Subnet Mask Converter

Convert between CIDR prefix length, dotted-decimal subnet mask and wildcard mask, with the binary representation of each.

Runs entirely in your browser. Your input is never sent to our servers.

Prefix length
/24
Subnet mask
255.255.255.0
Wildcard mask
0.0.0.255
Addresses in block
256
Usable hosts
254
Mask in binary
11111111.11111111.11111111.00000000
Hex mask
0xFFFFFF00

What is Subnet Mask Converter?

A subnet mask converter translates between the three interchangeable ways of writing the same IPv4 network boundary: a CIDR prefix length such as /24, a dotted-decimal mask such as 255.255.255.0, and a wildcard mask such as 0.0.0.255.

What this Subnet Mask Converter does

All three notations describe one 32-bit value. The prefix length counts the leading one-bits; the dotted mask writes those bits out in decimal; the wildcard mask is the bitwise inverse. This converter accepts whichever form you have and derives the rest, along with the block size, the usable host count, the binary layout and the hexadecimal value.

It also rejects masks that cannot exist. A valid IPv4 mask has its one-bits contiguous from the left, so 255.255.0.255 is a well-formed address but not a legal mask — a distinction most converters quietly ignore.

How to use it

  1. Enter a prefix length (/26), a dotted mask (255.255.255.192) or a wildcard (0.0.0.63).
  2. The tool works out which notation you used, so there is nothing to select.
  3. Read across for the other forms, the address count and the usable host count.
  4. Use the copy buttons to paste directly into a router, firewall or DHCP configuration.

Understanding your results

Addresses in block — every address the prefix covers, including the network and broadcast addresses.

Usable hosts — normally two fewer, because the first and last addresses name the network and the broadcast domain rather than an interface.

Wildcard mask — the inverse. Cisco access lists and OSPF network statements take a wildcard, not a mask, and swapping the two is a classic reason a rule silently matches nothing at all.

Mask in binary — where the network part ends and the host part begins. Reading this is the fastest way to see why /26 gives four subnets of 62 hosts rather than some other split.

Why this matters

Subnetting is difficult to undo. A block chosen too small forces renumbering across DHCP scopes, firewall rules, monitoring targets and documentation, usually under time pressure. A block far too large wastes space and, on a flat segment, enlarges both the broadcast domain and the reach of anything moving laterally inside it.

The security consequence of an arithmetic slip is quiet. A rule written against 10.0.0.0/16 when the author meant 10.0.0.0/24 admits 255 times more address space than intended, and nothing in the syntax will object.

Common mistakes

Using a wildcard where a mask belongs. 0.0.0.255 and 255.255.255.0 describe the same boundary but are not interchangeable in configuration syntax.

Assuming a /31 has no usable hosts. On point-to-point links RFC 3021 makes both addresses usable, which is why it is the conventional choice for router-to-router links.

Treating /24 as a rule rather than a habit. Nothing requires networks to fall on octet boundaries; /22 and /26 are ordinary and often the better fit.

Limitations

IPv4 only. IPv6 uses prefix lengths in the same way but across 128 bits, with no broadcast address and different conventions for host counts.

This describes what a mask means, not how your network is configured. It cannot tell you whether a range is already allocated, routed or filtered.

Frequently asked questions

Why does a /24 have 256 addresses but only 254 hosts?

The first address identifies the network itself and the last is the broadcast address for the segment. Neither can be assigned to an interface, so 256 addresses yield 254 assignable hosts.

What is a wildcard mask for?

It is the bitwise inverse of a subnet mask, used by Cisco access control lists and OSPF network statements. A zero bit means "must match" and a one bit means "ignore" — the opposite convention to a subnet mask.

Is 255.255.0.255 a valid subnet mask?

No. A valid IPv4 mask has all its one-bits contiguous from the left. That value is a legal address but cannot describe a network boundary, and this converter rejects it.

Can I really use a /31 on a link?

Yes, on point-to-point links. RFC 3021 defines the behaviour: there is no network or broadcast address, so both addresses are assignable. It halves the address waste compared with a /30.

References

Last reviewed