Variable-length subnet masks
VLSM Subnet Planner
Give a parent block and the hosts each subnet needs. Subnets are sized to fit and packed from the start of the block, largest first.
Saved plans (stored in this browser)
Allocation
parent 192.168.1.0/24 subnets 4 allocated 212 of 256 (82.8%) free 44
Largest first: Sales takes the first /25 (128 addresses), so every smaller block that follows starts on a multiple of its own size with no gaps.
| Name | Hosts | Subnet | Netmask | Usable range | Broadcast | Usable | Unused |
|---|---|---|---|---|---|---|---|
| Sales | 120 | 192.168.1.0/25 | 255.255.255.128 | 192.168.1.1 – 192.168.1.126 | 192.168.1.127 | 126 | 6 |
| Eng | 50 | 192.168.1.128/26 | 255.255.255.192 | 192.168.1.129 – 192.168.1.190 | 192.168.1.191 | 62 | 12 |
| Mgmt | 10 | 192.168.1.192/28 | 255.255.255.240 | 192.168.1.193 – 192.168.1.206 | 192.168.1.207 | 14 | 4 |
| P2P | 2 | 192.168.1.208/30 | 255.255.255.252 | 192.168.1.209 – 192.168.1.210 | 192.168.1.211 | 2 | 0 |
Free blocks: 192.168.1.212/30 192.168.1.216/29 192.168.1.224/27
Split tree
Each split halves a block. Select a split to fold or unfold it.
Export
name,hostsRequested,cidr,netmask,firstHost,lastHost,broadcast,usableHosts,wasted Sales,120,192.168.1.0/25,255.255.255.128,192.168.1.1,192.168.1.126,192.168.1.127,126,6 Eng,50,192.168.1.128/26,255.255.255.192,192.168.1.129,192.168.1.190,192.168.1.191,62,12 Mgmt,10,192.168.1.192/28,255.255.255.240,192.168.1.193,192.168.1.206,192.168.1.207,14,4 P2P,2,192.168.1.208/30,255.255.255.252,192.168.1.209,192.168.1.210,192.168.1.211,2,0
What VLSM is
Variable Length Subnet Masking gives each subnet the prefix length its host count needs. Without it, every subnet in a network has the same size, so a two-router link takes as much space as a 120-host office. With it, the office gets a /25 and the link a /30 (or /31), and the space between them stays free for later.
How the planner allocates
- For each request, find the smallest block whose usable hosts cover it: hosts + 2 rounded up to a power of two. 120 hosts need 122 addresses, so the block is 128, a
/25. - Sort the requests from largest to smallest. Requests of equal size keep the order you entered.
- Place each block at the next free address. Because the blocks shrink as you go, each one starts on a multiple of its own size, which is what a valid subnet needs.
- Whatever is left is listed as free CIDR blocks. If a request does not fit, the planner names it and suggests the smallest parent that would hold everything.
Capacity rule changes the math, not just the label. The generic rule reserves the network and broadcast addresses, and the /31 and /32 options give two-host links and single-host requests (loopbacks, host routes) their smallest legal blocks. AWS VPC and Azure VNet reserve five addresses per subnet (the first four and the last) and enforce a minimum size (/28 and /29); Google Cloud reserves the first two and the last two and enforces /29. The first and last usable address in the table follow those positions, and AWS also caps a subnet at /16, so a request that would need a larger block is rejected. A 60-host request gets a /25 on AWS instead of a /26, and the cloud exports show no warnings because the plan was built under the same rule.
To check one of the subnets in detail, open it in the subnet calculator. The subnetting tutorial works through a VLSM design by hand. For fixed, ready-to-read plans, see the AWS three-tier VPC and Azure hub-spoke examples.
Questions
What is VLSM?
Variable Length Subnet Masking means giving each subnet a prefix length that fits its own host count, instead of cutting a network into equal pieces. A 120-host LAN gets a /25 while a router link gets a /30, so less address space is wasted.
Why are the largest subnets allocated first?
Every subnet must start on a multiple of its own size. Placing the largest blocks first keeps each later, smaller block aligned with no gaps, so a set of requests fits whenever their total size fits in the parent.
How many hosts fit in a /27?
A /27 has 32 addresses and 30 usable hosts. The network and broadcast addresses are not assigned. 10.0.0.32/27
Should point-to-point links use /30 or /31?
A /30 gives two usable addresses plus a network and broadcast address. RFC 3021 allows a /31 on point-to-point links, using both addresses and saving two per link. This planner uses /30 by default and /31 when you turn the option on. A single-host request can use a /32 for a loopback or host route with the matching option.
Why does AWS show fewer usable addresses than the plan?
AWS and Azure reserve five addresses in every subnet: the first four and the last one. Google Cloud reserves four: the network address, the gateway, the second-to-last address and the broadcast. Choose a cloud under Capacity rule and the planner sizes, packs and reports the usable range under those rules, so the plan and the exports agree. AWS subnets also cannot be larger than /16, so a request that would need a bigger block is rejected. With the generic rule, the cloud exports flag subnets below the provider minimum (/28 on AWS, /29 on Azure and GCP) or that lose needed hosts to the reservation.
How does the Terraform export work?
It writes each subnet as cidrsubnet(base_cidr, newbits, netnum). newbits is the child prefix minus the parent prefix, and netnum is the index of the child block within the parent at that size, so the plan stays correct if base_cidr is changed.