Home/Labs/IP & CIDR Subnet Calculator
All 280 Labs
INTERACTIVE LAB🧮

IP Addressing & CIDR Subnetting Lab (Interactive)

Mask any IPv4 address bitwise, size /prefix blocks, and classify RFC 1918 private ranges. Compute network and broadcast addresses, usable host counts under AWS or classic rules, and public vs private classification live.

IP Addressing & CIDR Subnet Bench

Mask a real address with bitwise AND, size any /prefix, and see why private VPC subnets need NAT.

Address space comparison

IPv4 is 32-bit: ~4.3×10⁹ addresses (your /24 holds 8 host bits). IPv6 is 128-bit: 3.4×10³⁸ addresses — enough to end NAT forever.

10.0.1.47 is PRIVATE (RFC 1918, block 10.0.0.0/8) — never routable on the Internet; outbound traffic is masqueraded behind the NAT Gateway public IP, and no inbound connection can reach it directly.
Bitwise subnet computation
address  = 10.0.1.47 = 00001010 00000000 00000001 00101111
mask    = 255.255.255.0 = 11111111 11111111 11111111 00000000
AND → network = 10.0.1.0
Total addresses: 256Usable hosts: 251First usable: 10.0.1.4Last usable: 10.0.1.254Broadcast: 10.0.1.255AWS reserves: network+2112 (router), .2 DNS, .3 future, broadcast
Architecture rule: place ALBs and NAT Gateways in public subnets (e.g. 10.0.1.0/24), keep app servers, Redis, and databases in private subnets (10.0.2.0/24) with no route to an Internet Gateway — blocking 100% of direct internet-borne attacks against your data tier.

How It Works Under the Hood

IP addressing is the substrate of every cloud architecture. IPv4 is a 32-bit space; a CIDR prefix splits it into network and host bits, so a /24 leaves 8 host bits and 256 addresses. Real masks are applied with bitwise AND — this lab shows the binary math directly. RFC 1918 blocks (10/8, 172.16/12, 192.168/16) are never routed publicly, which is precisely why databases sit in private subnets and reach the Internet only through a NAT gateway that masquerades their source address. IPv6’s 128-bit space removes the scarcity that made NAT necessary.

Core Architectural Principles

  • Usable hosts = 2^(32 − prefix) − 2 classically, or − 5 reserved addresses in AWS VPC subnets.
  • Network address = IP AND mask; broadcast = network + block size − 1, computed bitwise.
  • RFC 1918 detection: 10.x, 172.16–172.31, and 192.168.x are non-routable on the public Internet.
Interview Round Script

When drawing a VPC, explicitly place ALBs and NAT gateways in public subnets and app servers, Redis, and databases in private subnets with no Internet Gateway route. Being able to size a subnet ("a /24 gives me ~251 usable IPs for twelve app containers") in one sentence signals real cloud fluency.

Key Trade-Offs

Private subnets block 100% of direct internet-borne attacks on the data tier but require NAT gateways and bastions for egress and maintenance.

Related Curriculum Chapter

IP Addressing (IPv4/IPv6, Public vs Private)

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs