Skip to content
MyIP.dog

DNS and routing

CIDR notation explained with IPv4 and IPv6 examples

Read CIDR notation, calculate prefix boundaries and address counts, and distinguish a subnet range from a routing or access-control rule.

Published:

How to read CIDR notation

CIDR notation writes an IP address followed by a slash and a prefix length, such as 192.0.2.0/24. The prefix length says how many leading address bits belong to the network prefix. The remaining bits describe positions within that range. A longer prefix produces a smaller block; a shorter prefix produces a larger one.

Use CIDR notation when reading network ranges, routes, firewall rules or subnet plans. The same format appears in these different contexts, but the surrounding operation determines what it does. Writing a range into a calculator only describes it. Writing it into an access rule may affect permissions, and writing it into routing configuration has different consequences again.

For a quick calculation, enter an address and prefix in the subnet calculator. Try the documentation example 192.0.2.130/26. The tool returns the containing network, boundaries and address count. CIDR notation becomes easier to understand when you can reproduce those values, rather than memorize a table without knowing how its boundaries are formed.

CIDR expands to Classless Inter-Domain Routing. It allows prefix lengths to describe allocation and routing without relying on the old class A, B and C boundaries. The architectural background is documented in RFC 4632. An address's first decimal number alone does not tell you the prefix used by a modern network.

CIDR notation for an interface and a network

CIDR notation can accompany a host's configured address, as in 192.0.2.130/26, or describe the normalized network block, 192.0.2.128/26. These strings do not play identical roles: the first retains host bits, while the second clears them to identify the block. Some tools accept both and normalize; strict policy editors may reject the first.

Before applying CIDR notation in configuration, check whether the field expects an interface address, a network, or a single host. Do not silently substitute one for another. Our calculator intentionally accepts an address within a range and reports its containing network, so its output can help you see the distinction before using another system's stricter input format.

CIDR notation for IPv4

An IPv4 address has thirty-two bits. For a prefix length p, its block contains 2^(32-p) addresses. In CIDR notation, /24 leaves eight variable bits and therefore 256 addresses; /26 leaves six and therefore 64. Those are total address counts, not promises that every value is assignable to an ordinary device.

In the example 192.0.2.130/26, the last octet is 10000010 in binary. The prefix keeps its first two bits and leaves six host bits. Clearing those six bits gives 10000000, or 128. Setting them all gives 10111111, or 191. CIDR notation therefore describes the block from 192.0.2.128 through 192.0.2.191.

The equivalent mask for that CIDR notation is 255.255.255.192. Each leading one bit belongs to the prefix, and each remaining zero bit belongs to the variable portion. Bitwise AND between an address and this contiguous mask produces the network address. A dotted mask and a prefix length are two ways to describe the same boundary in this example.

Compare CIDR notation across prefix sizes

The following CIDR notation examples use documentation addresses. They are arithmetic examples for learning, not networks you should contact or assign to a production interface. Notice how adding one prefix bit halves the block size while keeping the alignment requirement.

IPv4 examples: total addresses and masks

PrefixMaskTotalRange
192.0.2.0/24255.255.255.0256192.0.2.0–192.0.2.255
192.0.2.128/25255.255.255.128128192.0.2.128–192.0.2.255
192.0.2.128/26255.255.255.19264192.0.2.128–192.0.2.191
192.0.2.128/27255.255.255.22432192.0.2.128–192.0.2.159

For a conventional broadcast-capable IPv4 subnet, the network and directed-broadcast values are usually excluded from ordinary host assignment. The /26 example then has 62 such positions, from .129 to .190. CIDR notation itself only supplies the range; a platform can reserve additional values, and its configuration rules still determine what can be assigned.

The /31 and /32 exceptions in CIDR notation

Do not apply “subtract two” to every CIDR notation calculation. On an IPv4 point-to-point link using /31, both addresses can identify endpoints under the rules of RFC 3021. A /32 describes exactly one IPv4 address and is often used to identify a host route or a single-address match.

At the other extreme, 0.0.0.0/0 covers the full IPv4 address space. In a routing context, that can describe a default route's destination prefix. In an access-control context, the same CIDR notation can match any IPv4 source or destination. Neither use means that every address is reachable, assignable or appropriate for the policy you are editing.

CIDR notation for IPv6

IPv6 uses 128-bit addresses, so its block-size expression is 2^(128-p). CIDR notation works with the same leading-bit idea, but the address is normally written in hexadecimal with colon separators. A /64 leaves sixty-four variable bits. Avoid converting that large count into a floating-point approximation when you need an exact result.

For example, CIDR notation 2001:db8:1234:5678::1/64 belongs to 2001:db8:1234:5678::/64. The first four sixteen-bit groups form the prefix. The final sixty-four bits range from all zeroes to all ones, giving exactly 18,446,744,073,709,551,616 address positions. That number describes the block's mathematical size, not an inventory of machines.

IPv6 has no broadcast addresses. Do not copy the ordinary IPv4 network-and-broadcast subtraction into CIDR notation for IPv6. Address architecture, interface identifiers, link type and implementation rules still matter when deciding how a prefix is used. IPv6 addressing architecture

An IPv6 /128 describes one address. A /127 contains two and has a specified use on inter-router point-to-point links in RFC 6164. These examples do not imply that /127 is a general replacement for the prefixes expected by ordinary client networks and their address-configuration mechanisms.

When reading CIDR notation, remember that text compression and prefix length are separate. The :: abbreviation replaces zero groups in the address; it does not tell you how many network bits were configured. The slash value supplies that information. Two differently formatted strings can describe the same numeric address or the same normalized prefix.

CIDR notation in routes and access rules

A route associates a destination prefix with forwarding information. Among applicable destination routes, a more specific matching prefix generally takes precedence under longest-prefix matching. CIDR notation lets you distinguish a broad destination block from a narrower one. Additional routing policy can affect which table and routes are considered, so the prefix is not the whole configuration.

An access rule uses CIDR notation to describe a set of addresses for matching, but the effect depends on the product's rule evaluation. An allow rule and a deny rule can contain the same prefix and have opposite intentions. Rule order, priority, direction, protocol and ports may also matter. Review the complete rule rather than the slash number alone.

If the intention is one IPv4 host, CIDR notation ending in /32 expresses that one-address set. Replacing it with /24 expands the set to 256 addresses. Likewise, changing an IPv6 /128 to /64 greatly expands the match. Use the calculator to inspect the range before saving an access change, then test the actual intended policy separately.

Overlapping ranges are not necessarily an error. A narrow route can intentionally sit within a larger route, and a policy may have specific exceptions. CIDR notation makes that overlap measurable. Record which addresses each rule includes and what precedence applies in the system you operate instead of assuming the more visually prominent rule wins.

Splitting and combining blocks in CIDR notation

Splitting CIDR notation 192.0.2.0/24 into four equal /26 blocks produces starts at .0, .64, .128 and .192. Each block contains 64 addresses. The starts follow from the block size, not an arbitrary choice of four convenient-looking numbers. Together, those aligned blocks cover the original range without gaps or overlaps.

Combining blocks requires alignment as well as adjacency. The two ranges 192.0.2.0/25 and 192.0.2.128/25 combine into 192.0.2.0/24. Two adjacent blocks that straddle a larger boundary may need several prefixes instead. A shorter CIDR notation summary can unintentionally include extra addresses if you ignore that boundary.

For a concrete misalignment, 192.0.2.64/26 and 192.0.2.128/26 are adjacent but do not form one /25. Their combined interval runs from .64 through .191, while the aligned /25 boundaries start at .0 or .128. Keep the two prefixes if the objective is exactly those addresses; a broader summary changes the set.

CIDR notation questions and common mistakes

Does /24 mean twenty-four devices? No. CIDR notation /24 means twenty-four leading prefix bits. In IPv4 it leaves eight variable bits and 256 total addresses. The number of devices you can actually connect also depends on assignments, reservations, equipment and network policy, not just this arithmetic.

Can I omit the slash number? An address without a prefix does not supply the same range information. A tool may assume a default, but that assumption should be explicit. For CIDR notation input here, include the slash and a valid family-specific length so the calculator can reproduce the range you intended.

Does a calculated range reveal who owns it? No. CIDR notation is a mathematical description. Use IP WHOIS lookup for registry information and ASN lookup for observed routing context. Registration, routing and a local subnet plan answer different questions and can use different boundaries.

Does a subnet calculation prove connectivity? No. CIDR notation can show whether addresses fall within a range without sending traffic anywhere. It does not test a gateway, firewall, service or remote route. Combine the calculation with the specific configuration and measurements needed for your task, keeping arithmetic separate from live evidence.

To apply CIDR notation to a whole interval or network list, open the CIDR calculator. It converts ranges into exact prefix covers, combines networks while preserving gaps, and divides parents into equal children. Its normalization notices show when a host address becomes a network boundary. CIDR notation describes the resulting sets; a calculation does not configure or authorize a route.