Toolbit
Guides

Subnetting from the Bits: How to Calculate a Subnet by Hand

Work out the network, broadcast, mask, and host range of any IPv4 subnet straight from the bits, with two step-by-step worked examples.

By Javier VallejoPublished 7 min read

Why learn subnetting from the bits up

Most subnetting shortcuts — memorized charts, "magic numbers," the 256 rule — work fine until a problem doesn't fit the mold: a prefix that cuts through the second octet, an address that sits right on a block boundary, a mask written in an unusual way. When that happens, the only reliable way to get the right answer is to do what a router actually does: compare bits. This guide builds the whole calculation from scratch, with two worked examples and a method for splitting a network into several subnets. By the end, every shortcut reads as a logical consequence rather than a rule to memorize.

An IPv4 address is 32 bits in groups of 8

An address like 192.168.10.77 is just a human-friendly way to write a 32-bit number. Each of the four dot-separated numbers is an octet: 8 bits that can hold any value from 0 to 255. To convert an octet to binary, you only need the weight of each bit position:

Bit position87654321
Weight1286432168421

Walk the table from left to right and write a 1 whenever the weight fits into what's left of the number. For 77: 128 doesn't fit (0); 64 does (1, leaving 13); 32 doesn't (0); 16 doesn't (0); 8 does (1, leaving 5); 4 does (1, leaving 1); 2 doesn't (0); 1 does (1). That gives 01001101. Do the same for the other three octets and the full address looks like this:

192      .168      .10       .77
11000000 .10101000 .00001010 .01001101

If you want to double-check a conversion, the base converter shows the same value in binary, grouped into nibbles.

The prefix is a boundary, not a magic number

The CIDR prefix (/26 in 192.168.10.77/26) says how many bits, counting from the left, belong to the network. Everything after that belongs to the host. With /26, the first 26 bits identify the subnet and the last 6 identify each device inside it:

The subnet mask is that same boundary written as an address: 26 ones followed by 6 zeros. In decimal, 11111111.11111111.11111111.11000000 is 255.255.255.192. Because the ones are always contiguous and left-aligned, a mask octet can only ever take one of nine values:

Network bits in the octetOctet in binaryDecimal valueBlock size
0000000000256
110000000128128
21100000019264
31110000022432
41111000024016
5111110002488
6111111002524
7111111102542
8111111112551

Any other value — 255.255.255.160, for instance, which is 10100000 in binary — is not a valid mask, because there's a zero sitting between the ones.

Example 1: 192.168.10.77/26

Network address: IP AND mask

To figure out which network an address belongs to, a router performs a bitwise AND between the IP and the mask: the result has a 1 only where both inputs have a 1. The first three mask octets are 255 (all ones), so those octets pass through unchanged. All the work happens in the fourth octet:

IP       77  = 01001101
Mask    192  = 11000000
AND          = 01000000  = 64

The network address is 192.168.10.64. Put another way: keep the network bits, zero out every host bit.

Broadcast: network OR wildcard

The wildcard is the inverted mask: 0.0.0.63. A bitwise OR between the network address and the wildcard sets every host bit to one — which is exactly the broadcast address:

Network  64  = 01000000
Wildcard 63  = 00111111
OR           = 01111111  = 127

The broadcast is 192.168.10.127. Usable hosts are everything in between: 192.168.10.65 through 192.168.10.126, which is 2⁶ − 2 = 62 hosts.

The block-size shortcut, explained

The table above gives you a shortcut that reaches the same answer without writing out any bits: the block size is 256 − 192 = 64, so /26 subnets start at multiples of 64 (0, 64, 128, 192). Since 77 falls between 64 and 127, the network is .64 and the broadcast is the last value before the next block, .127. The shortcut works because 6 host bits give exactly 64 combinations: each block is one full sweep of those bits, from all zeros to all ones.

Example 2: when the boundary lands in another octet (172.16.45.200/20)

A /20 leaves 20 network bits: 8 from the first octet, 8 from the second, and 4 from the third. The mask is 255.255.240.0, and now the "interesting" octet is the third one, not the fourth.

Third IP octet     45  = 00101101
Mask              240  = 11110000
AND                    = 00100000  = 32

The fourth mask octet is 0, so it's zeroed out in the network address. The network is 172.16.32.0. The block size in the third octet is 256 − 240 = 16, so this subnet spans third-octet values 32 through 47. The broadcast sets every host bit to one — the 4 in the third octet and all 8 in the fourth: 172.16.47.255.

FieldValue
Network172.16.32.0
First host172.16.32.1
Last host172.16.47.254
Broadcast172.16.47.255
Usable hosts2¹² − 2 = 4094

Here's a detail that trips up a lot of people: 172.16.40.0 and 172.16.32.255 are perfectly valid host addresses inside this subnet. An octet ending in 0 or 255 means nothing on its own; what matters is whether all the host bits are zeros or ones.

You can check both examples in the calculator with the values already filled in: 192.168.10.77/26 and 172.16.45.200/20. The calculator also shows the binary notation with the prefix boundary highlighted.

Splitting a network into N equal subnets

The reverse problem comes up just as often: you have 192.168.10.0/24 and need 4 equal subnets. Every bit you move from the host part to the network part doubles the number of subnets, so you need n bits such that 2ⁿ ≥ 4. With n = 2, the prefix goes from /24 to /26:

SubnetNetworkHost rangeBroadcast
1192.168.10.0/26.1 – .62.63
2192.168.10.64/26.65 – .126.127
3192.168.10.128/26.129 – .190.191
4192.168.10.192/26.193 – .254.255

The two "borrowed" bits take the values 00, 01, 10, and 11, and that's what produces the four blocks. If you needed 5 subnets instead of 4, two bits are no longer enough (2² = 4), so you take three: the prefix becomes /27, giving 8 subnets of 30 hosts each. The three you don't use are left free for growth.

When subnets need different sizes — one with 100 hosts, another with 50, a handful of 2-host links — splitting into equal parts wastes addresses. That's what VLSM is for, and it's covered step by step in VLSM Step by Step: A Worked Example.

Common mistakes

  • Confusing the network address with the first host. 192.168.10.64 identifies the subnet itself; it never gets assigned to a device. The first host is .65.
  • Forgetting to subtract 2. A /26 has 64 addresses but 62 hosts. The exceptions are /31 (RFC 3021, point-to-point links, 2 hosts) and /32 (a single host).
  • Assuming networks break on octet boundaries. Class A, B, and C addressing went away with CIDR in 1993 (RFC 1519, later updated by RFC 4632). A /20 or a /27 is every bit as normal as a /24.
  • Writing non-contiguous masks. If an octet isn't one of the nine values in the table, the mask is wrong.
  • Computing the broadcast by adding the block size to the host IP. The broadcast is calculated from the network, not from the host address: 64 + 64 − 1 = 127, not 77 + 64.

Summary

Every IPv4 subnet comes down to two operations: AND with the mask to get the network, OR with the wildcard to get the broadcast. The block size is a shortcut for skipping the bit-level work, and it holds because each block runs through every combination of the host bits. Once that clicks, any prefix from /8 to /30 is solved exactly the same way.

Tools used in this guide

Related guides