← Networking
Technique Networking foundations

IPv4 addresses, prefixes, and subnetting

A VPN can be connected while a route still sends your request the wrong way.

A developer connects to the company VPN, but the staging dashboard still times out. At home, their laptop is 192.168.1.37/24. Staging also uses 192.168.1.0/24. The tunnel can be up while the route to staging points at the home Wi-Fi. We will inspect that choice, find the address overlap, and plan a range the two networks can route without ambiguity.

Follow the packet

A “connected” VPN status says the tunnel came up. The route table tells you where this destination will go. Read the address and prefix, then verify the selected path before changing the plan.

TypeScriptGo Address boundaries · membership · allocation
01 / Follow a failed VPN request

The VPN is connected, but the laptop thinks staging is at home.

The laptop has a local route for 192.168.1.0/24 through Wi-Fi. The VPN client also installs a route for staging at 192.168.1.0/24. Those ranges cover the same addresses. In this example, the active route lookup selects Wi-Fi, so a request for staging's 192.168.1.80 never enters the tunnel. The laptop treats that address as local and tries to find it on the home link instead of sending it to the VPN gateway.

The exact tie-breaking rule depends on the operating system and VPN client. The important evidence is the route actually selected on the affected laptop. A VPN icon alone cannot tell you whether this destination is using the tunnel.

Route selected for the staging request Illustrative Linux route lookup; interface names and route policy vary by device.
Source Developer laptop 192.168.1.37/24 Wi-Fi subnet: 192.168.1.0/24
selected path
Route lookup Home Wi-Fi dev wlan0 sample result: 192.168.1.80 dev wlan0
not reached
Intended destination Staging service 192.168.1.80 company network, behind VPN

The VPN also claims 192.168.1.0/24. The destination is inside both ranges, so the laptop's active route choice—not the VPN connection indicator—explains why this request misses the tunnel.

02 / Choose a block that fits

Move staging onto a range the home LAN does not use.

For a new staging environment, the team chooses 10.0.0.0/24 after checking that it does not overlap the connected office, VPN, or cloud networks. IPv4 has 32 bits, so a /24 leaves 8 host bits: 2^8 = 256 total addresses. Under conventional IPv4 subnet rules, the network and broadcast addresses are not assigned to hosts.

The service needs room for 100 API hosts, 50 workers, and 20 database hosts. Allocate the smallest power-of-two block that holds each group plus its two reserved addresses, then start each block on a boundary that matches its size.

One possible staging allocation, using conventional IPv4 reservations
WorkloadHosts neededBlockUsable capacityAssigned host range
API10010.0.0.0/2512610.0.0.1–10.0.0.126
Workers5010.0.0.128/266210.0.0.129–10.0.0.190
Database2010.0.0.192/273010.0.0.193–10.0.0.222
One /24 block, divided by address count Each segment’s width represents its share of the 256 addresses.
03 / Turn a prefix into a range

The slash counts fixed network bits—even when it cuts through an octet.

The dotted address is a readable form of 32 bits, grouped into four 8-bit octets. A /20 prefix fixes 16 bits in the first two octets and four more in the third. Its mask is 255.255.240.0: the third octet advances in blocks of 256 − 240 = 16.

Take 172.16.37.9/20. The third octet, 37, falls in the block from 32 through 47. The network begins at 172.16.32.0; the broadcast address is 172.16.47.255. The prefix is still a bit count even when its boundary is not a dot in the written address.

The same rule catches misleading string comparisons. 10.2.3.8 and 10.2.30.8 both start with the characters 10.2.3, but only the first belongs to 10.2.3.0/24. Membership means comparing the address bits selected by the mask.

For 192.168.4.6/30, two host bits remain, so the aligned block has four addresses: 192.168.4.4–192.168.4.7. Under the conventional rule, .4 is the network, .7 is the broadcast, and .5 and .6 are host addresses.

04 / Read the route decision

After the fix, the staging destination should use the VPN.

After staging moves, the VPN needs a route for 10.0.0.0/24. From the developer's laptop, traffic for 10.0.0.200 should select the VPN interface. Once the request reaches staging, the API at 10.0.0.10/25 makes a separate decision when calling the database at 10.0.0.200/27.

The API host sees that 10.0.0.200 is outside 10.0.0.0/25 and, with no more-specific host route, sends it to gateway 10.0.0.1 using its default route. The router then selects 10.0.0.192/27, the database subnet. Run ip route get 10.0.0.200 on both the laptop and API host: the laptop should select the VPN; the API host should select its gateway. Those are two route decisions at different points in the same conversation.

05 / Diagnose overlapping ranges

Connected networks need address ranges that route to one place.

The home and staging networks both claim 192.168.1.0/24. A route cannot distinguish which copy of 192.168.1.80 the user intended from the destination address alone. The laptop may select Wi-Fi or the tunnel according to route metrics and VPN policy; either way, the address plan is ambiguous across the connection.

For inclusive ranges [aStart, aEnd] and [bStart, bEnd], they overlap when aStart ≤ bEnd and bStart ≤ aEnd. Equality counts: ranges that share an endpoint overlap. Check each pair of connected networks, and check every child range stays inside its parent before installing routes or firewall rules.

Longest-prefix match chooses the most specific matching route. For nested ranges, that can direct traffic to the wrong segment: 10.0.0.64/26 can capture 10.0.0.100 from the broader 10.0.0.0/25. For exact duplicate prefixes like the home and staging ranges, the operating system and VPN policy choose between equally specific routes; the destination address cannot identify which network the user intended.

06 / Renumber and verify

A clean fix changes the plan and checks the route again.

For a new environment, allocate the non-overlapping parent range first, then divide it for the API, workers, and database. The example follows request order; each next block starts at the next boundary of its size. Stop at the parent network's end and report a request that cannot fit—never wrap into the next range.

First-fit in request order is easy to explain and preserves request order, but a different order can leave a different remainder. Sorting larger requests first can reduce fragmentation, while stable, reserved ranges may matter more for an established network. Pick and document the policy that fits the network’s ownership and growth plan.

Before rollout, check the new CIDRs against home, office, peer VPN, and cloud routes. Update the staging addresses, VPN's advertised routes, DNS records, firewall rules, and allowlists together. Then reconnect and repeat the route lookup from the affected laptop: the staging destination should select the VPN interface. If the route now uses the VPN and the service responds, that supports the overlap diagnosis. If the route changes but the service still times out, continue along the path and test the actual service port; the route alone does not prove the repair is complete.

This is easiest to fix before deployment. Renumbering a live network can require a migration plan; NAT can bridge some unavoidable overlaps, but it adds translation state and operational complexity.

07 / Practice in code

Calculate, check, and allocate IPv4 blocks.

Start with a subnet summary, then check membership and plan child networks. The tasks use bounded IPv4 cases and run the same checks in TypeScript and Go.

Networking practice 10 min

Find the address range behind a prefix

This is an experiment with ticket-style exercises, giving beginners a feel for how tasks may be described in the workplace. Leave feedback

Checking your sign-in status. Your lesson remains available while we check.

TypeScript Go

Networking practice 10 min

This is an experiment with ticket-style exercises, giving beginners a feel for how tasks may be described in the workplace. Leave feedback

Find the address range behind a prefix

TYPESCRIPT

Work item NET-204

Find the address range behind a prefix

Implementation exercise Ready

Context

The platform team received an IPv4 address and prefix from an address plan. They need the network and broadcast addresses plus the usable host range before assigning a service block.

Acceptance criteria
  1. AC-1Calculate the network boundary from the supplied address and prefix.
  2. AC-2Return the broadcast address, first and last usable host, and usable host count.
  3. AC-3Use conventional network and broadcast reservations for prefixes from /8 through /30.
Notes
  • The supplied address can be any address inside the subnet, not necessarily the network address.
  • This ticket scopes host ranges to /8 through /30; /31 point-to-point and /32 host routes have different conventions.
  • IPv4 contains four decimal octets, each from 0 through 255.

Copy the ticket to research the problem in your own notes or AI tool. Your code stays here.

Your implementation

Edit the function in the editor. Run the visible checks as often as you like; your code stays in this tab.

Checks cover

  • An address in a /24 maps to its full host range
  • A /30 leaves two usable host addresses
  • A wider prefix has the correct boundary