Variable-length subnet masks
VLSM Subnet Planner
Give a parent block and the hosts each subnet needs. Subnets are sized to fit and packed from the start of the block, largest first.
Allocation
parent 192.168.1.0/24 subnets 4 allocated 212 of 256 (82.8%) free 44
Largest first: Sales takes the first /25 (128 addresses), so every smaller block that follows starts on a multiple of its own size with no gaps.
| Name | Hosts | Subnet | Netmask | Usable range | Broadcast | Usable | Unused |
|---|---|---|---|---|---|---|---|
| Sales | 120 | 192.168.1.0/25 | 255.255.255.128 | 192.168.1.1 – 192.168.1.126 | 192.168.1.127 | 126 | 6 |
| Eng | 50 | 192.168.1.128/26 | 255.255.255.192 | 192.168.1.129 – 192.168.1.190 | 192.168.1.191 | 62 | 12 |
| Mgmt | 10 | 192.168.1.192/28 | 255.255.255.240 | 192.168.1.193 – 192.168.1.206 | 192.168.1.207 | 14 | 4 |
| P2P | 2 | 192.168.1.208/30 | 255.255.255.252 | 192.168.1.209 – 192.168.1.210 | 192.168.1.211 | 2 | 0 |
Free blocks: 192.168.1.212/30 192.168.1.216/29 192.168.1.224/27
Split tree
Each split halves a block. Select a split to fold or unfold it.
Export
name,hostsRequested,cidr,netmask,firstHost,lastHost,broadcast,usableHosts,wasted Sales,120,192.168.1.0/25,255.255.255.128,192.168.1.1,192.168.1.126,192.168.1.127,126,6 Eng,50,192.168.1.128/26,255.255.255.192,192.168.1.129,192.168.1.190,192.168.1.191,62,12 Mgmt,10,192.168.1.192/28,255.255.255.240,192.168.1.193,192.168.1.206,192.168.1.207,14,4 P2P,2,192.168.1.208/30,255.255.255.252,192.168.1.209,192.168.1.210,192.168.1.211,2,0
What VLSM is
Variable Length Subnet Masking gives each subnet the prefix length its host count needs. Without it, every subnet in a network has the same size, so a two-router link takes as much space as a 120-host office. With it, the office gets a /25 and the link a /30 (or /31), and the space between them stays free for later.
How the planner allocates
- For each request, find the smallest block whose usable hosts cover it: hosts + 2 rounded up to a power of two. 120 hosts need 122 addresses, so the block is 128, a
/25. - Sort the requests from largest to smallest. Requests of equal size keep the order you entered.
- Place each block at the next free address. Because the blocks shrink as you go, each one starts on a multiple of its own size, which is what a valid subnet needs.
- Whatever is left is listed as free CIDR blocks. If a request does not fit, the planner names it and suggests the smallest parent that would hold everything.
To check one of the subnets in detail, open it in the subnet calculator. The subnetting tutorial works through a VLSM design by hand.
Questions
What is VLSM?
Variable Length Subnet Masking means giving each subnet a prefix length that fits its own host count, instead of cutting a network into equal pieces. A 120-host LAN gets a /25 while a router link gets a /30, so less address space is wasted.
Why are the largest subnets allocated first?
Every subnet must start on a multiple of its own size. Placing the largest blocks first keeps each later, smaller block aligned with no gaps, so a set of requests fits whenever their total size fits in the parent.
How many hosts fit in a /27?
A /27 has 32 addresses and 30 usable hosts. The network and broadcast addresses are not assigned. 10.0.0.32/27
Should point-to-point links use /30 or /31?
A /30 gives two usable addresses plus a network and broadcast address. RFC 3021 allows a /31 on point-to-point links, using both addresses and saving two per link. This planner uses /30 by default and /31 when you turn the option on.
Why does AWS show fewer usable addresses than the plan?
AWS reserves five addresses in every subnet: the first four and the last one. Azure does the same. The AWS and Azure exports flag subnets that are below the provider minimum (/28 on AWS, /29 on Azure) or that lose needed hosts to the reservation.
How does the Terraform export work?
It writes each subnet as cidrsubnet(base_cidr, newbits, netnum). newbits is the child prefix minus the parent prefix, and netnum is the index of the child block within the parent at that size, so the plan stays correct if base_cidr is changed.