Netmask and Subnetting Explained: CIDR, Subnet Masks, and How They Work

A netmask (subnet mask) defines which part of an IP address is the network portion and which part is the host portion. This guide explains netmasks, CIDR notation, and how to read common subnet formats accurately.
In this extensive guide, we will investigate netmasks and CIDR clearly. If you want range calculation examples, check out How to Calculate IP Addresses.
Understanding the Basics
What is a Netmask?
To crack the netmask code, it's essential to start at the very beginning. A netmask (also called a subnet mask) tells a device which part of an IP address is the network portion and which part is the host portion.
-
The network portion identifies the subnet.
-
The host portion identifies a specific device inside that subnet.
In IPv4, a netmask is often shown as dotted decimal (e.g., 255.255.255.0) or as CIDR (e.g., /24). In both forms, the meaning is the same: how many bits belong to the network.
A practical way to think about it:
-
If two IPs are in the same network portion (based on the mask), they are “local” to each other.
-
If they’re not, traffic must be sent to a router (default gateway).
What is a CIDR Notation?
CIDR stands for Classless Inter-Domain Routing. CIDR notation expresses the netmask as a prefix length, written as /number.
Example:
-
/24 means 24 bits are used for the network portion.
-
The remaining bits are used for hosts.
CIDR applies to both IPv4 and IPv6. It’s not an IPv6-only system. CIDR is used for:
-
IPv4 (e.g., 192.168.1.10/24)
-
IPv6 (e.g., 2001:db8:abcd:10::/64)
IPv6 commonly uses prefix lengths like /64 for subnets, but the notation and concept (network prefix length) is still CIDR.
CIDR vs Subnet Mask (Dotted Decimal)
CIDR is just a different way to represent the same boundary:
-
255.255.255.0 = /24
-
255.255.255.240 = /28
CIDR is typically the most convenient form for documentation, routing, and IP allocations, while dotted decimal is still commonly seen in OS interface settings and older network documentation.
Binary and Dotted Decimal
Netmasks make more sense when you understand what “bits” are doing, but this does not need to become a math lesson. The key idea is simple:
-
A 1 bit means “this belongs to the network”
-
A 0 bit means “this belongs to the host”
Clean IPv4 example: /24
An IPv4 address is 32 bits. A /24 mask means the first 24 bits are network bits.
-
IP: 192.168.1.10
-
Binary: 11000000.10101000.00000001.00001010
/24 mask means:
Mask: 11111111.11111111.11111111.00000000
In dotted decimal, that /24 mask becomes:
-
11111111 = 255
-
00000000 = 0
So /24 = 255.255.255.0
Quick intuition: smaller prefix = larger subnet
-
/24 leaves 8 host bits → more usable host addresses
-
/29 leaves 3 host bits → fewer usable host addresses
Common Subnet Sizes in Hosting
In hosting environments, you’ll frequently see IP blocks allocated as CIDR prefixes. These blocks are used for:
-
Dedicated server allocations
-
Routed IP ranges
-
Additional IPs for VPS setups (provider-dependent)
-
Service separation (mail vs web) and operational planning
Here are common blocks and what they typically mean operationally:
/24 subnet (common for larger allocations)
-
256 total IPv4 addresses
-
254 usable (in classic subnetting where network + broadcast are reserved)
A /24 is large enough for bigger infrastructure allocations, multi-tenant routing, or providers assigning ranges internally.
/27 subnet (common for medium allocations)
-
32 total addresses
-
30 usable (typical)
Often used when you need a meaningful block for multiple services or customers without going as large as a /24.
/28 subnet (common for small block allocations)
-
16 total addresses
-
14 usable (typical)
A /28 is common when you need multiple usable IPs, but not a large allocation.
/29 subnet (very common for small dedicated/VPS add-on blocks)
-
8 total addresses
-
6 usable (typical)
A /29 is often the smallest practical “block” allocation used when a customer needs multiple IPs for specific use cases.
If you’re deciding between these blocks (or trying to understand what you were allocated), check out our guide: /29 vs /28 vs /27 IP Blocks Explained for Dedicated Servers.
How Netmask Relates to Routing Decisions
Netmasks matter because they directly influence routing behavior. When a server wants to reach an IP address, it performs a basic check:
-
“Is the destination IP inside my local subnet?”
-
If yes, it uses ARP (IPv4) or neighbor discovery (IPv6) and sends locally.
-
If no, it forwards traffic to the default gateway (router).
This is why a wrong netmask can cause confusing behavior:
-
A host might treat a gateway as “off subnet” and fail to route.
-
A host might treat too many addresses as “local” and send traffic that should be routed.
If you are diagnosing errors like “network not reachable,” “invalid subnet mask,” or “inconsistent address and mask,” check out this troubleshooting resource.
Netmask Planning for VPS Environments
Most VPS scaling issues are not caused by netmask math, but netmask understanding is important when you:
-
Add multiple IPs to a VPS (policy and allocation dependent)
-
Receive a routed block from a provider
-
Separate services across addresses (e.g., mail reputation separation)
-
Plan for growth and avoid overlapping subnets in private networks
Understanding netmasks is foundational for working with IP addressing and subnetting. It helps you interpret CIDR prefixes, allocate subnets correctly, and avoid routing and reachability issues caused by incorrect network boundaries.
FAQs
-
What is a netmask in simple terms?
A netmask tells a device which part of an IP address is the network and which part is the host. It defines subnet boundaries and affects local vs routed traffic.
-
Is CIDR the same as a subnet mask?
CIDR is a notation for expressing the subnet mask as a prefix length (like /24). It represents the same boundary as dotted decimal masks like 255.255.255.0.
-
Does CIDR apply to IPv6?
Yes. CIDR applies to both IPv4 and IPv6. IPv6 commonly uses prefix lengths such as /64, but the concept is the same: a network prefix length.