Firewall rules, cloud security groups, VPN settings and hosting control panels all ask for IP ranges written like 10.0.0.0/16 or 203.0.113.8/29. That format is CIDR notation, and the number after the slash is the key to the whole thing. Read it correctly and you know exactly how many addresses a rule covers; misread it and you might open a database to the entire internet.
What CIDR notation means
CIDR stands for Classless Inter-Domain Routing, the addressing scheme defined in RFC 4632 that replaced the old fixed "Class A, B, C" networks in the 1990s. A CIDR block has two parts:
- A starting IP address, such as
192.168.4.0. - A prefix length after the slash, such as
/24.
The prefix length says how many of the 32 bits in an IPv4 address are fixed. Those fixed bits identify the network; the remaining bits are free to vary and identify individual addresses within the block. So /24 means the first 24 bits are fixed and 8 bits vary, giving 2 to the power of 8, or 256, addresses.
The rule to remember: every step up in the prefix halves the block; every step down doubles it. A /25 is half of a /24 (128 addresses); a /23 is two /24s (512 addresses).
CIDR quick reference table
| CIDR | Subnet mask | Total addresses | Usable hosts | Typical use |
|---|---|---|---|---|
| /8 | 255.0.0.0 | 16,777,216 | 16,777,214 | Whole private range 10.0.0.0/8 |
| /16 | 255.255.0.0 | 65,536 | 65,534 | Cloud virtual network, large campus |
| /20 | 255.255.240.0 | 4,096 | 4,094 | Large cloud subnet |
| /22 | 255.255.252.0 | 1,024 | 1,022 | Large office or Wi-Fi network |
| /24 | 255.255.255.0 | 256 | 254 | Typical office or home LAN |
| /25 | 255.255.255.128 | 128 | 126 | Half a /24 |
| /26 | 255.255.255.192 | 64 | 62 | Department or VLAN |
| /27 | 255.255.255.224 | 32 | 30 | Small server segment |
| /28 | 255.255.255.240 | 16 | 14 | Small public IP block from an ISP |
| /29 | 255.255.255.248 | 8 | 6 | Small business static IP block |
| /30 | 255.255.255.252 | 4 | 2 | Point-to-point link |
| /31 | 255.255.255.254 | 2 | 2 (special case) | Point-to-point link without waste |
| /32 | 255.255.255.255 | 1 | 1 | A single host |
"Usable hosts" subtracts the network and broadcast addresses, which ordinary subnets reserve. Note that cloud providers often reserve a few extra addresses in each subnet for their own routers and DNS, so the real usable count there is slightly lower; check your provider's documentation.
Reading the three examples in the title
/24: the familiar office network
192.168.1.0/24 covers 192.168.1.0 to 192.168.1.255. Only the last number changes. This is the default for most home and small-office routers.
/27: thirty usable addresses
192.168.1.64/27 covers 32 addresses, .64 to .95. The network address is .64, broadcast is .95, and .65 to .94 are assignable. A /27 block must start on a multiple of 32 (0, 32, 64, 96…), so 192.168.1.70/27 is not a valid network start; it is simply an address inside the .64/27 block.
/30: just enough for a link
10.255.0.4/30 holds four addresses: network .4, usable .5 and .6, broadcast .7. That is exactly enough for two routers connected to each other, which is why /30 was traditionally used for WAN links. Many modern routers support /31 on such links instead, as described in RFC 3021, using both addresses and wasting none.
CIDR notation in firewall and cloud rules
This is where getting CIDR wrong has real consequences:
203.0.113.25/32means one specific address. Use this when allowing a single office IP to reach SSH or a database. You can find your office's current public address with What Is My IP.203.0.113.0/24allows 256 addresses, which may include other customers of the same ISP.0.0.0.0/0means every IPv4 address. It is correct for a public website on ports 80 and 443, and dangerous for anything else. A rule allowing0.0.0.0/0on port 3306 (MySQL) or 3389 (Remote Desktop) exposes that service to the whole internet.::/0is the IPv6 equivalent of "everything". If you lock down IPv4 but leave an IPv6 rule open, the service is still exposed.
When you see an unfamiliar range in a rule, paste it into a subnet calculator to see the first and last address it covers before approving it.
Converting a prefix to a mask in your head
You do not need to memorize the whole table. Split the prefix into whole octets and a remainder. Every complete group of 8 bits is 255. For the remaining bits, the octet value follows a fixed sequence: 1 bit is 128, 2 bits 192, 3 bits 224, 4 bits 240, 5 bits 248, 6 bits 252, 7 bits 254. Any octets after that are 0.
Example: /20 is two full octets (16 bits) plus 4 bits, so the mask is 255.255.240.0. The block size in the third octet is 256 − 240 = 16, so /20 networks start at x.x.0.0, x.x.16.0, x.x.32.0 and so on, each spanning 16 × 256 = 4,096 addresses.
Going the other way, to find the prefix from a mask, count the 1 bits: 255.255.255.248 is 8 + 8 + 8 + 5 = 29, so it is a /29.
Combining ranges (route aggregation)
CIDR also lets adjacent blocks be written as one. 192.168.0.0/24 and 192.168.1.0/24 together form 192.168.0.0/23. This only works when the blocks are contiguous and the combined block starts on a valid boundary: 192.168.1.0/24 plus 192.168.2.0/24 cannot be merged into a single /23. Aggregation keeps routing tables and firewall rule lists shorter.
CIDR in IPv6
IPv6 uses the same slash notation with 128-bit addresses. The numbers are much larger, and conventions differ: a single network segment is normally a /64, and a site commonly receives a /48 or /56 from its provider. A /128 is one address, the IPv6 equivalent of a /32.
Key takeaways
- The number after the slash is how many bits are fixed; the rest vary.
- Each +1 halves the block size: /24 is 256 addresses, /27 is 32, /30 is 4, /32 is one.
- In firewall rules, prefer /32 for single trusted IPs and treat 0.0.0.0/0 and ::/0 with great care.
- Blocks must start on a multiple of their size; check unfamiliar ranges with a calculator.