The formula is:
Usable hosts = 2^(host bits) − 2
Where host bits = 32 − prefix length (for IPv4).
You subtract 2 because the first address (all host bits = 0) is the network address and the last (all host bits = 1) is the broadcast address — neither can be assigned to a device.
| Prefix | Host bits | Total addresses | Usable hosts |
|---|---|---|---|
| /8 | 24 | 16,777,216 | 16,777,214 |
| /16 | 16 | 65,536 | 65,534 |
| /24 | 8 | 256 | 254 |
| /25 | 7 | 128 | 126 |
| /26 | 6 | 64 | 62 |
| /27 | 5 | 32 | 30 |
| /28 | 4 | 16 | 14 |
| /29 | 3 | 8 | 6 |
| /30 | 2 | 4 | 2 |
| /31 | 1 | 2 | 2* |
| /32 | 0 | 1 | 1* |
* /31 and /32 are special cases (RFC 3021) — no broadcast address exists, so both addresses in a /31 are usable for point-to-point links.
Example: 192.168.10.0/25 → host bits = 32 − 25 = 7 → 2⁷ − 2 = 126 usable hosts
CIDR (Classless Inter-Domain Routing) notation writes an IP address followed by a slash and a prefix length: 192.168.1.0/24
The number after the slash tells you how many leading bits are the network portion. The remaining bits are for hosts.
How it maps to a subnet mask:
| CIDR | Binary mask | Dotted-quad mask |
|---|---|---|
| /8 | 11111111.00000000.00000000.00000000 | 255.0.0.0 |
| /16 | 11111111.11111111.00000000.00000000 | 255.255.0.0 |
| /24 | 11111111.11111111.11111111.00000000 | 255.255.255.0 |
| /25 | 11111111.11111111.11111111.10000000 | 255.255.255.128 |
| /30 | 11111111.11111111.11111111.11111100 | 255.255.255.252 |
Why it exists: Before 1993, IP addresses were divided into fixed classes (A = /8, B = /16, C = /24), which wasted enormous amounts of address space. CIDR allows any prefix length from /0 to /32, so you can allocate exactly the size you need.
In IPv6, the same concept applies to 128-bit addresses with prefix lengths from /0 to /128 (e.g., 2001:db8::/64).
They're the same thing in two different formats. A subnet mask and CIDR notation both describe the network/host boundary of an IP address — the only difference is how you write it.
| Subnet Mask (dotted decimal) | CIDR (prefix length) | |
|---|---|---|
| Format | 255.255.255.128 | /25 |
| What it says | "These 32 bits are the mask" | "The first 25 bits are network" |
| Where you'll see it | OS settings, legacy configs | Routing tables, cloud consoles, modern docs |
They convert directly:
255.255.255.128 → 11111111.11111111.11111111.10000000 → 25 ones → /25
Why CIDR won in practice:
/25) vs. thirteen (255.255.255.128)/27, /29, /31 are all validWhen you still see dotted-decimal masks: Windows "View IP Properties" dialog, older Cisco/IOS configs, some ACLs and legacy documentation.
Formula:
Usable hosts = 2^(host bits) − 2
Where host bits = 32 − prefix length.
Step-by-step for 192.168.10.0/25:
The "−2" accounts for the two reserved addresses (network and broadcast).
Reverse lookup (given a host count, find the prefix):
prefix = 32 − ceil(log2(required_hosts + 2))
e.g. need 50 hosts → log₂(52) ≈ 5.7 → round up to 6 → prefix = 32 − 6 = /26 (62 usable).
| Prefix | Host bits | Usable hosts |
|---|---|---|
| /24 | 8 | 254 |
| /25 | 7 | 126 |
| /26 | 6 | 62 |
| /27 | 5 | 30 |
| /28 | 4 | 14 |
| /29 | 3 | 6 |
| /30 | 2 | 2 |
These are the two "bookend" addresses in every subnet — the first and last. Neither can be assigned to a device.
| Network Address | Broadcast Address | |
|---|---|---|
| Position | First address in the subnet | Last address in the subnet |
| Host bits | All 0 | All 1 |
| Purpose | Identifies the subnet itself (used in routing tables) | Sends a packet to every device on the subnet |
| Calculate | IP AND mask | network OR wildcard |
| Example (/24) | 192.168.1.0 | 192.168.1.255 |
| Example (/25) | 192.168.10.0 | 192.168.10.127 |
In short: the network address says *"this is the subnet"*; the broadcast address says *"talk to everyone in this subnet at once."
Special cases:
ff02::1 = all-nodes)