CIDR
Classless Inter-Domain Routing
- Pronunciation
- SY-der
In short
CIDR (Classless Inter-Domain Routing) writes an IP range as an address and prefix length, like 10.0.0.0/16; the prefix counts the leading network bits.
What is CIDR notation?
Before 1993, IPv4 addresses were handed out in fixed classes: class A networks had about 16 million addresses, class B about 65 thousand, class C 256. Most organizations needed something in between, which wasted huge numbers of addresses. CIDR replaced the classes with prefixes of any length, so networks can be sized to fit.
In 192.168.1.0/24, the /24 means the first 24 of the 32 bits are the network part, leaving 8 bits for hosts: 256 addresses, of which 254 are usable for devices in a classic subnet. Each step changes the size by a factor of two: a /16 has 65,536 addresses, a /28 has 16, and a /32 is a single address. The same notation works for IPv6, where a /64 is the usual subnet.
CIDR is everywhere in infrastructure work. Cloud virtual networks and their subnets are defined as CIDR blocks, firewall and security group rules allow traffic from ranges such as 203.0.113.0/24, and Kubernetes assigns pod and service ranges the same way. Routers also aggregate many smaller routes into one shorter prefix, which keeps internet routing tables manageable.
A common misconception is that CIDR blocks can start anywhere. The network address must align with the prefix: 10.0.0.0/16 is valid, while 10.0.5.0/16 is really the same block written incorrectly. Planning non-overlapping ranges early also matters, because connecting two networks that use the same private range later is painful.
Key takeaways
- CIDR writes a range as an address plus a prefix length, such as /24.
- The prefix is the number of leading bits that identify the network.
- A /24 has 256 addresses, a /16 has 65,536 and a /32 is one address.
- It replaced fixed address classes in 1993.
- Cloud networks, firewall rules and Kubernetes all use CIDR blocks.
Example
import ipaddress
vpc = ipaddress.ip_network("10.0.0.0/16")
print(vpc.num_addresses) # 65536
# Split the VPC into /24 subnets
subnets = list(vpc.subnets(new_prefix=24))
print(subnets[0], subnets[1], len(subnets)) # 10.0.0.0/24 10.0.1.0/24 256
web = ipaddress.ip_network("10.0.1.0/24")
print(web.netmask, web[1], web[-2]) # 255.255.255.0 10.0.1.1 10.0.1.254
print(ipaddress.ip_address("10.0.1.77") in web) # TrueReaders ask
What does /24 mean in an IP address?
That the first 24 bits are the network prefix, the same as the subnet mask 255.255.255.0. The remaining 8 bits give 256 addresses in the block.
How many addresses are in a CIDR block?
Two to the power of the bits left over. For IPv4 that is 2^(32 − prefix): a /24 has 256, a /20 has 4,096 and a /16 has 65,536.
What is the difference between CIDR and a subnet mask?
They express the same thing differently. The subnet mask 255.255.255.0 and the prefix /24 both say the first 24 bits are the network. CIDR notation is shorter and also used for IPv6.
See also
- SubnetNetworking, p. 29A subnet is a smaller network carved out of a larger one by splitting its range of IP addresses, which keeps traffic organized, contained, and easier to secure.
- IPv4Networking, p. 11IPv4 is the internet's original addressing system, using 32-bit addresses written as four numbers such as 192.168.1.10, allowing about 4.3 billion addresses.
- IP AddressNetworking, p. 10An IP address is a numeric label assigned to each device on a network so that data can be routed to it, much like a postal address for a house.
- RouterNetworking, p. 25A router is a networking device that forwards packets between different networks, choosing the next hop for each one based on its destination IP address.
- FirewallNetworking, p. 8A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.
- IPv6Networking, p. 12IPv6 is the newest version of the Internet Protocol, using 128-bit addresses that give every device a unique address and replace the exhausted IPv4 pool.
Spotted a mistake or something missing on this page?Suggest an edit