was fair game the same way it would be in a /24 they were more used to working with. It isn’t. This exact mistake — grabbing the network or broadcast address by accident, especially in a subnet smaller than the default /24 — is one of the most common real-world subnetting errors, and it’s exactly why walking through the network and broadcast address explicitly, every time, is worth the extra thirty seconds.

Two Special Cases: /31 and /32

Two prefix lengths break the usual pattern, and they’re worth knowing specifically because they look like exceptions to the 2^n − 2 rule.

A /31 has just 1 host bit — normally that would round down to zero usable addresses after subtracting network and broadcast. But a specific standard (RFC 3021) allows /31 to be used anyway, treating both addresses as usable, specifically for point-to-point links where there’s no need for a broadcast address at all. It’s a deliberate exception, not a mistake.

A /32 identifies a single, specific host — no network portion left to subnet at all. You’ll see this show up in static routes pointing to one exact device, or in access control rules targeting a single IP precisely. Think of /32 as the far end of the same spectrum this whole lesson has been walking down — /8 covers millions of addresses, /24 covers a couple hundred, and /32 covers exactly one, with every step in between just adjusting how finely that address space gets sliced.

Recognition-Level Verification Concepts

This objective leans on calculation, but recognizing the pieces matters just as much as doing the math:

  • A subnet mask of 255.255.255.0 is /24 — instantly recognizable, and the most common LAN subnet you’ll encounter.
  • Any device configuration showing a subnet mask can be converted straight to CIDR by counting the consecutive 1-bits — 255.255.255.192 is /26, since 192 in binary is 11000000, adding 2 more 1-bits to the 24 already accounted for by the first three octets.
  • The lowest address in a range is the network address; the highest is the broadcast address — neither is ever assignable to a host.

Common Exam Traps

  • Forgetting to subtract 2 is the single most common subnetting mistake. 2^n alone gives you the total addresses in the subnet, not the usable ones — always subtract network and broadcast.
  • The network address and broadcast address are not usable hosts, even though they sit right at the edges of the range and are easy to mistake for the first and last assignable devices.
  • More network bits means a smaller subnet, not a bigger one. A /28 is smaller than a /24, not larger — it’s easy to instinctively read the higher number as “more” and get this backward.
  • /31 is a genuine, intentional exception for point-to-point links, not a mistake or a typo in a scenario question.
  • CIDR isn’t tied to the old class boundaries anymore. A /27 or /29 can be carved out of what used to be Class A, B, or C space — CIDR doesn’t care what class an address block would have belonged to under the old system.
  • Equal-sized subnetting isn’t the only option, and it isn’t always the right one. Splitting a network into equal blocks is simple, but wastes addresses when the actual devices needed per subnet vary a lot — the kind of unevenness VLSM exists to solve.
# Lesson 1.7.2 — Subnetting Fundamentals & CIDR Notation **Domain 1.0 | Networking Concepts — 23% of exam** ## Learning Objectives By the end of this lesson, you will be able to: - Explain what CIDR notation means and how it maps to a subnet mask - Calculate the number of usable host addresses in a given subnet - Identify the network address, broadcast address, and usable host range for a subnet - Explain why organizations subnet their networks instead of using one flat address block ## Key Terms | Term | Definition | |---|---| | CIDR (Classless Inter-Domain Routing) | A notation that specifies how many bits of an address are network bits, written as a slash followed by a number, like /24 | | Subnet Mask | A 32-bit value that marks which bits of an address are network bits and which are host bits | | Network Address | The first address in a subnet, representing the subnet itself rather than any individual device | | Broadcast Address | The last address in a subnet, used to reach every device in that subnet at once | | Host Bits | The bits left over after network bits are accounted for, used to number individual devices within a subnet | | Subnetting | Splitting one larger network into multiple smaller ones | ## Explanation ### Picking Up Where Classful Addressing Left Off [Lesson 1.7.1](https://networkustad.com/network-plus/lessons/lesson-1-7-1-ipv4-address-classes-special-ranges/) ended on a specific complaint: classful addressing wasted a lot of address space. A Class C network gave you 254 addresses, take it or leave it. A Class B gave you over 65,000, even if you only needed a few hundred. **CIDR** fixed that by letting a network be exactly the size it needs, instead of one of three fixed sizes. ### What CIDR Notation Actually Means CIDR notation looks like this: 192.168.1.0/24. That slash and number — the "/24" — tells you how many bits of the address are **network bits**. The rest are **host bits**, available for numbering individual devices. An IPv4 address is 32 bits total. So /24 means 24 network bits, leaving 8 host bits. /26 means 26 network bits, leaving just 6 host bits. More network bits means fewer host bits, and fewer host bits means fewer devices that particular subnet can hold. That trade-off is the entire game of subnetting. CIDR notation is really just a shorthand for a subnet mask, and you'll see both used interchangeably. | CIDR | Subnet Mask | Host Bits | |---|---|---| | /24 | 255.255.255.0 | 8 | | /25 | 255.255.255.128 | 7 | | /26 | 255.255.255.192 | 6 | | /27 | 255.255.255.224 | 5 | | /28 | 255.255.255.240 | 4 | | /29 | 255.255.255.248 | 3 | | /30 | 255.255.255.252 | 2 | [See Diagram: CIDR Notation and Subnet Masks] Memorizing this table cold pays off constantly, both on the exam and in real work. You'll see /24 and /30 especially often — /24 for typical LANs, /30 for point-to-point links between routers, since a link between exactly two devices only needs two usable addresses. Here's the binary underneath one of those rows, so the conversion isn't just a memorized table. Take 255.255.255.192. In binary, that last octet — 192 — is 11000000. Count the 1-bits: two of them. Add those two to the 24 bits already represented by the first three full octets (255.255.255), and you land on 26 total network bits. That's /26. Every mask in the table above works exactly the same way — count the 1-bits across all four octets, and that count is your CIDR prefix. ### Counting Hosts: The 2^n − 2 Rule Every subnet reserves two addresses that can't be assigned to a device. The **network address** — the very first address — represents the subnet itself. The **broadcast address** — the very last address — reaches every device in that subnet at once. Neither one can be handed out to an individual host. That gives you a simple formula: usable hosts equals 2 raised to the number of host bits, minus 2. A /24 has 8 host bits. 2^8 is 256. Subtract 2, and you get 254 usable addresses. A /26 has 6 host bits — 2^6 is 64, minus 2 is 62 usable addresses. Smaller subnets, predictably, hold fewer devices. [See Diagram: Usable Hosts by CIDR Prefix] ### Working Through a Real Example Take 192.168.1.0/24. The network address is 192.168.1.0. The broadcast address is 192.168.1.255. Everything in between — 192.168.1.1 through 192.168.1.254 — is fair game for actual devices. That's 254 usable addresses, matching the formula exactly. Now suppose that one /24 needs to become four separate subnets — maybe for four different departments, each wanting its own segment for the security and broadcast-domain reasons covered back in [Lesson 1.2.1](https://networkustad.com/network-plus/lessons/lesson-1-2-1-core-infrastructure-devices/). To make four subnets out of one, you borrow bits from the host portion. Four subnets needs 2 borrowed bits (2² = 4), turning your /24 into four /26 networks: | Subnet | Network Address | Broadcast Address | Usable Range | |---|---|---|---| | 1 | 192.168.1.0 | 192.168.1.63 | .1 – .62 | | 2 | 192.168.1.64 | 192.168.1.127 | .65 – .126 | | 3 | 192.168.1.128 | 192.168.1.191 | .129 – .190 | | 4 | 192.168.1.192 | 192.168.1.255 | .193 – .254 | Each of those four now holds 62 usable hosts instead of the original 254 — but you've gone from one flat network to four separate, isolated ones, each with its own network and broadcast address, each capable of enforcing its own policy at the boundary. [See Diagram: Subnetting a /24 into Four /26 Networks] Notice something about that four-way split: every subnet came out the exact same size, 62 hosts each. That's fine when every department genuinely needs a similar number of addresses. It's wasteful when they don't — a department with 5 people and a department with 55 people would both get the same 62-host block, burning addresses on the smaller department for no reason. Fixing that unevenness is exactly what VLSM (Variable Length Subnet Masking) is for, letting different subnets use different prefix lengths sized to their actual needs. That's the next lesson's territory — for now, the key takeaway is that equal-sized subnetting like the example above is a starting point, not the only option. ### Why Bother Subnetting at All A few genuinely practical reasons drive this, beyond just "because the exam says so." Smaller broadcast domains, for one. Recall from Lesson 1.2.1 that broadcast traffic reaches every device in the domain, whether it's wanted or not. A flat network of a thousand devices means every broadcast reaches all thousand. Split that into ten subnets of a hundred, and a broadcast in one subnet stays contained to that subnet alone — less noise, less wasted bandwidth, less unnecessary processing on every device. Security and organization matter too. Subnets give you a natural boundary to apply firewall rules or ACLs against — the security appliances from [Lesson 1.2.2](https://networkustad.com/network-plus/lessons/lesson-1-2-2-security-appliances/) can filter traffic moving between subnets in ways that are much harder to enforce inside one flat, undivided network. And there's the address-efficiency point this lesson opened with. Subnetting means an organization doesn't have to hand a whole /24 to a point-to-point link that only needs two addresses. A /30 does that job with zero waste. ### A Common Mistake, Caught in the Act Picture a technician configuring a new server on the 192.168.1.128/26 subnet from the table above. They type in 192.168.1.191 as the server's address, and nothing works — the server can't communicate with anything else on the network at all. Look at the subnet again: 192.168.1.128 through 192.168.1.191 is the range, but 192.168.1.191 is the **broadcast address** for that specific subnet, not a usable host address. The technician picked the very last number in the range, assuming it was fair game the same way it would be in a /24 they were more used to working with. It isn't. This exact mistake — grabbing the network or broadcast address by accident, especially in a subnet smaller than the default /24 — is one of the most common real-world subnetting errors, and it's exactly why walking through the network and broadcast address explicitly, every time, is worth the extra thirty seconds. ### Two Special Cases: /31 and /32 Two prefix lengths break the usual pattern, and they're worth knowing specifically because they look like exceptions to the 2^n − 2 rule. A **/31** has just 1 host bit — normally that would round down to zero usable addresses after subtracting network and broadcast. But a specific standard (RFC 3021) allows /31 to be used anyway, treating both addresses as usable, specifically for point-to-point links where there's no need for a broadcast address at all. It's a deliberate exception, not a mistake. A **/32** identifies a single, specific host — no network portion left to subnet at all. You'll see this show up in static routes pointing to one exact device, or in access control rules targeting a single IP precisely. Think of /32 as the far end of the same spectrum this whole lesson has been walking down — /8 covers millions of addresses, /24 covers a couple hundred, and /32 covers exactly one, with every step in between just adjusting how finely that address space gets sliced. ### Recognition-Level Verification Concepts This objective leans on calculation, but recognizing the pieces matters just as much as doing the math: - A subnet mask of 255.255.255.0 is /24 — instantly recognizable, and the most common LAN subnet you'll encounter. - Any device configuration showing a subnet mask can be converted straight to CIDR by counting the consecutive 1-bits — 255.255.255.192 is /26, since 192 in binary is 11000000, adding 2 more 1-bits to the 24 already accounted for by the first three octets. - The lowest address in a range is the network address; the highest is the broadcast address — neither is ever assignable to a host. ### Common Exam Traps - **Forgetting to subtract 2 is the single most common subnetting mistake.** 2^n alone gives you the total addresses in the subnet, not the usable ones — always subtract network and broadcast. - **The network address and broadcast address are not usable hosts**, even though they sit right at the edges of the range and are easy to mistake for the first and last assignable devices. - **More network bits means a smaller subnet, not a bigger one.** A /28 is smaller than a /24, not larger — it's easy to instinctively read the higher number as "more" and get this backward. - **/31 is a genuine, intentional exception** for point-to-point links, not a mistake or a typo in a scenario question. - **CIDR isn't tied to the old class boundaries anymore.** A /27 or /29 can be carved out of what used to be Class A, B, or C space — CIDR doesn't care what class an address block would have belonged to under the old system. - **Equal-sized subnetting isn't the only option, and it isn't always the right one.** Splitting a network into equal blocks is simple, but wastes addresses when the actual devices needed per subnet vary a lot — the kind of unevenness VLSM exists to solve. ## Summary - CIDR notation (like /24) specifies how many bits of an address are network bits, replacing the old rigid class system with flexible, exactly-sized subnets. - Usable hosts in a subnet equal 2 raised to the number of host bits, minus 2 — the minus 2 accounts for the network and broadcast addresses, which are never assignable. - The network address is the first address in a subnet; the broadcast address is the last; neither can be given to a device. - Subnetting shrinks broadcast domains, creates natural security boundaries, and avoids wasting address space on links that only need a couple of addresses. - /31 and /32 are special cases worth knowing — /31 for point-to-point links using both addresses, /32 for identifying one single host.
📝

Summary

CIDR notation (like /24) specifies how many bits of an address are network bits, replacing the old rigid class system with flexible, exactly-sized subnets.

Usable hosts in a subnet equal 2 raised to the number of host bits, minus 2 — the minus 2 accounts for the network and broadcast addresses, which are never assignable.

The network address is the first address in a subnet; the broadcast address is the last; neither can be given to a device.

Subnetting shrinks broadcast domains, creates natural security boundaries, and avoids wasting address space on links that only need a couple of addresses.

/31 and /32 are special cases worth knowing — /31 for point-to-point links using both addresses, /32 for identifying one single host.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.