Subnetting you can actually see.
Work bidirectionally across subnets, hosts, CIDR prefixes, and subnet masks. Calculate masks from subnets or hosts, design multi-tier VLSM departmental allocations, test host membership, and practice dynamic CCNA drills.
01 · Interactive 4-Way Synchronized Subnet Calculator
Change ANY field (IP, CIDR Prefix, Subnet Mask, Subnets Count, or Hosts per Range) — all fields synchronize bidirectionally.
02 · Bidirectional Subnet/Host Reverse Engineering Matrix
Convert Given Subnets $ o$ Mask/Hosts, or Given Hosts $ o$ Mask/Subnets with live instant calculations.
03 · Real-World Enterprise Scenarios (Subnet & Host Sizing)
Click any scenario to load the architecture into the interactive solvers and review the exact derivation.
Enterprise assigns 192.168.100.0/24. Need at least 14 store branches with 12 POS terminals each.
VPC root 172.16.0.0/16. Divide into 4 Availability Zones with at least 1,000 servers per AZ.
Smart factory assigns 10.0.0.0/8. Needs 500 plant subnets with 50 sensors per range.
Core network assigns 10.255.0.0/24. Allocate 30 router interconnections with zero waste.
04 · Binary Conversion Workbench
Observe how the bitwise AND operation produces the network ID.
05 · Fixed-Length Subnet Generator (FLSM)
Divide any parent network into equal-sized child subnets.
| # | Subnet / CIDR | Network | First Host | Last Host | Broadcast | Usable |
|---|
06 · Variable-Length Subnet Mask (VLSM) Designer
Allocate custom departmental host requirements with zero wasted space.
Always assign the largest departmental block first, lock its boundary, and move the next network increment forward to prevent subnet overlap.
| Req. | Allocated | CIDR | Network | First Host | Last Host | Broadcast | Total | Waste |
|---|
07 · Host Membership & Boundary Tester
Validate if a given host IP resides inside a subnet or strays outside.
08 · Supernetting & Route Aggregation
Summarize multiple contiguous routing prefixes into a single concise route.
09 · Nth Subnet & Host Target Finder
Calculate the Network ID, Broadcast, and exact First/Last usable host for any Nth subnet allocation instantly.
10 · Interactive Subnetting Practice Arena & Visual Solver
Dynamic random questions covering all CCNA & JNCIA question types with animated, step-by-step visual calculations.
What is the network address for 172.24.115.89/20?
11 · Independent Calculation & Practice Drills (8 Comprehensive Challenges)
Solve these questions manually before clicking "Show Verification & Steps" to test your exam, architectural, and incident triage readiness.
Drill 1: Usable Hosts & Network Identification IPv4 /20
Given the host address 172.20.45.190/20, determine:
1. The Subnet Mask
2. The Network Address
3. The Broadcast Address
4. The Valid Usable Host Range
• Prefix /20 = 20 network bits (11111111.11111111.11110000.00000000)
• Subnet Mask: 255.255.240.0
• Third Octet Block Size: 256 - 240 = 16
• Subnet Multiples in Octet 3: 0, 16, 32, 48... 45 falls into the 32 block.
• Network Address: 172.20.32.0
• Broadcast Address: 172.20.47.255
• Usable Host Range: 172.20.32.1 – 172.20.47.254 (4,094 usable hosts).
Drill 2: Subnet Borrowing & FLSM Design FLSM /28
An enterprise assigns you 192.168.50.0/24 and instructs you to create at least 12 individual subnets for distinct store locations.
1. How many host bits must be borrowed?
2. What is the new CIDR prefix and subnet mask?
3. How many usable hosts will each store receive?
• 2^n ≥ 12 subnets → Borrow 4 bits (2^4 = 16 subnets created).
• New Prefix: /24 + 4 = /28
• Subnet Mask: 255.255.255.240
• Remaining Host Bits: 32 - 28 = 4 bits
• Usable Hosts per Subnet: 2^4 - 2 = 14 usable hosts.
Drill 3: VLSM Departmental Allocation VLSM Sizing
You have the parent block 10.50.0.0/22 (1,024 total addresses). You must allocate subnets for:
• Engineering: 480 hosts
• Support: 110 hosts
• Marketing: 55 hosts
• Point-to-Point WAN Link: 2 hosts
List the allocated CIDR prefix and network address for each department.
1. Engineering (480 hosts): Needs 512-block → /23. Network: 10.50.0.0/23 (Range: 10.50.0.1 – 10.50.1.254, BC: 10.50.1.255)
2. Support (110 hosts): Needs 128-block → /25. Network: 10.50.2.0/25 (Range: 10.50.2.1 – 10.50.2.126, BC: 10.50.2.127)
3. Marketing (55 hosts): Needs 64-block → /26. Network: 10.50.2.128/26 (Range: 10.50.2.129 – 10.50.2.190, BC: 10.50.2.191)
4. WAN Link (2 hosts): Needs 4-block → /30. Network: 10.50.2.192/30 (Range: 10.50.2.193 – 10.50.2.194, BC: 10.50.2.195).
Drill 4: Route Aggregation Forensic BGP / OSPF Supernet
A core router receives route advertisements for:
• 10.100.16.0/24
• 10.100.17.0/24
• 10.100.18.0/24
• 10.100.19.0/24
What is the most concise single summary route that encompasses all four routes?
• Binary analysis of Octet 3: 16 (00010000), 17 (00010001), 18 (00010010), 19 (00010011)
• The first 6 bits of the 3rd octet match (000100xx).
• Common Prefix: 8 + 8 + 6 = /22
• Summarized Route: 10.100.16.0/22 (Covers 10.100.16.0 through 10.100.19.255).
Drill 5: Overlapping Subnet Conflict Triage Troubleshooting
HQ uses 10.10.16.0/20. A newly acquired remote branch is configured with 10.10.24.0/22. The network engineer reports asymmetric routing and unreachable hosts.
1. Does the branch subnet overlap with HQ?
2. What is the exact range of both allocations?
3. How should this conflict be resolved?
• HQ /20 Range: 10.10.16.0 through 10.10.31.255 (Block size 16 in octet 3: 16 to 31).
• Branch /22 Range: 10.10.24.0 through 10.10.27.255.
• Overlap Diagnosis: YES! 10.10.24.0/22 is completely contained inside HQ's 10.10.16.0/20 address space.
• Resolution: Re-IP the branch to a distinct non-overlapping RFC 1918 block (e.g. 10.10.32.0/22 or 172.16.24.0/22) or implement 1:1 NAT / Policy-Based NAT at the IPsec edge tunnel.
Drill 6: Cisco Wildcard Mask for ACLs & OSPF Cisco ACL / OSPF
You need to write an extended ACL on a core router permitting traffic from subnet 172.16.64.0/19 to any destination.
1. What is the subnet mask for a /19?
2. What is the inverted wildcard mask?
3. Write the exact Cisco IOS ACL statement.
• Subnet Mask (/19): 255.255.224.0
• Wildcard Mask: 255.255.255.255 − 255.255.224.0 = 0.0.31.255
• Cisco IOS Statement:
access-list 101 permit ip 172.16.64.0 0.0.31.255 any• OSPF Area 0 Statement:
network 172.16.64.0 0.0.31.255 area 0
Drill 7: IPv6 Subnetting & /64 Global Unicast IPv6 Allocation
Your organization receives the global routing prefix 2001:db8:acad::/48 from the RIR (Regional Internet Registry). Standard practice requires creating /64 subnets for SLAAC.
1. How many /64 subnets can be carved from a /48?
2. Provide the first 3 subnet IDs for DMZ, Internal LAN, and Guest Wi-Fi.
• Subnet bits available: 64 − 48 = 16 bits (the 4th hextet).
• Total /64 Subnets: 2^16 = 65,536 subnets.
• Subnet 1 (DMZ): 2001:db8:acad:0001::/64 (or
2001:db8:acad:1::/64)• Subnet 2 (Internal LAN): 2001:db8:acad:0002::/64 (or
2001:db8:acad:2::/64)• Subnet 3 (Guest Wi-Fi): 2001:db8:acad:0003::/64 (or
2001:db8:acad:3::/64)
Drill 8: Lateral Movement & Broadcast Boundary Security SOC Incident
A threat actor compromises host 192.168.1.50/24 in the Marketing VLAN. They attempt an ARP spoofing attack against the Finance server at 192.168.2.10/24.
1. Can ARP broadcast frames cross the Layer 3 boundary between 192.168.1.0/24 and 192.168.2.0/24 without a router?
2. Why does proper subnetting and Layer 3 micro-segmentation mitigate direct Layer 2 ARP poisoning?
• 1. No. ARP requests are broadcast frames (FF:FF:FF:FF:FF:FF) confined to their local Layer 2 broadcast domain (VLAN). Switches do not forward broadcasts across different subnets/VLANs.
• 2. Security Impact: Because the Finance server is in a different subnet (192.168.2.0/24), the compromised host must send its traffic to the Default Gateway at Layer 3. The gateway router/firewall inspects IP and transport headers and enforces ACL policies, preventing the attacker from sniffing or spoofing the Finance server's MAC address directly.