ShadowXLab
SHADOWXLAB CYBER·OS SIMULATOR
SUBNETTING & VLSM ARCHITECTURE
🏠 Platform Home 🔌 Wireshark & 30-Phase Lab 🧮 IP Addressing Lab
SHADOWXLAB CYBER-OS · LAYER 3 ARCHITECTURE & SUBNETTING

Subnetting you can actually see.

Work bidirectionally across subnets, hosts, CIDR prefixes, and subnet masks. Calculate masks from subnets or hosts, design multi-tier VLSM departmental allocations, test host membership, and practice dynamic CCNA drills.

IPv432-BIT BINARYCIDRFLSMVLSMSUPERNETTINGBIDIRECTIONAL

01 · Interactive 4-Way Synchronized Subnet Calculator

Change ANY field (IP, CIDR Prefix, Subnet Mask, Subnets Count, or Hosts per Range) — all fields synchronize bidirectionally.

Network Address
Broadcast Address
First Usable Host
Last Usable Host
Subnet Mask
Wildcard Mask
Total Addresses
Usable Hosts / Range
⚡ LIVE BITWISE AND OPERATION (IP ∧ MASK = NETWORK ID)
LOGIC RULE: 1 ∧ 1 = 1 · ANY ∧ 0 = 0 (HOST BITS FORCED TO 0)
Decimal Bitwise Formulation
Subnet Boundary Action
32-Bit Network / Host Bit Boundary
Network Bits (1s in Mask)Host Bits (0s in Mask)

02 · Bidirectional Subnet/Host Reverse Engineering Matrix

Convert Given Subnets $ o$ Mask/Hosts, or Given Hosts $ o$ Mask/Subnets with live instant calculations.

🅰️ GIVEN NUMBER OF SUBNETS NEEDED $ o$ FIND MASK & HOSTS
🅱️ GIVEN USABLE HOSTS PER RANGE $ o$ FIND MASK & SUBNETS

03 · Real-World Enterprise Scenarios (Subnet & Host Sizing)

Click any scenario to load the architecture into the interactive solvers and review the exact derivation.

🏬 Retail Store Rollout 28 Stores

Enterprise assigns 192.168.100.0/24. Need at least 14 store branches with 12 POS terminals each.

Solution: /28 (255.255.255.240) · 16 subnets · 14 usable hosts each
☁️ Cloud VPC 4-AZ Architecture 4 AZs · 1000 Hosts

VPC root 172.16.0.0/16. Divide into 4 Availability Zones with at least 1,000 servers per AZ.

Solution: /22 (255.255.252.0) · 64 subnets possible · 1,022 usable hosts each
🏭 Industrial IoT Sensor Slicing 500 Subnets · 50 Hosts

Smart factory assigns 10.0.0.0/8. Needs 500 plant subnets with 50 sensors per range.

Solution: /26 (255.255.255.192) · 262,144 subnets · 62 usable hosts each
🌐 WAN Point-to-Point Links 30 Links · 2 Hosts

Core network assigns 10.255.0.0/24. Allocate 30 router interconnections with zero waste.

Solution: /30 (255.255.255.252) · 64 subnets · 2 usable hosts each (or /31 RFC 3021)

04 · Binary Conversion Workbench

Observe how the bitwise AND operation produces the network ID.

IP ADDRESS (BINARY)
SUBNET MASK (BINARY)
STEP 01
Write 32-Bit IPEvery octet represents 8 binary bits.
STEP 02
Write MaskPrefix length sets exact count of consecutive 1s.
STEP 03
Bitwise ANDIP ∧ Mask locks the Network Address.
STEP 04
Host BoundaryHost bits = all 0s for Network; all 1s for Broadcast.
STEP 05
Usable HostsFormula: 2^(32 - prefix) - 2 usable addresses.

05 · Fixed-Length Subnet Generator (FLSM)

Divide any parent network into equal-sized child subnets.

Subnets Created
Total Addresses / Subnet
Usable Hosts / Subnet
Block Increment
#Subnet / CIDRNetworkFirst HostLast HostBroadcastUsable

06 · Variable-Length Subnet Mask (VLSM) Designer

Allocate custom departmental host requirements with zero wasted space.

VLSM Golden RuleSort requirements from largest to smallest

Always assign the largest departmental block first, lock its boundary, and move the next network increment forward to prevent subnet overlap.

Req.AllocatedCIDRNetworkFirst HostLast HostBroadcastTotalWaste

07 · Host Membership & Boundary Tester

Validate if a given host IP resides inside a subnet or strays outside.

Enter a subnet and host to test.

08 · Supernetting & Route Aggregation

Summarize multiple contiguous routing prefixes into a single concise route.

Enter adjacent networks to calculate the summary route.

09 · Nth Subnet & Host Target Finder

Calculate the Network ID, Broadcast, and exact First/Last usable host for any Nth subnet allocation instantly.

5th Subnet Network ID172.16.128.0/19
First Usable Host172.16.128.1
Target: Last Usable Host172.16.159.254
Broadcast Address172.16.159.255
🗺️ VISUAL 1: ALL SUBNET BLOCKS IN PARENT NETWORK (CLICK ANY BLOCK) 8 Subnets Total
🎯 VISUAL 2: TARGET SUBNET HOST RANGE & MEMORY LAYOUT
NETWORK ID 172.16.128.0 [Reserved]
FIRST USABLE 172.16.128.1 [Net + 1]
USABLE HOST ADDRESS POOL 8,190 Total Usable Host IP Slots Servers, Workstations, Access Points, Gateways
🎯 TARGET: LAST HOST 172.16.159.254 [BC − 1: ASSIGN THIS!]
BROADCAST ID 172.16.159.255 [All 1s Host Bits]
🔬 VISUAL 3: 32-BIT BINARY OFFSET & BORROWED BITS BREAKDOWN

10 · Interactive Subnetting Practice Arena & Visual Solver

Dynamic random questions covering all CCNA & JNCIA question types with animated, step-by-step visual calculations.

SCORE: 0 XP
STREAK: 0🔥
QUESTION #1 · NETWORK ID DIFFICULTY: CCNA STANDARD

What is the network address for 172.24.115.89/20?

11 · Independent Calculation & Practice Drills (8 Comprehensive Challenges)

Solve these questions manually before clicking "Show Verification & Steps" to test your exam, architectural, and incident triage readiness.

Drill 1: Usable Hosts & Network Identification IPv4 /20

Given the host address 172.20.45.190/20, determine:
1. The Subnet Mask
2. The Network Address
3. The Broadcast Address
4. The Valid Usable Host Range

Solution Breakdown:
• Prefix /20 = 20 network bits (11111111.11111111.11110000.00000000)
• Subnet Mask: 255.255.240.0
• Third Octet Block Size: 256 - 240 = 16
• Subnet Multiples in Octet 3: 0, 16, 32, 48... 45 falls into the 32 block.
• Network Address: 172.20.32.0
• Broadcast Address: 172.20.47.255
• Usable Host Range: 172.20.32.1 – 172.20.47.254 (4,094 usable hosts).

Drill 2: Subnet Borrowing & FLSM Design FLSM /28

An enterprise assigns you 192.168.50.0/24 and instructs you to create at least 12 individual subnets for distinct store locations.
1. How many host bits must be borrowed?
2. What is the new CIDR prefix and subnet mask?
3. How many usable hosts will each store receive?

Solution Breakdown:
• 2^n ≥ 12 subnets → Borrow 4 bits (2^4 = 16 subnets created).
• New Prefix: /24 + 4 = /28
• Subnet Mask: 255.255.255.240
• Remaining Host Bits: 32 - 28 = 4 bits
• Usable Hosts per Subnet: 2^4 - 2 = 14 usable hosts.

Drill 3: VLSM Departmental Allocation VLSM Sizing

You have the parent block 10.50.0.0/22 (1,024 total addresses). You must allocate subnets for:
• Engineering: 480 hosts
• Support: 110 hosts
• Marketing: 55 hosts
• Point-to-Point WAN Link: 2 hosts
List the allocated CIDR prefix and network address for each department.

Solution Breakdown (Largest First):
1. Engineering (480 hosts): Needs 512-block → /23. Network: 10.50.0.0/23 (Range: 10.50.0.1 – 10.50.1.254, BC: 10.50.1.255)
2. Support (110 hosts): Needs 128-block → /25. Network: 10.50.2.0/25 (Range: 10.50.2.1 – 10.50.2.126, BC: 10.50.2.127)
3. Marketing (55 hosts): Needs 64-block → /26. Network: 10.50.2.128/26 (Range: 10.50.2.129 – 10.50.2.190, BC: 10.50.2.191)
4. WAN Link (2 hosts): Needs 4-block → /30. Network: 10.50.2.192/30 (Range: 10.50.2.193 – 10.50.2.194, BC: 10.50.2.195).

Drill 4: Route Aggregation Forensic BGP / OSPF Supernet

A core router receives route advertisements for:
• 10.100.16.0/24
• 10.100.17.0/24
• 10.100.18.0/24
• 10.100.19.0/24
What is the most concise single summary route that encompasses all four routes?

Solution Breakdown:
• Binary analysis of Octet 3: 16 (00010000), 17 (00010001), 18 (00010010), 19 (00010011)
• The first 6 bits of the 3rd octet match (000100xx).
• Common Prefix: 8 + 8 + 6 = /22
• Summarized Route: 10.100.16.0/22 (Covers 10.100.16.0 through 10.100.19.255).

Drill 5: Overlapping Subnet Conflict Triage Troubleshooting

HQ uses 10.10.16.0/20. A newly acquired remote branch is configured with 10.10.24.0/22. The network engineer reports asymmetric routing and unreachable hosts.
1. Does the branch subnet overlap with HQ?
2. What is the exact range of both allocations?
3. How should this conflict be resolved?

Solution Breakdown:
HQ /20 Range: 10.10.16.0 through 10.10.31.255 (Block size 16 in octet 3: 16 to 31).
Branch /22 Range: 10.10.24.0 through 10.10.27.255.
Overlap Diagnosis: YES! 10.10.24.0/22 is completely contained inside HQ's 10.10.16.0/20 address space.
Resolution: Re-IP the branch to a distinct non-overlapping RFC 1918 block (e.g. 10.10.32.0/22 or 172.16.24.0/22) or implement 1:1 NAT / Policy-Based NAT at the IPsec edge tunnel.

Drill 6: Cisco Wildcard Mask for ACLs & OSPF Cisco ACL / OSPF

You need to write an extended ACL on a core router permitting traffic from subnet 172.16.64.0/19 to any destination.
1. What is the subnet mask for a /19?
2. What is the inverted wildcard mask?
3. Write the exact Cisco IOS ACL statement.

Solution Breakdown:
• Subnet Mask (/19): 255.255.224.0
• Wildcard Mask: 255.255.255.255 − 255.255.224.0 = 0.0.31.255
• Cisco IOS Statement: access-list 101 permit ip 172.16.64.0 0.0.31.255 any
• OSPF Area 0 Statement: network 172.16.64.0 0.0.31.255 area 0

Drill 7: IPv6 Subnetting & /64 Global Unicast IPv6 Allocation

Your organization receives the global routing prefix 2001:db8:acad::/48 from the RIR (Regional Internet Registry). Standard practice requires creating /64 subnets for SLAAC.
1. How many /64 subnets can be carved from a /48?
2. Provide the first 3 subnet IDs for DMZ, Internal LAN, and Guest Wi-Fi.

Solution Breakdown:
• Subnet bits available: 64 − 48 = 16 bits (the 4th hextet).
• Total /64 Subnets: 2^16 = 65,536 subnets.
Subnet 1 (DMZ): 2001:db8:acad:0001::/64 (or 2001:db8:acad:1::/64)
Subnet 2 (Internal LAN): 2001:db8:acad:0002::/64 (or 2001:db8:acad:2::/64)
Subnet 3 (Guest Wi-Fi): 2001:db8:acad:0003::/64 (or 2001:db8:acad:3::/64)

Drill 8: Lateral Movement & Broadcast Boundary Security SOC Incident

A threat actor compromises host 192.168.1.50/24 in the Marketing VLAN. They attempt an ARP spoofing attack against the Finance server at 192.168.2.10/24.
1. Can ARP broadcast frames cross the Layer 3 boundary between 192.168.1.0/24 and 192.168.2.0/24 without a router?
2. Why does proper subnetting and Layer 3 micro-segmentation mitigate direct Layer 2 ARP poisoning?

Solution Breakdown:
1. No. ARP requests are broadcast frames (FF:FF:FF:FF:FF:FF) confined to their local Layer 2 broadcast domain (VLAN). Switches do not forward broadcasts across different subnets/VLANs.
2. Security Impact: Because the Finance server is in a different subnet (192.168.2.0/24), the compromised host must send its traffic to the Default Gateway at Layer 3. The gateway router/firewall inspects IP and transport headers and enforces ACL policies, preventing the attacker from sniffing or spoofing the Finance server's MAC address directly.