Is anything I type sent to a server?
No. All subnet math runs in your browser with 128-bit integers; the tool never looks addresses up or contacts them.
Network, broadcast, host range and counts for any CIDR block, AWS/Azure/GCP reserved addresses, subnet splitting, range-to-CIDR and overlap checks. IPv4 and IPv6.
Loading CIDR Calculator…
Loading CIDR Calculator…
Subnetting is simple arithmetic that's easy to get subtly wrong: an off-by-one on the broadcast address, a /31 reported as having zero hosts, an AWS subnet that turns out to have five fewer addresses than planned, two VPCs that can't be peered because their ranges overlap. This calculator takes an address in any common form — 10.0.0.0/16, 10.0.0.0 255.255.0.0, a Cisco-style wildcard mask, a bare IP, or an IPv6 prefix — and shows the network and broadcast addresses, first and last usable host, total and usable counts, netmask, wildcard mask, binary and hex forms, the reverse DNS zone, and what kind of range it is (RFC 1918 private, carrier-grade NAT, link-local, documentation, multicast). A provider switch applies AWS, Azure or Google Cloud reserved addresses. Other modes split a network into subnets by size or count, turn any IP range into the minimal CIDR list, test whether an address is inside a block, and check a list of CIDRs for overlaps before you peer VPCs or add routes.
Addresses are 32-bit (IPv4) or 128-bit (IPv6) integers held as BigInt. The netmask has the first n bits set; network = address AND mask; the last address = network OR NOT mask. Total addresses = 2^(bits − n). For IPv4, usable = total − 2 except for /31 (2, RFC 3021) and /32 (1). IPv6 has no broadcast address.
Octets must be 0–255 without leading zeros (010 is rejected because some software reads it as octal). Masks must have contiguous 1 bits; a mask like 0.0.0.255 is recognized as a wildcard mask. IPv6 accepts "::" compression, embedded IPv4 (::ffff:192.0.2.1), brackets and zone IDs, and is shown in RFC 5952 canonical form and fully expanded.
Starting from the first address, the tool repeatedly takes the largest block that is aligned at the current address and doesn't pass the end of the range. The result is the minimal set of prefixes — the same algorithm as Python's ipaddress.summarize_address_range — and is tested by checking that the blocks cover the range exactly with no gaps.
AWS VPC and Azure VNet subnets reserve the first four addresses and the last one; Google Cloud reserves the network, gateway, second-to-last and last addresses. The allowed subnet sizes differ too (AWS /16–/28, Azure /8–/29), and the tool tells you when a size isn't allowed.
Short answers for the things developers usually ask before trusting a tool.
No. All subnet math runs in your browser with 128-bit integers; the tool never looks addresses up or contacts them.
254. A /24 has 256 addresses; the first is the network address and the last is the broadcast address, so 254 can be assigned to hosts. In general a /n has 2^(32−n) addresses and 2^(32−n) − 2 usable hosts — except /31, which has 2 usable addresses on point-to-point links (RFC 3021), and /32, which is a single host.
AWS reserves five addresses in every subnet: the network address, the VPC router (+1), the DNS server (+2), one reserved for future use (+3), and the last address. Azure also reserves five (network, gateway, two for DNS, and the last); Google Cloud reserves four. Choose the provider under "Reserved addresses" to see the real usable count and first/last usable IP. AWS subnets must be between /16 and /28.
192.168.1.10/24 isn't a network address — the network is 192.168.1.0/24. Many tools (and cloud APIs) reject the first form. The calculator shows the normalized network and says so.
Because they're ambiguous. Some software (inet_aton, ping on many systems) reads 010 as octal, so 10.010.0.1 means 10.8.0.1 to them and 10.10.0.1 to others. This has caused real security bugs in allow-lists. Write each octet without leading zeros.
Use "Range → CIDR" and enter the first and last address. The tool returns the smallest list of CIDR blocks that covers exactly that range — for example 192.168.1.0–192.168.1.130 is 192.168.1.0/25, 192.168.1.128/31 and 192.168.1.130/32.
Useful follow-ups when one conversion usually turns into three more.
Convert Unix permissions between checkboxes, octal (755) and symbolic (rwxr-xr-x), including setuid, setgid and sticky bits; parse ls -l output; get the chmod command.
Convert between hex, decimal, binary and octal with two's complement and byte order, inspect IEEE 754 floats bit by bit, and convert byte lists between C, Python and C# syntax.
Convert one or more docker run commands into a Compose file (compose.yaml, no obsolete version key): ports, volumes, env, networks, healthchecks, GPUs and more.