Toolbit
Guides

VLSM Step by Step: A Worked Example

A complete VLSM exercise on a /24 with six subnets of different sizes: block sizing, assignment order, and what to do when the address space runs out.

By Javier VallejoPublished 6 min read

The problem VLSM solves

Splitting a network into equal parts is easy, but it almost never matches reality. A typical office has one department with a hundred devices, another with fifty, a couple of small teams, and several router-to-router links that only need two addresses each. Carve everything into same-size blocks and you have to size them for the largest department — which means every point-to-point link ends up burning a 128-address block to use two.

VLSM (Variable Length Subnet Masking) fixes that by letting each subnet have its own prefix length. This guide works through a complete exercise from start to finish, explains why assignment order matters, and shows what to do when the address space runs out. If network address, broadcast, and block size aren't fresh in your mind, start with Subnetting from the Bits: How to Calculate a Subnet by Hand first.

The exercise

You've been given 192.168.50.0/24 (256 addresses) and need subnets for the following:

SubnetHosts needed
Sales100
Engineering50
Support25
Management10
WAN link 12
WAN link 22

The goal: give each subnet the smallest block that fits its hosts, with no overlaps, and keep the leftover space as contiguous as possible so there's room to grow.

Step 1: work out each subnet's block

Every subnet needs its hosts plus two addresses — one for the network and one for the broadcast. Round that total up to the next power of 2, because CIDR blocks only come in those sizes. The prefix follows from how many host bits you need: a block of 2ʰ addresses has a prefix of /(32 − h).

SubnetHostsHosts + 2BlockPrefixUsable hostsWaste
Sales100102128/2512626
Engineering505264/266212
Support252732/27305
Management101216/28144
WAN link 1244/3020
WAN link 2244/3020

Before assigning anything, check that it all fits: 128 + 64 + 32 + 16 + 4 + 4 = 248 addresses, and the base network has 256. That leaves 8 to spare, so the exercise is solvable. If the total were over 256, no assignment order in the world would make it work.

Step 2: sort from largest to smallest

This is the step that decides whether the result comes out clean or fragmented. A block of size 2ᵏ can only start at an address that's a multiple of 2ᵏ: a /25 starts at .0 or .128; a /26 at .0, .64, .128, or .192; and so on. It's the same rule that makes a network address have all its host bits set to zero.

Assign the big blocks first and each subsequent block starts exactly where the previous one ended — and that address is already a multiple of its size, because everything assigned before it is a multiple of larger blocks. Start with the small ones and you get gaps. Say WAN link 1 takes 192.168.50.0/30: the next free address is .4, but a /25 can't start at .4. Apply the 255.255.255.128 mask to .4 and you get .0, which is already taken. Sales would have to move to .128, leaving the space between .4 and .127 broken into pieces you'd have to fit together by hand.

Step 3: assign in order

With the list sorted, assign each block starting from the first free address:

Sales (/25, 128 addresses). Starts at 192.168.50.0. The broadcast is the last address in the block: .0 + 128 − 1 = .127. Hosts .1 through .126. Next free: .128.

Engineering (/26, 64 addresses). Starts at .128, which is a multiple of 64. Broadcast .128 + 63 = .191. Hosts .129 through .190. Next free: .192.

Support (/27, 32 addresses). Starts at .192. Broadcast .223. Hosts .193 through .222. Next free: .224.

Management (/28, 16 addresses). Starts at .224. Broadcast .239. Hosts .225 through .238. Next free: .240.

WAN link 1 (/30, 4 addresses). Starts at .240. Broadcast .243. Hosts .241 and .242. Next free: .244.

WAN link 2 (/30, 4 addresses). Starts at .244. Broadcast .247. Hosts .245 and .246. Next free: .248.

The complete result

SubnetNetworkMaskFirst hostLast hostBroadcast
Sales192.168.50.0/25255.255.255.128.1.126.127
Engineering192.168.50.128/26255.255.255.192.129.190.191
Support192.168.50.192/27255.255.255.224.193.222.223
Management192.168.50.224/28255.255.255.240.225.238.239
WAN link 1192.168.50.240/30255.255.255.252.241.242.243
WAN link 2192.168.50.244/30255.255.255.252.245.246.247

That's 248 of 256 addresses in use (96.9% utilization), with 192.168.50.248 through .255 still free — a contiguous /29 with 6 usable hosts, ready for a future link or a small team. Total waste, counting the gap between usable and requested hosts, is 47 addresses. Equal /25 subnets, by comparison, wouldn't even cover all six requirements.

To check the result, enter the base network and all six requirements into the VLSM calculator in any order: the tool sorts them largest-first on its own and should return exactly this table. Any individual row can be inspected in detail with the subnet calculator.

Variation: when the space runs out

Now suppose Sales needs 130 hosts instead of 100. With 132 addresses required, the block jumps to 256 — an entire /24. Sales would take over the whole base network, leaving no room for Engineering, Support, or anyone else. The block total (256 + 64 + 32 + 16 + 4 + 4 = 376) exceeds the 256 available, and Step 1 catches that before you assign a single subnet.

There are three usual ways out:

  • Ask for a larger base network, such as a /23 (512 addresses).
  • Split the large requirement into two subnets (two /25s of 126 hosts each), if the design allows it.
  • Revisit the numbers: sometimes those 130 hosts include printers or devices that belong on a different subnet anyway.

The VLSM calculator flags this case with an insufficient-space warning and tells you how many addresses you're short.

Common VLSM mistakes

  • Forgetting to add 2 before rounding. 30 hosts fit in a /27 (30 usable), but 31 hosts already need a /26.
  • Rounding to the wrong block size. 100 hosts is not a /26 (62 usable): the block has to cover the usable hosts, not just the total address count.
  • Assigning in the order given. Exercises list requirements out of size order on purpose — sorting is part of the problem.
  • Overlapping blocks. If one subnet's broadcast is greater than or equal to the next subnet's network address, something went wrong.
  • Using /31 without checking the hardware. /31 links (RFC 3021) save two addresses, but not every device supports them. /30 remains the safe default.

Summary

VLSM always comes down to the same sequence: work out each subnet's block (hosts + 2, rounded up to a power of 2), confirm the total fits in the base network, sort largest to smallest, and assign contiguously. The ordering isn't a style choice — it's what guarantees every block lands aligned to its own size, with no gaps.

Tools used in this guide

Related guides