IPv4 Subnet Calculator
Find the network, broadcast, mask and usable address range for an IPv4 prefix.
Calculator / generatorPlan a subnet. Compare network lists. Prepare a firewall change.
Calculations stay in your browser. No accounts, ads or tracking scripts.
80 tools and references
Try a shorter task name or clear the filters to see the full directory.
Find the network, broadcast, mask and usable address range for an IPv4 prefix.
Calculator / generatorConvert an IPv4 prefix length into a contiguous dotted-decimal subnet mask.
Calculator / generatorValidate an IPv4 subnet mask and recover its prefix length.
Calculator / generatorConvert between a contiguous subnet mask and its inverse ACL wildcard.
Calculator / generatorCover an inclusive IPv4 range with the smallest exact set of CIDR blocks.
Calculator / generatorAggregate IPv4 or IPv6 CIDRs exactly, or calculate a covering supernet with explicit counts of extra address space.
Calculator / generatorDivide one IPv4 parent network into equal-size child subnets.
Calculator / generatorAllocate different-size IPv4 LAN subnets from a parent network.
Calculator / generatorCalculate an IPv6 network boundary, final address and exact address-space size.
Calculator / generatorNormalize IPv6 text and inspect all eight hexadecimal groups.
Calculator / generatorBuild IPv4 host reverse names and IPv6 host or nibble-aligned reverse-zone names.
Calculator / generatorCompare two IPv4 or IPv6 CIDR lists and get their exact intersection, differences, duplicates and containment relationships.
Calculator / generatorFind the TCP MSS option value for an IP MTU, and the room left for TCP data when options are present.
Calculator / generatorFind the inner IP packet size and ping data size that fit after reserving bytes for tunnel headers.
Calculator / generatorFind how many bytes IPsec adds to your packet and the resulting IP packet size.
Calculator / generatorEstimate file transfer duration with explicit file units and useful-throughput efficiency.
Calculator / generatorEstimate bytes in flight from bottleneck bandwidth and round-trip delay.
Calculator / generatorFind the Ethernet frames per second that fit a link rate, including the time used by preamble and the gap between frames.
Calculator / generatorEstimate optical path loss and spare margin from your transceiver and cable specifications.
Calculator / generatorConvert logarithmic power in dBm to milliwatts and back.
Calculator / generatorCalculate Ethernet frame size, tag cost, padding and payload efficiency.
Calculator / generatorGenerate FortiOS address objects from IPv4 lists or name,cidr CSV, preview the batch, and copy or download the CLI configuration.
Calculator / generatorCreate an IPv4 address group snippet from existing object names.
Calculator / generatorGenerate a TCP or UDP destination-port service object for FortiOS.
Calculator / generatorCheck whether selected IKEv2 encryption and integrity choices fit together, and identify the setting to change.
Calculator / generatorTranslate a three-digit Unix octal mode into owner, group and other permissions.
Calculator / generatorOne A4 page: every IPv4 prefix, mask, wildcard, address count, subnet boundaries and special-range reminders.
A4 referenceWork through original subnetting examples for boundaries, host capacity and address allocation.
A4 referenceRecognize common private, shared, loopback, documentation and local address ranges.
A4 referenceCommon service ports and transport choices in a printable reference.
A4 referenceUnderstand common DNS record types, TTLs and frequent configuration mistakes.
A4 referenceA one-page A4 reference for IPv6 notation, prefix sizes, address types, multicast and reverse DNS.
A4 referenceA one-page A4 reference for frame size, VLAN overhead, IP MTU, TCP MSS and tunnel budgeting.
A4 referenceOne A4 page explaining Wi-Fi generations, channel widths, spatial streams and PHY rates without promising Internet speeds.
A4 referenceOne A4 page of current /interface/wifi band selectors, package distinctions and channel-width syntax.
A4 referenceOne A4 field reference for selected European-relevant LTE and NR bands, duplex modes, frequency ranges and RouterOS selectors.
A4 referenceBuild a wired WAN-to-LAN setup with DHCP, a bridge, DNS, masquerade and explicit firewall protection.
Practical guideFix same-subnet hairpin NAT with a LAN destination rule and a scoped return-path translation; check external forwarding separately.
Practical guideAllow LAN Internet access, restrict SSH and WinBox to one administrator, and apply separate IPv4 and IPv6 firewall rules.
Practical guideStage RouterOS bridge VLANs and diagnose a management lockout: CPU-port membership, PVID, tagged uplinks, input policy and Safe Mode recovery.
Practical guideFix commands copied for the wrong wireless driver and set a supported channel width in the correct RouterOS menu.
Practical guideChoose the correct LTE/5G restriction and undo a band, cell or operator lock without confusing the three settings.
Practical guideSelect or restore LTE and NR bands with supported RouterOS properties while accounting for carrier aggregation and NSA anchors.
Practical guideRead the serving LTE cell, scan supported modems and collect the EARFCN/PCI pair needed for cell locking.
Practical guideChoose the documented LTE cell-lock family, query supported locks and understand reset, handover and carrier-aggregation limits.
Practical guideLock a supported modem to a measured 5G SA cell, query or clear the lock, and avoid applying it to an NSA connection.
Practical guideFix an ignored manual APN on an MBIM modem, restore registration after a bad lock, or separate LTE service from LAN forwarding.
Practical guideFind the fix for client DNS, hairpin NAT, lost VLAN management, FastTrack, WireGuard, LTE APN and device-mode errors.
Practical guideCheck model and port-group limits when H is missing, routing loads the CPU, or full L3 hardware offload bypasses firewall rules.
Practical guideDiagnose simple queues that do not limit traffic, missing packet marks and connections taking the wrong WAN when FastTrack is enabled.
Practical guideTrace allowed-address, routes, input versus forward rules and the return path when a RouterOS WireGuard peer handshakes but cannot reach the remote LAN.
Practical guideUse local-address-as-src-ip on RouterOS 7.17+ when the DHCP server path expects the relay address instead of the transit source.
Practical guideCheck DHCP-advertised DNS, allow-remote-requests, TCP and UDP 53, static records and application DNS when RouterOS resolves names but LAN clients fail.
Practical guideCompare endpoint-address and current-endpoint-address, NAT keepalive and responder roles after an LTE/5G or roaming endpoint changes.
Practical guideDiagnose resolving error, SSL errors and connection reset by peer using DoH bootstrap DNS, endpoint compatibility and certificate validation.
Practical guideFind the device-mode setting for the refused RouterOS tool, then enable the sniffer with physical confirmation. Handle flagged configuration separately.
Practical guideFix a RouterOS WireGuard import rejected because the configuration file begins with a comment.
Practical guideFix legacy IoT connection failures, congested channels, unintended speed limits and poor client coverage with the relevant UniFi setting.
Practical guideConfigure the SSID VLAN and trace missing DHCP through AP native/tagged ports, switch uplinks and the gateway while preserving AP management.
Practical guideBlock Guest access across VLANs and between clients on the same VLAN, while keeping intentional Trusted-to-IoT exceptions.
Practical guideCreate a specific trusted-to-IoT service allowance, order stateful replies and blocks, and keep gateway services separate.
Practical guideTrace failed UniFi port forwards through CGNAT or double NAT, WAN selection, the server listener and the return route.
Practical guideCheck Network application compatibility, management VLAN, TCP 8080 reachability and previous management before resetting an AP or switch.
Practical guideInvestigate “Multiple devices are using the same IP address”, static addresses inside DHCP pools and DHCP Guarding without blocking the legitimate server.
Practical guideUse AP uptime, PoE events and link changes to distinguish power loss, cable faults and management connectivity failures.
Practical guideSeparate service discovery from the application connection, scope the mDNS proxy and diagnose IoT discovery without opening every inter-VLAN service.
Practical guideDistinguish normal RSTP redundancy from Loop Protection or BPDU Guard shutdown, inspect wired and mesh paths, and recover without disabling loop protection globally.
Practical guideDiagnose FE instead of GbE on an AP, switch or gateway: verify negotiated speed, isolate cable and port faults, and separate link rate from Wi-Fi throughput.
Practical guideConvert an existing route-based FortiGate tunnel to IKEv2: phase 1 changes, peer IDs, Child SA selectors and common negotiation failures.
Practical guideCheck VDOM, inherited filters, log-filter versus log filter syntax and whether a negotiation is actually starting.
Practical guideTrace one new protected network through Child SA selectors, routing, policy, NAT and the destination host’s return path.
Practical guideTroubleshoot FortiGate management access using interface services, trusted hosts and local-in rule order, with a scoped CLI example.
Practical guideApply Fortinet’s scoped IPS-update memory workaround on 2 GB models and identify the related fixed high-CPU defect.
Practical guideFix an inter-VDOM policy-routing RPF drop when a suitable kernel return route cannot be used, with an exception on the receiving VDOM link.
Practical guideTroubleshoot cross-model FortiGate imports with config-error-log, interface dependency mapping and a comparison of the loaded configuration.
Practical guideTroubleshoot FortiGate proposal errors by tunnel selection, IKE/ESP transforms, PRF, DH, PFS and the failed negotiation stage.
Practical guideFix the PSK/local-user migration settings: enable EAP, restore policy groups and remove the conflicting tunnel-level group binding.
Practical guideMap overlapping VPN networks to distinct translated prefixes and align FortiGate selectors, routes, IP pools, VIPs and reverse traffic.
Practical guideDiagnose intermittent IPsec data loss using Child SA rekey, tunnel counters, routing and narrowly scoped hardware-offload issues.
Practical guideRemove an automatically created interface-subnet object or an obsolete packet-capture reference using the documented correction.
Practical guide10.42.7.93/26 belongs to 10.42.7.64/26. Its usable range is 10.42.7.65–10.42.7.126: 62 addresses. Open the subnet calculator to inspect the mask and broadcast address.