Subnet
- In Turkish
- Alt Ağ
In short
A subnet is a smaller network carved out of a larger one by splitting its range of IP addresses, which keeps traffic organized, contained, and easier to secure.
What is a subnet?
A subnet, short for subnetwork, is a logical slice of a larger IP network. Every IP address is split into two parts: a network prefix, which identifies the subnet, and a host part, which identifies a single device inside it. Devices in the same subnet can talk to each other directly, while traffic to any other subnet must go through a router.
Subnets are usually written in CIDR (Classless Inter-Domain Routing) notation, such as 192.168.1.0/24. The number after the slash is how many of the 32 bits in an IPv4 address belong to the network prefix, so /24 leaves 8 bits for hosts: 256 addresses, of which 254 are usable, because the first identifies the network itself and the last is the broadcast address. The same prefix can be written as a subnet mask, 255.255.255.0, which a device uses to decide whether a destination is local or must be sent to its default gateway, the router.
Think of a large office building: the street address gets mail to the building, and the floor number routes it to the right department. Cloud networks are divided into subnets too, typically public subnets for internet-facing load balancers and private subnets for databases and internal services, with firewall rules controlling traffic between them. Subnets also limit broadcast traffic and let you apply different security policies to different groups of machines.
A subnet is sometimes confused with a VLAN (virtual LAN). A subnet is a range of IP addresses at the network layer, while a VLAN separates devices at the data link layer, one layer below; in practice they are often paired one to one, but they are different things. Also remember that a larger prefix number means a smaller subnet: a /28 holds only 16 addresses, while a /16 holds 65,536.
Key takeaways
- A subnet is a range of IP addresses that forms a smaller network within a larger one.
- CIDR notation such as
10.0.1.0/24gives the network address and how many bits form the prefix. - A
/24IPv4 subnet has 256 addresses, of which 254 can be assigned to devices. - Traffic between different subnets must pass through a router.
- Cloud networks commonly use public subnets for internet-facing resources and private subnets for internal ones.
Example
import ipaddress
subnet = ipaddress.ip_network("192.168.1.0/24")
print(subnet.netmask) # 255.255.255.0
print(subnet.num_addresses) # 256
print(len(list(subnet.hosts()))) # 254 usable host addresses
# Is a device inside this subnet?
print(ipaddress.ip_address("192.168.1.42") in subnet) # True
print(ipaddress.ip_address("192.168.2.42") in subnet) # False
# Split the /24 into four smaller /26 subnets of 64 addresses each
for small in subnet.subnets(new_prefix=26):
print(small) # 192.168.1.0/26, 192.168.1.64/26, ...Readers ask
What does /24 mean in an IP address?
It is CIDR notation meaning that the first 24 bits of the address identify the network, leaving 8 bits for devices. A /24 IPv4 subnet therefore contains 256 addresses, 254 of which are usable for hosts.
What is a subnet mask?
A subnet mask is another way to write the network prefix, as a dotted number such as 255.255.255.0, which is the same as /24. A device compares it with a destination address to decide whether the destination is on the local subnet or must be sent to the router.
What is the difference between a public and a private subnet in the cloud?
A public subnet has a route to the internet, so resources in it, such as load balancers, can receive traffic from outside. A private subnet has no direct route from the internet, which makes it the usual home for databases and internal services.
See also
- IP AddressNetworking, p. 10An IP address is a numeric label assigned to each device on a network so that data can be routed to it, much like a postal address for a house.
- NATNetworking, p. 17NAT is a technique in which a router rewrites the IP addresses in passing packets, letting many devices on a private network share one public IP address.
- DHCPNetworking, p. 6DHCP is a network protocol that automatically gives devices an IP address and other settings, such as the router and DNS server, when they join a network.
- FirewallNetworking, p. 8A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.
- Cloud ComputingDevOps & Cloud, p. 10Cloud computing is the on-demand delivery of computing resources, such as servers, storage, and databases, over the internet with pay-as-you-go pricing.
- OSI ModelNetworking, p. 19The OSI model is a conceptual framework that splits network communication into seven layers, from physical cables up to the applications people use.
- CIDRNetworking, p. 4CIDR (Classless Inter-Domain Routing) writes an IP range as an address and prefix length, like 10.0.0.0/16; the prefix counts the leading network bits.
Spotted a mistake or something missing on this page?Suggest an edit