IPv4 and IPv6 Addressing: CIDR and Subnetting
Read IPv4 and IPv6 prefixes, calculate subnet membership, plan routes, and avoid CIDR overlap with practical examples in Python and production network design.
This guide explains how IPv4 and IPv6 prefixes define subnet membership and shape routing. It walks through CIDR calculations, aligned route aggregation, reserved ranges, IPv6 conventions, and dual-stack failure cases, with a Python example for checking an IPv4 network. Use the checklists and production scenarios to review address plans, find overlapping ranges, and trace routing or firewall problems before deployment.
IPv4 and IPv6 Addressing: CIDR and Subnetting
IP addresses identify interfaces at the network layer. A prefix tells you which leading bits describe the network and which bits vary between addresses. That simple boundary drives subnet membership, routing, access rules, and address planning.
This guide works through IPv4 and IPv6 notation, practical address ranges, and a few calculations you can verify locally. The goal is to read a prefix and know what it means for a packet or a route, rather than memorize a host-count formula.
Introduction
IP addresses identify interfaces, while prefixes define which addresses belong to a network and how routers aggregate routes. Sound IPv4 and IPv6 allocation prevents overlapping ranges, wasted address space, and reachability problems as an environment grows.
This guide explains prefix notation, subnet membership, allocation, and route aggregation, with practical checks for planning and troubleshooting. It also covers IPv6 and dual-stack concerns that can be missed when teams assume every client follows the same address family.
When to Use
Use CIDR when you need to allocate address space, decide whether two endpoints share a subnet, write firewall or cloud network rules, or understand a routing table. It also makes route aggregation possible: advertise one larger block when it exactly covers several smaller adjacent blocks.
IPv4 private ranges are commonly used inside networks that are not directly routed on the public internet:
10.0.0.0/8172.16.0.0/12(from172.16.0.0through172.31.255.255)192.168.0.0/16
Private does not mean protected. A private address can still be reachable by any system with a route and permissive security rules. NAT is common at the internet edge, but it does not replace firewall policy.
Other ranges worth recognizing include 127.0.0.0/8 for IPv4 loopback, 169.254.0.0/16 for IPv4 link-local, and 100.64.0.0/10 for shared carrier-grade NAT space. 192.0.2.0/24, 198.51.100.0/24, and 203.0.113.0/24 are documentation ranges; they are useful in examples and should not be treated as reachable production destinations.
IPv6 commonly uses global unicast addresses from 2000::/3, unique local addresses from fc00::/7 (often fd00::/8 in locally assigned networks), and link-local addresses from fe80::/10. ::1 is loopback, :: is the unspecified address, and ff00::/8 is multicast. 2001:db8::/32 is reserved for documentation. IPv6 has no broadcast address; multicast and neighbor discovery fill related roles.
When NOT to Use
Do not infer security boundaries from address labels alone. A private CIDR is not an authorization rule, and a globally scoped IPv6 address is not automatically reachable through every router or firewall.
Avoid copying a prefix from an example into production without checking all connected networks, VPNs, peering links, container networks, and partner ranges. A syntactically valid subnet can still collide with another network and create ambiguous routing.
Do not use IPv4 broadcast assumptions to plan IPv6 subnets. Many IPv6 LANs use /64, while point-to-point links may use /127; IPv6 has no broadcast address and address counts do not tell you the number of assigned hosts.
Reading prefixes and calculating membership
For IPv4, /26 means 26 network bits and 6 remaining bits. The block size is 64 addresses in the last octet when the first three octets are fixed. Therefore 192.168.10.77/26 belongs to 192.168.10.64/26, covering 192.168.10.64 through 192.168.10.127.
On a conventional IPv4 broadcast subnet with a /30 or shorter prefix length, the lowest address is the network identifier and the highest is the directed broadcast address. But this is not a universal usable-host rule: /31 is defined for point-to-point links, where both addresses can be used, and /32 identifies one address, often as a host route. Check the link type and platform behavior before allocating addresses.
IPv6 addresses have eight groups of four hexadecimal digits. Leading zeroes in a group may be omitted, and one consecutive run of zero groups can be compressed as :::
2001:0db8:0000:0000:0000:0000:0000:0042becomes2001:db8::42.2001:db8::/32describes all addresses whose first 32 bits match that prefix.
IPv6 subnet sizes are expressed in the same bit-based way. A /64 leaves 64 interface identifier bits; it does not imply that a network should assign every possible address. A /128 is a single address route. A /127 is commonly used for point-to-point router links under the relevant operational guidance. Do not apply the IPv4 network-and-broadcast subtraction rule to IPv6.
A practical IPv4 subnet check with Python’s standard library:
from ipaddress import ip_address, ip_network
network = ip_network("192.168.10.77/26", strict=False)
address = ip_address("192.168.10.100")
other = ip_address("192.168.10.130")
print(network)
print(network.network_address, network.broadcast_address)
print(address in network)
print(other in network)
Expected output:
192.168.10.64/26
192.168.10.64 192.168.10.127
True
False
strict=False tells Python to normalize the host address to its containing network. If you use strict=True (the default), ip_network("192.168.10.77/26") raises ValueError because .77 is not the network boundary. For IPv6, substitute an IPv6 address and prefix, such as ip_network("2001:db8:42::9/64", strict=False).
Subnet membership and route aggregation
Two addresses belong to the same subnet when their first n bits match for a prefix of length n. For example, 10.20.4.8 and 10.20.4.200 are both in 10.20.4.0/24; 10.20.5.8 is not.
Route aggregation summarizes adjacent networks only when their boundaries align. 10.20.100.0/24 and 10.20.101.0/24 can be represented by 10.20.100.0/23. The /23 has one fewer network bit and covers exactly both /24 blocks. By contrast, 10.20.100.0/24 and 10.20.102.0/24 cannot be represented by one /23: that would also include 10.20.101.0/24.
In operations, aggregation reduces route-table size but can hide reachability detail. If a summary route points traffic toward a site that does not actually contain one of its component networks, packets can black-hole. Keep summary routes aligned with the network topology and use more-specific routes where needed.
For route and firewall troubleshooting, it helps to understand how the address plan interacts with ports and firewall rules and network security and segmentation. Addressing tells you where traffic may be routed; policy decides whether it is allowed.
Production Failure Scenarios
Overlapping networks after a VPN connection
A company uses 10.0.0.0/16 in its cloud VPC. A laptop user connects to a partner VPN that also advertises 10.0.0.0/8. Traffic for cloud services may follow the partner route, depending on the local routing table. The application reports timeouts, but the actual failure is a CIDR collision. Reserve address ranges across environments and inspect effective routes when VPN behavior changes.
A summary route attracts traffic for a missing subnet
A branch advertises 172.20.0.0/16, but its local networks only use part of that block. A more-specific route is removed during a migration. Traffic to the withdrawn subnet still follows the summary route and disappears at the branch. Route aggregation must reflect which component networks are actually reachable.
A subnet rule misses IPv6
An operations team restricts service access to an IPv4 allowlist and assumes the service is private. The host also has a global IPv6 address, and the firewall allows the service port over IPv6. Clients can bypass the intended IPv4-only control. Review IPv4 and IPv6 routes and filtering policies together.
Trade-Off Table
| Choice | Advantages | Costs and risks |
|---|---|---|
Smaller IPv4 subnets, such as /24 |
Easier to reason about and limit broadcast domains | More subnets and routes to manage; address space can be wasted |
Larger IPv4 blocks, such as /16 |
Flexible allocation and fewer summary routes | Broad rules can grant more reachability than intended |
IPv6 /64 LANs |
Standard fit for common IPv6 host configuration and neighbor discovery | Large address count; inventory and scanning assumptions must change |
| Route aggregation | Smaller routing tables and simpler advertisements | A summary can attract traffic to unavailable component networks |
| Dual stack | Supports IPv4 and IPv6 clients during migration | Two routing and policy paths must be operated and monitored |
Observability Checklist
- Record the source and destination IP, address family, selected route, and interface for failed connections.
- Inspect the effective route table on the client and the next-hop router; do not stop at the configured route source.
- Compare firewall, security group, and network policy rules for both IPv4 and IPv6.
- Alert on unexpected route advertisements, duplicate address detection events, and changes to subnet allocations.
- Track connection failures by address family. A working IPv4 path can hide a broken IPv6 path, or the reverse.
- When a route is summarized, verify that each advertised component network is reachable through the summary next hop.
For latency symptoms, pair route inspection with the measurements in network performance basics. A route can be correct while the path still has loss, congestion, or an overloaded interface.
Security and Compliance Notes
Treat address allocation as part of access design. Keep public ingress narrow, document why each allowed CIDR exists, and remove stale ranges when vendors, office networks, or temporary environments change.
IPv6 must receive the same firewall review as IPv4. Disabling IPv6 on one host does not prove that the network has no IPv6 path; routers, cloud interfaces, and managed services may still use it. Confirm the actual interfaces, routes, and policy enforcement points.
CIDR membership is not identity. If a control must distinguish users or workloads, use authenticated identities and application-layer authorization in addition to network filtering. For regulated systems, retain change records for address allocations and network rules so reviewers can trace who approved a path and why.
Common Pitfalls / Anti-Patterns
- Treating private ranges as trusted. RFC1918 addresses can cross a flat internal network or VPN. Enforce least-privilege rules between segments.
- Assuming every IPv4 subnet loses two addresses.
/31point-to-point links use both addresses;/32represents one address. Check the actual link and route semantics. - Assuming IPv6 uses a broadcast address. It does not. Use IPv6 multicast and neighbor discovery concepts when troubleshooting local delivery.
- Allocating the same block in connected environments. Overlap makes route choice ambiguous and complicates VPNs, peering, and mergers.
- Aggregating non-aligned blocks. The aggregate may include addresses you did not intend to route. Verify the exact range with an IP calculator.
- Checking only one address family. Dual-stack applications can succeed on one path and fail on the other, which makes intermittent reports confusing.
- Using an arbitrary IPv6 prefix length for a LAN. Follow the host, router, and provider requirements for the link instead of treating IPv6 as IPv4 with longer addresses.
Quick Recap Checklist
- Read
/nas the number of leading network bits: 32 total in IPv4 and 128 in IPv6. - Normalize an address with a host-bit suffix before deciding which network it belongs to.
- Use longest-prefix match to explain which route wins.
- Confirm that aggregated networks are adjacent, aligned, and reachable through the advertised next hop.
- Check for CIDR overlap before connecting VPCs, VPNs, containers, or partner networks.
- Review IPv4 and IPv6 firewall rules, routes, and monitoring as separate paths.
Interview Questions
It means the first 26 of the 32 IPv4 bits identify the network. With host bits cleared, the containing network is 192.168.10.64/26, which spans 192.168.10.64 through 192.168.10.127.
On a conventional broadcast subnet, `.64` is the network address and `.127` is the directed broadcast address. That convention should not be generalized to `/31` point-to-point links or `/32` host routes.
It uses longest-prefix match. The `/24` has more matching leading bits, so it is the more specific route and wins when both routes are otherwise eligible. Route preference and policy can still affect which routes enter the forwarding table.
That shortcut assumes a conventional IPv4 broadcast subnet. IPv4 `/31` point-to-point links can use both addresses, and `/32` is a single-address route. IPv6 has no broadcast address, and a prefix's size does not directly tell you how many interfaces a network should assign.
They must be contiguous and aligned on a `/23` boundary. For example, 10.20.100.0/24 and 10.20.101.0/24 together cover exactly 10.20.100.0/23. A gap or misaligned pair would make the summary include additional addresses.
Expected answer points:
- The summary still advertises a larger block that includes the removed subnet.
- Routers forward traffic for that subnet toward the summary next hop even though no reachable component network exists there.
- Update the summary to match reachable networks or install and verify an appropriate more-specific route.
Expected answer points:
- The local network and VPN may use overlapping private CIDR ranges.
- The effective route can send a destination to the VPN or another interface instead of the intended network.
- Inspect the client's installed routes and reserve non-overlapping ranges across connected environments.
Expected answer points:
- A service may have a global IPv6 address even when operators only considered its IPv4 address.
- A permissive IPv6 route or firewall rule can provide a path around an IPv4-only restriction.
- Review routes and enforcement rules for both address families at the host, cloud, and network boundaries.
Expected answer points:
- It requires the supplied address to have all host bits cleared for the stated prefix.
- An address such as `192.168.10.77/26` raises `ValueError` because `.77` is not the `/26` network boundary.
- Use `strict=False` when you intentionally want the library to normalize an address to its containing network; keep strict validation when input should already be a network boundary.
Further Reading
- RFC 4632: Classless Inter-domain Routing (CIDR) explains address allocation and route aggregation.
- RFC 8200: Internet Protocol, Version 6 (IPv6) Specification defines IPv6 packet processing.
- RFC 4291: IP Version 6 Addressing Architecture describes IPv6 address types and architecture.
- The Computer Networks Roadmap places addressing between packet delivery and routing, then connects it to transport, troubleshooting, and security.
Conclusion
A CIDR prefix marks the network bits shared by addresses. Use that boundary to calculate subnet membership and understand longest-prefix route selection. Plan IPv4 and IPv6 ranges together, account for special ranges and link conventions, and check connected networks for overlap before deployment. Small scripts can verify calculations, but production routing still depends on the routes and policies installed across the whole path.
Category
Related Posts
Ethernet, ARP, and Neighbor Discovery Explained
Learn how Ethernet frames, switches, VLANs, ARP, and IPv6 Neighbor Discovery deliver packets on a local link, with Linux diagnostics and failure examples.
Network Encapsulation: Follow a Packet Across the Stack
Follow an HTTPS request from a browser through transport, IP, and link layers, and learn how headers, MTU, routers, and packet captures fit together.
Forward and Reverse Proxies: Routing, Trust, and Use Cases
Learn how forward and reverse proxies handle HTTP traffic, CONNECT tunnels, TLS termination, caching, routing, trusted headers, and production failures.