Subnet increments and worked examples

The increment (block size)

Subnets step by the place value of the last borrowed bit, also called the block size: how many addresses each subnet spans in that octet. Land the last bit on 128 and subnets step by 128; on 64, by 64; and so on down the chart to 1.

The shortcut: 256 minus the interesting mask octet gives the same number.

The first subnet is subnet zero: all subnet bits set to 0, the same address as the original network.

To list subnets: start at the network address, keep adding the increment in the octet where borrowing stopped.

Example 1: borrow 8 bits from /16 (making /24s)

172.16.0.0/16, borrowing all 8 bits of the third octet. The mask is 255.255.255.0, the last borrowed bit’s value is 1, so subnets step by 1 in the third octet. That’s 2^8 = 256 subnets with 2^8 - 2 = 254 hosts each.

console
Subnet          Hosts                Broadcast
172.16.0.0      .0.1  - .0.254      172.16.0.255
172.16.1.0      .1.1  - .1.254      172.16.1.255
172.16.2.0      .2.1  - .2.254      172.16.2.255
...
172.16.255.0    .255.1 - .255.254   172.16.255.255

Example 2: borrow 2 bits from /16 (making /18s)

Mask 255.255.192.0, last borrowed bit value 64, so subnets step by 64 in the third octet. That’s 2^2 = 4 subnets with 2^14 - 2 = 16,382 hosts each. The last subnet is 192, because 192 + 64 = 256, past the top of the octet.

console
Subnet          Hosts                          Broadcast
172.16.0.0      172.16.0.1   - 172.16.63.254   172.16.63.255
172.16.64.0     172.16.64.1  - 172.16.127.254  172.16.127.255
172.16.128.0    172.16.128.1 - 172.16.191.254  172.16.191.255
172.16.192.0    172.16.192.1 - 172.16.255.254  172.16.255.255

Note the host range crosses third-octet values: each /18 subnet owns 64 whole third-octet values, and the fourth octet runs 0-255 inside every one of them.

Example 3: borrow 11 bits from /16 (making /27s, crossing an octet)

Mask 255.255.255.224: all 8 bits of the third octet plus 3 of the fourth. The last borrowed bit’s value is 32, and it sits in the fourth octet, so the increment applies there first. That’s 2^11 = 2048 subnets with 2^5 - 2 = 30 hosts each.

Walk the fourth octet by 32s (0, 32, 64 … 224), then roll the third octet up by 1 and start the fourth octet over at 0.

console
Subnet           Hosts                 Broadcast
172.16.0.0       .0.1    - .0.30      172.16.0.31
172.16.0.32      .0.33   - .0.62      172.16.0.63
172.16.0.64      .0.65   - .0.94      172.16.0.95
...
172.16.0.224     .0.225  - .0.254     172.16.0.255
172.16.1.0       .1.1    - .1.30      172.16.1.31
172.16.1.32      .1.33   - .1.62      172.16.1.63
...
172.16.255.224   .255.225 - .255.254  172.16.255.255

VLSM preview

Variable Length Subnet Masking means mixing prefix lengths in one design: some /24s, some /22s, a /26 for a small segment. It avoids burning a whole classful block per network.

It’s called classless because the mask no longer matches the class (a /24 on a Class B range, for example).

Related: borrowing bits and the subnet formulas, subnet masks and the AND operation.