IP Addressing & CIDR Subnetting Lab (Interactive)
Mask any IPv4 address bitwise, size /prefix blocks, and classify RFC 1918 private ranges. Compute network and broadcast addresses, usable host counts under AWS or classic rules, and public vs private classification live.
IP Addressing & CIDR Subnet Bench
Mask a real address with bitwise AND, size any /prefix, and see why private VPC subnets need NAT.
Address space comparison
IPv4 is 32-bit: ~4.3×10⁹ addresses (your /24 holds 8 host bits). IPv6 is 128-bit: 3.4×10³⁸ addresses — enough to end NAT forever.
How It Works Under the Hood
IP addressing is the substrate of every cloud architecture. IPv4 is a 32-bit space; a CIDR prefix splits it into network and host bits, so a /24 leaves 8 host bits and 256 addresses. Real masks are applied with bitwise AND — this lab shows the binary math directly. RFC 1918 blocks (10/8, 172.16/12, 192.168/16) are never routed publicly, which is precisely why databases sit in private subnets and reach the Internet only through a NAT gateway that masquerades their source address. IPv6’s 128-bit space removes the scarcity that made NAT necessary.
Core Architectural Principles
- Usable hosts = 2^(32 − prefix) − 2 classically, or − 5 reserved addresses in AWS VPC subnets.
- Network address = IP AND mask; broadcast = network + block size − 1, computed bitwise.
- RFC 1918 detection: 10.x, 172.16–172.31, and 192.168.x are non-routable on the public Internet.
When drawing a VPC, explicitly place ALBs and NAT gateways in public subnets and app servers, Redis, and databases in private subnets with no Internet Gateway route. Being able to size a subnet ("a /24 gives me ~251 usable IPs for twelve app containers") in one sentence signals real cloud fluency.
Private subnets block 100% of direct internet-borne attacks on the data tier but require NAT gateways and bastions for egress and maintenance.