Blog

Networking articles

CIDR Notation: What /24, /27 and /30 Mean

CIDR notation decoded: what the slash number means, a quick reference table from /8 to /32, and how CIDR ranges appear in firewalls and cloud rules.

4 min read Networking

Firewall rules, cloud security groups, VPN settings and hosting control panels all ask for IP ranges written like 10.0.0.0/16 or 203.0.113.8/29. That format is CIDR notation, and the number after the slash is the key to the whole thing. Read it correctly and you know exactly how many addresses a rule covers; misread it and you might open a database to the entire internet.

What CIDR notation means

CIDR stands for Classless Inter-Domain Routing, the addressing scheme defined in RFC 4632 that replaced the old fixed "Class A, B, C" networks in the 1990s. A CIDR block has two parts:

  • A starting IP address, such as 192.168.4.0.
  • A prefix length after the slash, such as /24.

The prefix length says how many of the 32 bits in an IPv4 address are fixed. Those fixed bits identify the network; the remaining bits are free to vary and identify individual addresses within the block. So /24 means the first 24 bits are fixed and 8 bits vary, giving 2 to the power of 8, or 256, addresses.

The rule to remember: every step up in the prefix halves the block; every step down doubles it. A /25 is half of a /24 (128 addresses); a /23 is two /24s (512 addresses).

CIDR quick reference table

CIDRSubnet maskTotal addressesUsable hostsTypical use
/8255.0.0.016,777,21616,777,214Whole private range 10.0.0.0/8
/16255.255.0.065,53665,534Cloud virtual network, large campus
/20255.255.240.04,0964,094Large cloud subnet
/22255.255.252.01,0241,022Large office or Wi-Fi network
/24255.255.255.0256254Typical office or home LAN
/25255.255.255.128128126Half a /24
/26255.255.255.1926462Department or VLAN
/27255.255.255.2243230Small server segment
/28255.255.255.2401614Small public IP block from an ISP
/29255.255.255.24886Small business static IP block
/30255.255.255.25242Point-to-point link
/31255.255.255.25422 (special case)Point-to-point link without waste
/32255.255.255.25511A single host

"Usable hosts" subtracts the network and broadcast addresses, which ordinary subnets reserve. Note that cloud providers often reserve a few extra addresses in each subnet for their own routers and DNS, so the real usable count there is slightly lower; check your provider's documentation.

Reading the three examples in the title

/24: the familiar office network

192.168.1.0/24 covers 192.168.1.0 to 192.168.1.255. Only the last number changes. This is the default for most home and small-office routers.

/27: thirty usable addresses

192.168.1.64/27 covers 32 addresses, .64 to .95. The network address is .64, broadcast is .95, and .65 to .94 are assignable. A /27 block must start on a multiple of 32 (0, 32, 64, 96…), so 192.168.1.70/27 is not a valid network start; it is simply an address inside the .64/27 block.

/30: just enough for a link

10.255.0.4/30 holds four addresses: network .4, usable .5 and .6, broadcast .7. That is exactly enough for two routers connected to each other, which is why /30 was traditionally used for WAN links. Many modern routers support /31 on such links instead, as described in RFC 3021, using both addresses and wasting none.

CIDR notation in firewall and cloud rules

This is where getting CIDR wrong has real consequences:

  • 203.0.113.25/32 means one specific address. Use this when allowing a single office IP to reach SSH or a database. You can find your office's current public address with What Is My IP.
  • 203.0.113.0/24 allows 256 addresses, which may include other customers of the same ISP.
  • 0.0.0.0/0 means every IPv4 address. It is correct for a public website on ports 80 and 443, and dangerous for anything else. A rule allowing 0.0.0.0/0 on port 3306 (MySQL) or 3389 (Remote Desktop) exposes that service to the whole internet.
  • ::/0 is the IPv6 equivalent of "everything". If you lock down IPv4 but leave an IPv6 rule open, the service is still exposed.

When you see an unfamiliar range in a rule, paste it into a subnet calculator to see the first and last address it covers before approving it.

Converting a prefix to a mask in your head

You do not need to memorize the whole table. Split the prefix into whole octets and a remainder. Every complete group of 8 bits is 255. For the remaining bits, the octet value follows a fixed sequence: 1 bit is 128, 2 bits 192, 3 bits 224, 4 bits 240, 5 bits 248, 6 bits 252, 7 bits 254. Any octets after that are 0.

Example: /20 is two full octets (16 bits) plus 4 bits, so the mask is 255.255.240.0. The block size in the third octet is 256 − 240 = 16, so /20 networks start at x.x.0.0, x.x.16.0, x.x.32.0 and so on, each spanning 16 × 256 = 4,096 addresses.

Going the other way, to find the prefix from a mask, count the 1 bits: 255.255.255.248 is 8 + 8 + 8 + 5 = 29, so it is a /29.

Combining ranges (route aggregation)

CIDR also lets adjacent blocks be written as one. 192.168.0.0/24 and 192.168.1.0/24 together form 192.168.0.0/23. This only works when the blocks are contiguous and the combined block starts on a valid boundary: 192.168.1.0/24 plus 192.168.2.0/24 cannot be merged into a single /23. Aggregation keeps routing tables and firewall rule lists shorter.

CIDR in IPv6

IPv6 uses the same slash notation with 128-bit addresses. The numbers are much larger, and conventions differ: a single network segment is normally a /64, and a site commonly receives a /48 or /56 from its provider. A /128 is one address, the IPv6 equivalent of a /32.

Key takeaways

  • The number after the slash is how many bits are fixed; the rest vary.
  • Each +1 halves the block size: /24 is 256 addresses, /27 is 32, /30 is 4, /32 is one.
  • In firewall rules, prefer /32 for single trusted IPs and treat 0.0.0.0/0 and ::/0 with great care.
  • Blocks must start on a multiple of their size; check unfamiliar ranges with a calculator.

Need help with this?

Netifi helps businesses around the world with Networking. Tell us what you are working on.