IP Addressing and Subnetting

IP Addressing and Subnetting

Definition: IP addressing is the logical addressing scheme (IPv4 or IPv6) that uniquely identifies hosts on a network; subnetting, expressed via CIDR notation, partitions an address space into smaller routable networks.

How It Works

An IPv4 address is 32 bits, written as four decimal octets (192.168.1.1), each 0-255. An IPv6 address is 128 bits, written as eight groups of four hex digits (2001:0db8:0000:0000:0000:0000:0000:0001), commonly abbreviated by collapsing one run of zero groups with :: (2001:db8::1).

Every address splits into a network portion and a host portion. CIDR (Classless Inter-Domain Routing) notation marks the boundary with a slash: 192.168.1.0/24 means the first 24 bits are the network ID, leaving 8 bits (256 addresses) for hosts. The subnet mask is the same idea expressed as a dotted address: /24 = 255.255.255.0.

To determine if a destination is on the local subnet or needs routing, a host performs a bitwise AND of its own IP and the subnet mask, and compares it to the same AND applied to the destination IP. Same result means same subnet (deliver directly via ARP/Layer 2); different result means send to the default gateway.

Within a subnet, two addresses are reserved: the network address (all host bits 0, identifies the subnet itself) and the broadcast address (all host bits 1, reaches every host on the subnet). That’s why a /24 has 256 total addresses but only 254 usable host addresses.

Under the Hood

Usable hosts per prefix length (IPv4):

PrefixSubnet maskTotal addressesUsable hosts
/30255.255.255.25242
/29255.255.255.24886
/24255.255.255.0256254
/16255.255.0.065,53665,534
/8255.0.0.016,777,21616,777,214

Formula: usable hosts = 2^(32 - prefix) - 2 (the -2 accounts for network and broadcast addresses; point-to-point links commonly use /31, which RFC 3021 exempts from this rule, treating both addresses as usable).

Private (RFC 1918) IPv4 ranges, never routed on the public internet, reserved for use behind NAT:

  • 10.0.0.0/8
  • 172.16.0.0/12
  • 192.168.0.0/16

IPv6 addressing works differently from IPv4 in ways that matter: it drops NAT as a necessity (address space is large enough for every device to have a globally unique address), uses a 64-bit interface identifier by convention (often derived from the MAC address via EUI-64, or randomized for privacy), and reserves fe80::/10 for link-local addresses that every interface auto-configures regardless of any router. IPv6 has no broadcast at all, only unicast, multicast, and anycast.

Subnetting math in practice: to carve a /24 into four equal subnets, borrow 2 bits from the host portion to get four /26 networks (.0/26, .64/26, .128/26, .192/26), each with 64 addresses (62 usable). VLSM (Variable Length Subnet Masking) extends this to carve unequal-sized subnets from the same block based on actual host count needed per segment, avoiding waste.

Worked Subnetting Example

Given 172.16.0.0/22 and a need for four equally sized subnets:

  1. A /22 has 10 host bits (32 - 22). Splitting into 4 subnets means borrowing 2 bits, moving to /24.
  2. That yields four /24 blocks: 172.16.0.0/24, 172.16.1.0/24, 172.16.2.0/24, 172.16.3.0/24.
  3. Each /24 gives 254 usable host addresses (256 total, minus network and broadcast).
  4. If one segment actually only needs 20 hosts, VLSM lets you instead carve it as a /27 (30 usable hosts) and return the rest of that range to the available pool instead of wasting an entire /24 on it.

This borrow-bits-from-the-host-portion approach is the core mechanical skill behind subnetting exam questions and real allocation work alike, the only real risk is losing track of which bits have already been borrowed when subnets are further subdivided.

IPv4 Exhaustion and IPv6 Adoption Timeline

  • IPv4’s ~4.3 billion addresses seemed inexhaustible in the 1980s but were visibly running low by the early 2000s as internet growth, especially mobile devices, accelerated demand far beyond original projections.
  • IANA allocated its last remaining IPv4 address blocks to the five Regional Internet Registries in February 2011. Individual RIRs exhausted their free pools over the following years (APNIC in 2011, RIPE NCC in 2012, ARIN in 2015), after which new allocations came only from returned or reclaimed space, or paid transfer markets.
  • IPv6 was standardized far earlier than the exhaustion crisis (RFC 1883 in 1995, refined as RFC 8200 in 2017) specifically to head this off, but adoption lagged for years because IPv6 isn’t backward-compatible with IPv4 and required dual-stack support across an enormous installed base of hardware and software before it was practical to rely on.
  • CGNAT and RFC 1918 private addressing became the dominant short-term workaround, stretching remaining IPv4 space rather than forcing a hard cutover, which is part of why IPv6 adoption, while steadily climbing (over 40% of Google’s measured traffic by the mid-2020s), still isn’t universal decades after standardization.

Why It Matters

Addressing and subnetting are what make routing scale. Without hierarchical, aggregatable address blocks, every router on the internet would need a route to every individual host, instead they need routes to aggregated prefixes (like 8.8.8.0/24), collapsing millions of addresses into a single routing table entry. Subnetting inside an organization does the same at smaller scale: it isolates broadcast domains, applies security boundaries, and matches IP allocation to actual topology.

Common Pitfalls

  • Off-by-one host count errors: forgetting to subtract the network and broadcast addresses when sizing a subnet.
  • Over-allocating: assigning a /24 to a segment that only needs 10 hosts, wasting address space and enlarging the broadcast domain unnecessarily.
  • Under-allocating: sizing a subnet exactly to current headcount with no room to grow, forcing a disruptive re-addressing project later.
  • Mismatched subnet masks between two hosts meant to communicate directly, one thinks the other is local, the other thinks it needs the gateway, causing asymmetric or broken connectivity.
  • Confusing a “slash” prefix as a hard boundary that must align to nice numbers, valid CIDR blocks require the prefix’s network portion to be on a proper bit boundary, you can’t have 192.168.1.10/24 as a network id, only as a host address within 192.168.1.0/24.
  • Treating IPv6 like IPv4 with longer addresses, e.g. trying to conserve IPv6 addresses or design tight subnets, when the standard practice is generous allocation (a /64 per LAN segment) because scarcity isn’t the constraint it was with IPv4.
  • Overlapping address ranges when merging two networks (e.g. after a company acquisition, or connecting two sites via VPN), both sides using 192.168.1.0/24 independently means one side has to be renumbered before routing between them works at all.
  • Forgetting that a subnet mask must be identical across every host on the same logical subnet, a single misconfigured host with a narrower mask will believe part of its own subnet is remote and route those packets to the gateway unnecessarily.

Comparison

IPv4IPv6
Address size32 bits128 bits
NotationDotted decimalHex, colon-separated
Address space~4.3 billion~340 undecillion
BroadcastYesNo (multicast/anycast only)
NATCommon, often requiredGenerally unnecessary
AutoconfigurationDHCP (stateful)SLAAC (stateless) or DHCPv6

Debugging an Addressing/Subnetting Issue

A host that can reach some machines on the network but not others, or that unexpectedly routes local traffic through the gateway, usually traces back to an addressing mismatch:

  1. ipconfig (Windows) or ip addr (Linux) confirms the host’s actual assigned IP and subnet mask, don’t assume it matches what a config file says, DHCP or manual misconfiguration can diverge from expectations.
  2. Manually compute the network address (IP AND mask) for both the host and the machine it’s failing to reach. If they differ, the host will try to route through the gateway instead of ARPing directly, if the two machines are actually meant to be on the same physical segment, that’s the bug.
  3. ping a known-good host on the same subnet to confirm basic Layer 3 reachability before assuming the problem is subnetting-specific.
  4. On a router or Layer 3 switch, show ip route (or the vendor equivalent) confirms whether a route to the target subnet exists at all, a missing route produces “destination unreachable,” not a timeout.
  5. A subnet calculator (or ipcalc on Linux) is worth using to double check hand math on interview-style questions or unfamiliar prefix lengths, off-by-one errors in usable host counts are common enough to always verify.

Example

ipconfig (Windows) or ip addr (Linux) shows a host’s assigned IP and subnet mask. A cloud VPC commonly uses 10.0.0.0/16 as its overall range, then splits it into /24 subnets per availability zone, e.g. 10.0.1.0/24, 10.0.2.0/24, giving each zone 254 usable addresses while keeping the whole VPC’s routing table compact.

FAQ

Why can’t a host use the network or broadcast address as its own IP? The network address identifies the subnet as a whole (used in routing tables), and the broadcast address is reserved to reach every host on the subnet at once, assigning either to a single host would make both mechanisms ambiguous.

Is /31 really usable, doesn’t it have zero usable hosts by the normal formula? RFC 3021 carves out a specific exception for point-to-point links: with only two addresses total and no need for a broadcast address on a link with exactly two endpoints, both addresses are treated as usable.

Why do private IP ranges exist at all if NAT is going to hide them anyway? They guarantee that internal addressing never collides with public internet addresses, so a NAT gateway can safely rewrite them without any router elsewhere ever needing to route to 10.x.x.x directly.

Do IPv6 addresses need subnetting the same way? Conceptually yes, but practically it’s simpler: the convention is to allocate a /64 to every LAN segment regardless of host count, since the address space per subnet (2^64) is effectively inexhaustible, removing the tight host-count optimization that drives IPv4 subnetting decisions.

Dig deeper