← Network reference library

Wolex engineer reference · Fundamentals

IPv4 subnetting & address planning

Calculate boundaries, size a subnet and identify address-plan mistakes before touching a device.

Download branded PDF

Revision 2.0 · Documentation reviewed 2026-10-10 · Original Wolex reference

Prefix /27Block size 32Network .64Broadcast .95
Worked example: 192.0.2.77/27 belongs to 192.0.2.64/27. Usable ordinary host addresses are .65 through .94.

Quick reference

PrefixMaskAddressesOrdinary hosts
/24255.255.255.0256254
/25255.255.255.128128126
/26255.255.255.1926462
/27255.255.255.2243230
/28255.255.255.2401614
/29255.255.255.24886
/30255.255.255.25242
/31255.255.255.25422 on P2P
/32255.255.255.2551Single address

What to understand first

01

Address count is 2^(32 - prefix length). For ordinary broadcast subnets, subtract the network and broadcast addresses. /31 point-to-point links and /32 host routes have different semantics.

02

Find the boundary by applying the mask to the address. In the changing octet, block size is 256 minus the mask value. Round down to a multiple of that size; carry across octets when required.

03

Use variable-length subnetting by allocating the largest requirements first. Include growth, infrastructure and reserved addresses; track every allocation to prevent overlap.

04

A summary must cover the intended component networks and be aligned to its prefix boundary. A larger summary can accidentally attract traffic for space you do not own.

Commands and interpretation

Inspection commands are read-only unless explicitly labeled otherwise. Capture commands start collection; configuration-mode commits change device state.

Cisco IOS XE

Read-only EXEC

show ip interface brief
show ip route 192.0.2.77
show ip arp

Inspect: Compare the actual mask, selected route and next-hop resolution. A default route can hide a missing more-specific route.

Junos

Read-only operational

show interfaces terse
show route 192.0.2.77 detail
show arp no-resolve

Inspect: Confirm the correct routing-instance table and interface address. A neighbor entry does not prove an application is reachable.

Worked example · Illustrative, not a device capture

Worked boundary calculation

Address: 192.0.2.77/27
Mask:    255.255.255.224
Block:   32 addresses
Network: 192.0.2.64
Hosts:   192.0.2.65 - 192.0.2.94
Bcast:   192.0.2.95

77 falls between the aligned boundaries 64 and 96. The last address before 96 is the broadcast address.

A gateway chosen as .65 leaves 29 other ordinary host addresses; reservations reduce the usable pool further.

Troubleshooting sequence

  1. Write the client address, mask and gateway exactly as configured; compare them with IPAM rather than trusting a diagram.
  2. Calculate the client and gateway subnet boundaries independently. Check duplicate addresses and DHCP scope options.
  3. If the destination is on-link, inspect ARP and VLAN carriage. If off-link, inspect gateway reachability and routing.
  4. Check the return route from the destination context. Overlapping private networks can make VPN routing ambiguous.
  5. Validate the real application from the affected client after correcting the address plan.

Common mistakes

  • Applying the 2^n - 2 rule to a /31 point-to-point link.
  • Choosing a broadcast address as a host or assuming the first address is always the gateway.
  • Treating a successful gateway ping as proof of correct DHCP, DNS or return routing.

Acceptance checks

  • No overlapping allocations; gateway and client masks agree.
  • DHCP exclusions, static reservations and documentation match.
  • Forward and reverse application paths pass from each affected subnet.

Primary references

Vendor documentation and protocol specifications support this guide. The diagrams, scenarios and troubleshooting sequences are Wolex-authored.