Learn by tracing / build real instincts
Read the path a packet takes.
Build a working mental model from address space to traffic decisions. Practice subnetting, forwarding, policy, wireless, and diagnosis in the same order a real network reveals them.
Live topology
Packet path
Scope → decision
CIDR /24
23
interactive labs
04
learning stages
01
prerequisite path
Learning path / 04 stages
Move from address space to traffic decisions
Each stage narrows the distance between a prefix on paper and a packet making a production decision. Start at the left, or jump to the signal you need.
Networking Foundations
Start with how hosts, bits, prefixes, and subnet boundaries work; then calculate and design IPv4 address space before moving on.
Stage signal
7 labs in scope
1. What is a Subnet?
A subnet (subnetwork) is a logical subdivision of an IP network. A prefix and mask define which addresses are on the local IP network and which destinations require a router. In common designs, each subnet is mapped to a VLAN or other Layer 2 segment, while routing and policy controls determine whether subnets can communicate.
Performance & Traffic Control
Switches and VLANs define the Layer 2 broadcast domain. Subnet boundaries give hosts an IP-level on-link scope, so ARP and DHCP broadcasts normally stay within the associated segment.
Enhanced Security Isolation
Subnetting provides an addressing boundary; it does not enforce security by itself. Firewalls, ACLs, routing policy, and identity controls must explicitly restrict access between sensitive and less-trusted networks.
Logical Addressing & Scale
A deliberate addressing hierarchy supports IPAM, route summarization, and predictable growth across buildings, sites, or cloud regions.
Network Topology Example: 192.168.1.0/24 Subnet Partitioning
A single private /24 CIDR block divided into 3 functional subnets with a central Layer 3 gateway router.
Management & Admin
Staff Workstations
IoT & Guest Wi-Fi
2. IP Addresses & Binary
Every IPv4 address is a 32-bit binary number represented in 4 decimal octets separated by dots. Understanding bit values, positional binary weights (128, 64, 32, 16, 8, 4, 2, 1), and bitwise operations is fundamental to networking.
Live 4-Octet Decimal to Binary Converter
Enter values from 0 to 255 for each octet to visualize their 8-bit binary representation in real time.
IPv4 Address Anatomy: Network ID vs Host ID
A subnet mask divides an IPv4 address into a network prefix and host portion. Hosts use this relationship to decide whether a destination is on-link; routers use destination prefixes during route lookup to choose a next hop.
RFC 1918 Private IPv4 Ranges
RFC 1918 designates three IPv4 blocks for private internets. The addresses may be reused by different organizations, and routing information for them should not cross inter-enterprise links.
| Class | CIDR Block | IP Address Range | Total Addresses | Typical Application |
|---|---|---|---|---|
| 10/8 block | 10.0.0.0 / 8 | 10.0.0.0 — 10.255.255.255 | 16,777,216 | Enterprise networks and cloud VPCs |
| 172.16/12 block | 172.16.0.0 / 12 | 172.16.0.0 — 172.31.255.255 | 1,048,576 | Enterprise networks and container bridges |
| 192.168/16 block | 192.168.0.0 / 16 | 192.168.0.0 — 192.168.255.255 | 65,536 | Home, SOHO, and local networks |
Classful vs CIDR Addressing
Historical Classful routing forced rigid network boundaries, leading to rapid IP address exhaustion. CIDR (Classless Inter-Domain Routing) introduced variable-length prefix masks.
| Feature | Legacy Classful Routing (Historical) | Modern CIDR (RFC 1519, obsoleted by RFC 4632) |
|---|---|---|
| Mask Allocation | Fixed class boundaries (/8, /16, /24) | Any prefix from /0 to /32 |
| Routing Protocol Support | RIPv1 and IGRP used classful updates (historical) | OSPF, BGP4, RIPv2, and IS-IS carry prefix information |
| IP Utilization Efficiency | Often wasteful for networks smaller than a class boundary | VLSM enables subnet sizing to match requirements |
| Route Table Aggregation | Limited to classful boundaries | Supports arbitrary aligned CIDR summaries |
Loopback Address Space
Reserved for host-internal network stack testing (127.0.0.1 / localhost). Traffic sent to loopback is handled by the host and does not reach a physical interface or switch port.
IPv4 Link-Local (APIPA)
A host may self-configure an IPv4 link-local address when no routable configuration is available. RFC 3927 limits communication to the same physical or logical link; it is not an Internet-routable fallback.
Bitwise AND Operation: Calculating Network Address
A bitwise AND between an IPv4 address and its subnet mask produces the address of the containing subnet. Hosts and routing software use this calculation when determining local scope and route matches.
3. CIDR & Subnet Masks — Interactive
CIDR (Classless Inter-Domain Routing) specifies how many leading bits in an IP address represent the network prefix. Adjust the slider or click any bit box below to interactively observe how changing prefix length affects subnet mask, bit allocation, total addresses, and usable host count.
Subnet Mask Bit Allocator
Selected Prefix: /24 (24 Network Bits, 8 Host Bits)
Usable Hosts Calculation Formula: 2h - 2
For an IPv4 subnet, use Usable Hosts = 2h - 2, where h = 32 - CIDR is the number of host bits.
4. Subnet Calculator
Enter an IPv4 address and select a CIDR prefix length to calculate subnet or route boundaries, usable address ranges, and subnet masks in real time.
Common Subnet Quick Reference
| CIDR | Subnet Mask | Usable Hosts | Typical Use |
|---|---|---|---|
| /16 | 255.255.0.0 | 65,534 | Large Enterprise / Cloud VPC |
| /24 | 255.255.255.0 | 254 | Standard Local Subnet (LAN / Office) |
| /25 | 255.255.255.128 | 126 | Medium Department (100+ devices) |
| /26 | 255.255.255.192 | 62 | Small Department / Server Rack |
| /27 | 255.255.255.224 | 30 | Branch Office / Small Workgroup |
| /28 | 255.255.255.240 | 14 | Management Network / DMZ Subnet |
| /30 | 255.255.255.252 | 2 | Point-to-Point Router Link |
| /31 | 255.255.255.254 | 2 | RFC 3021 Point-to-Point Link (both endpoints usable) |
| /32 | 255.255.255.255 | 1 | Host Route (one endpoint) |
5. Creating Subnets on Your Local Network
Building custom subnets on a local area network requires methodical planning and accurate configuration across your gateway router, managed switches, and endpoint operating systems. Follow this 4-step workflow to partition and verify your subnets.
Step 1: Plan Address Space & CIDR Blocks
Select a private RFC 1918 base network (e.g. 192.168.0.0/16) and divide it into subnets based on required host capacity and isolation goals.
Step 2: Configure Router/Switch Gateways
Configure 802.1Q sub-interfaces on your router (Router-on-a-Stick) or SVIs on a Layer 3 switch to act as default gateways.
! Step 2: Configure Router Sub-Interfaces (Router-on-a-Stick) interface GigabitEthernet0/0.10 description LAN_Subnet_Staff encapsulation dot1Q 10 ip address 192.168.10.1 255.255.255.0 no shutdown ! interface GigabitEthernet0/0.20 description LAN_Subnet_Guest encapsulation dot1Q 20 ip address 192.168.20.1 255.255.255.0 no shutdown
Step 3: Assign IP Addresses to Host Interfaces
Configure static IP address parameters, netmasks, and default gateways directly on host machines via OS CLI tools.
# Assign Static IP & Netmask on Windows via Netsh netsh interface ip set address name="Ethernet" static 192.168.10.50 255.255.255.0 192.168.10.1 # Configure Primary DNS Server netsh interface ip set dns name="Ethernet" static 1.1.1.1
Step 4: Verify & Test Inter-Subnet Routing
Confirm local gateway reachability, test cross-subnet packet forwarding, and inspect hop pathways using standard diagnostic utilities.
# 1. Verify Gateway Reachability ping 192.168.10.1 # 2. Test Inter-Subnet Routing to Guest Subnet ping 192.168.20.50 # 3. Trace Route Path across Gateway (Windows / Linux) tracert 192.168.20.50 # Windows traceroute 192.168.20.50 # Linux / macOS
6. VLSM — Variable Length Subnet Masking
Variable Length Subnet Masking (VLSM) allows network engineers to subdivide an address block into non-uniform subnets sized for different host requirements. Longer prefixes such as /27 and /30 create smaller subnets; allocating the smallest suitable block avoids wasting addresses.
Point-to-Point Router Links
Provides exactly 4 total IPv4 addresses (22), yielding 2 conventional host addresses. It is common for two-endpoint links, while RFC 3021 /31 can use both addresses on supported point-to-point interfaces.
Branch & Small Departments
Provides 32 total IP addresses (25), yielding 30 usable hosts. Perfect for small department teams, remote office locations, or server racks.
Standard Building / LAN
Provides 256 total IPv4 addresses (28), yielding 254 conventional host addresses. It is a common LAN example, not a universal allocation size.
Worked VLSM Example: Subnetting a 192.168.1.0/24 Block
Requirement: Allocate subnets for Engineering (50 hosts), Sales (25 hosts), Executive (10 hosts), and 2 Router Links.
| Department | Needed Hosts | Allocated CIDR | Subnet Mask | Network Address | Usable Host Range | Broadcast Address |
|---|---|---|---|---|---|---|
| Engineering | 50 hosts | /26 (64 IPs) | 255.255.255.192 | 192.168.1.0 | 192.168.1.1 — 192.168.1.62 | 192.168.1.63 |
| Sales | 25 hosts | /27 (32 IPs) | 255.255.255.224 | 192.168.1.64 | 192.168.1.65 — 192.168.1.94 | 192.168.1.95 |
| Executive | 10 hosts | /28 (16 IPs) | 255.255.255.240 | 192.168.1.96 | 192.168.1.97 — 192.168.1.110 | 192.168.1.111 |
| Router Link 1 | 2 hosts | /30 (4 IPs) | 255.255.255.252 | 192.168.1.112 | 192.168.1.113 — 192.168.1.114 | 192.168.1.115 |
| Router Link 2 | 2 hosts | /30 (4 IPs) | 255.255.255.252 | 192.168.1.116 | 192.168.1.117 — 192.168.1.118 | 192.168.1.119 |
| Unassigned Pool | Future expansion | 136 IPs free | /29 + /25 | 192.168.1.120/29 + 192.168.1.128/25 | 192.168.1.120–.127; .128–.255 (136 raw addresses) | Free range, no broadcast assignment |
192.168.1.0/24 (256 Total IPs) ├── 192.168.1.0/26 [Engineering: 50 hosts required, 62 usable (.1-.62)] ├── 192.168.1.64/27 [Sales: 25 hosts required, 30 usable (.65-.94)] ├── 192.168.1.96/28 [Executive: 10 hosts required, 14 usable (.97-.110)] ├── 192.168.1.112/30 [Router Link 1: 2 hosts required, 2 usable (.113-.114)] ├── 192.168.1.116/30 [Router Link 2: 2 hosts required, 2 usable (.117-.118)] └── 192.168.1.120/29 + 192.168.1.128/25 [Reserved Future Allocation Pool: 136 raw addresses (.120-.127 and .128-.255)]
/31 Subnet Prefixes on Point-to-Point Links
Under conventional IPv4 subnet rules, a /30 block uses 4 addresses to supply 2 host addresses. RFC 3021 defines a limited /31 interpretation for point-to-point links so both addresses can identify the two endpoints.
7. Supernetting & CIDR Aggregation
Supernetting (also called CIDR Route Aggregation or Route Summarization) is the process of combining multiple contiguous smaller networks into a single, shorter-prefix network route. This dramatically reduces core routing table sizes and conserves memory on enterprise network backbones.
❌ Before Aggregation (4 Individual Routes)
Bloated Routing TableRouters must store, query, and advertise four separate routing table entries for adjacent subnets:
✅ After Aggregation (1 Supernet Route)
75% Table ReductionAll 4 subnets are consolidated into a single summary prefix with a shorter network mask:
192.168.0.0 to 192.168.3.255 (Total 1,024 IP addresses in 1 route entry).Connect & Operate Networks
Apply the addressing model to VLANs, DHCP, IPv6, NAT, cloud subnets, and wireless access.
Stage signal
6 labs in scope
8. VLANs & Subnets — How They Connect
While both VLANs (Virtual LANs) and Subnets isolate network traffic, they operate at different layers of the OSI model. Understanding how Layer 2 physical switch isolation pairs with Layer 3 IP addressing is essential for modern enterprise network design.
VLAN (Virtual Local Area Network)
Partitioning at the physical switch level. Inserts a 4-byte 802.1Q tag into Ethernet frame headers to divide a single switch into multiple virtual broadcast domains.
IP Subnet (Subnetwork)
Logical IP address grouping defined by subnet masks (e.g., 255.255.255.0). Determines whether a packet stays local or must be routed through a gateway.
Industry Standard: 1:1 Mapping & Inter-VLAN Routing
Best practice commonly maps one IP subnet to one VLAN. Communication between VLANs requires a Layer 3 router or Layer 3 switch.
Access Ports (End Devices)
Switch ports configured as Access Ports belong to a single access VLAN (the port's PVID). They send and receive standard untagged Ethernet frames directly to workstations, printers, and IP phones. "Native VLAN" is trunk terminology and does not apply to an access port.
Trunk Ports (IEEE 802.1Q Inter-Switch Links)
Switch ports configured as Trunk Ports multiplex traffic from multiple VLANs over a single physical link by appending a 4-byte 802.1Q VLAN ID tag to each Ethernet frame header. The exception is the trunk's native (untagged) VLAN: frames in that VLAN are forwarded across the trunk without a tag, so both ends must agree on which VLAN it is.
9. DHCP & IP Address Management (IPAM)
Dynamic Host Configuration Protocol (DHCP) automates IPv4/IPv6 allocation across local networks. Explore the step-by-step DORA handshake, Layer 3 relay agent forwarding across subnets, core DHCP options, and enterprise IPAM pool sizing.
The 4-Step DORA Handshake
Interactive four-step DHCP discovery, offer, request, and acknowledgement flow.
DHCP DISCOVER Summary
When an unconfigured device connects to a network, it commonly sends a UDP broadcast from 0.0.0.0:68 to 255.255.255.255:67. A DHCP relay can forward the request to servers on another network.
Payload Parameters & Options
DHCP Relay Agent (ip helper-address)
A relay agent forwards client broadcasts across routed subnets.
GIADDR (Gateway IP Address) field to 192.168.10.1, and forwards a unicast packet across subnets directly to 10.0.0.100.! Cisco IOS DHCP Relay Agent Configuration ! 1. Enter Gateway Subnet Interface (VLAN 10) interface GigabitEthernet0/0.10 description LAN-VLAN10-GATEWAY ip address 192.168.10.1 255.255.255.0 ! 2. Configure Primary & Secondary DHCP Server Relays ! Helper-address converts L2/L3 Broadcasts into Unicast to target IP ip helper-address 10.0.0.100 ip helper-address 10.0.0.101 ! 3. (Optional) Fine-tune Relay Security & Option 82 Insertion ip dhcp relay information option ip dhcp relay information trust-all
Essential DHCP Options
Specifies the subnet mask of the client's subnet according to dotted decimal notation.
List of IP addresses for routers on the client's subnet. Routers should be listed in order of preference.
List of DNS recursive name servers available to the client.
Specifies the name of the client host, often populated automatically into Dynamic DNS (DDNS).
Specifies the domain name that client should use when resolving unqualified hostnames.
Identifies TFTP boot server used for PXE network operating system deployment.
Specifies the executable filename location on the TFTP server to initiate PXE boot.
Injects specific static routing table entries directly into client operating systems.
Enterprise IPAM & Pool Exhaustion Calculator
WARNING: High pool usage. High churn during peak hours may trigger address depletion.
10. IPv6 — The Next Generation
IPv6 replaces IPv4's 32-bit address space with a 128-bit address space (about 3.4 × 10 to the 38th power total addresses). Its architecture supports hierarchical routing, SLAAC, and a simplified base header; IPsec support is recommended for IPv6 nodes (RFC 8504), but IPv6 itself does not provide confidentiality or access control.
IPv6 Address Anatomy: 8 Hextets (128 Bits)
Written as 8 groups of 4 hexadecimal digits (called hextets), separated by colons. Each hextet represents 16 bits (8 × 16 = 128 bits).
Zero Compression Rules
RFC 5952 recommends a canonical text representation for IPv6 addresses. Other valid RFC 4291 representations remain valid input.
In any hextet, leading zeros can be dropped. For example, 0db8 becomes db8, and 0000 becomes 0.
A single contiguous sequence of all-zero hextets can be replaced with ::.Critical Constraint: :: can only be used ONCE per address to prevent ambiguity when parsing.
IPv4 vs IPv6 Feature Matrix
Architectural comparison between legacy IPv4 protocols and modern IPv6 standards.
| Feature | IPv4 Standard | IPv6 Standard |
|---|---|---|
| Address Size | 32 Bits (4 Bytes) | 128 Bits (16 Bytes) |
| Total Address Count | ~4.3 Billion (4.3 × 10 to the 9th power) | ~340 Undecillion (3.4 × 10 to the 38th power) |
| Format Notation | Dotted Decimal (e.g. 192.168.1.1) | Hexadecimal Colons (e.g. 2001:db8::1) |
| Prefix Length | Variable prefixes (/0 to /32) | /64 is common for SLAAC subnets; other prefixes exist |
| Address Auto-Configuration | Static configuration or DHCPv4 are common options | SLAAC can configure addresses; DHCPv6 can supply other parameters or addresses |
| NAT Use | Commonly used to conserve public IPv4 space, but not required by IPv4 | Usually unnecessary for address conservation; filtering is still required |
Why IPv6 LANs Commonly Use /64
Many IPv6 LANs use /64 subnets because SLAAC is designed around a 64-bit interface identifier. Point-to-point links, loopbacks, and infrastructure-specific designs may use other prefix lengths, so /64 is a convention rather than a universal rule.
11. Public vs Private IPs & NAT
IPv4 addresses may be publicly routable or drawn from private-use ranges. Because public IPv4 space is limited, Network Address Translation (NAT), especially port translation, lets many private hosts share one public address for outbound connections. NAT changes address/port reachability; it is not a replacement for firewall policy.
Internet-Facing Infrastructure
Public addresses are allocated through the Internet number registry system and advertised by networks that have routing connectivity. A public address can still be blocked by firewalls or service policy; public does not mean universally reachable.
Internal LAN & Cloud VPCs
RFC 1918 reserves these ranges for private internets. They are not meant to be advertised across inter-enterprise links; whether an upstream router filters them is a policy and implementation matter, not a guaranteed behavior of every ISP.
Interactive NAT / PAT (Port Address Translation) Flow
Step-by-step walkthrough showing how a NAT Gateway translates private sockets to public sockets.
Outbound Request Sent by Private Host
Client (192.168.1.50) sends a packet to Web Server (93.184.216.34:80) via ephemeral port 51234.
12. Subnets in the Cloud
Cloud hyperscalers (AWS, Azure, GCP) use Software-Defined Networking (SDN) to deliver virtual private clouds. While cloud subnets share traditional CIDR math, cloud vendors enforce vendor-specific IP reservations, availability zone scopes, and routing rules.
AWS VPC (Virtual Private Cloud)
Cloud SDN Subnet Architecture# AWS VPC & Subnet Terraform Example
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_subnet" "public_az1" {
vpc_id = aws_vpc.main.id
cidr_block = "10.0.1.0/24"
availability_zone = "us-east-1a"
}📋 Cloud Subnetting Architecture Checklist & Tips
Plan for growth and non-overlap
Choose an address range that leaves room for growth and does not overlap networks you must connect over VPN or Direct Connect. The required size depends on the design; /16 is not a universal default.
Treat public/private as a routing design
A common pattern places internet-facing resources in public subnets and application or database workloads in private subnets. Route tables, gateways, load balancers, and policy determine the actual exposure.
Check provider address reservations
Account for each provider's reservations when sizing IPv4 subnets. For example, AWS and Azure reserve five addresses in each subnet; in a /28, that leaves 11 addresses available for provider resources. Minimum prefix lengths and other limits vary by provider.
Design for the availability model
Use separate subnets in multiple zones when the workload and provider support zone redundancy; the number of zones is an availability decision, not a universal requirement.
Verify the platform's controls
Use the controls provided by the platform: security groups are commonly stateful, while network ACLs are commonly stateless and evaluated at a subnet boundary. Verify the provider's rule direction and default behavior before relying on a policy.
13. Wireless & WLAN Integration
Modern enterprise wireless LANs bridge 802.11 radio networks to wired Ethernet through access points and, in many designs, a wireless LAN controller. This section explores SSID-to-VLAN mapping, WLC topologies, 2.4GHz, 5GHz, and 6GHz bands, RF planning, and Wi-Fi 6/6E/7 behavior.
SSID-to-VLAN Mapping & WLC Topology
Live Frame Flow for SSID: Corp-Enterprise
CAPWAP Data Tunneling (UDP 5247)Centralized WLC (Split MAC Architecture)
CAPWAP TunnelThe AP handles time-sensitive 802.11 radio work. In a centralized forwarding design, user traffic commonly travels in CAPWAP data (UDP 5247) to the WLC, while authentication and policy placement depend on the controller design.
FlexConnect (Local Switching Architecture)
Branch & Remote APsIn local-switching designs, CAPWAP control traffic (UDP 5246) reaches the WLC while user payload is switched onto local VLANs. Continued branch service during a WAN outage depends on the AP, authentication, and site configuration.
Wi-Fi Frequency Bands & Technical Comparison
2.4 GHz Band (Legacy & IoT)
2.400 - 2.4835 GHz (regulatory-domain dependent channel use)- • Often better reach through typical indoor obstacles
- • Broad client compatibility
- • Fewer clean 20 MHz planning choices
- • Often congested in homes and dense deployments
| Specification / Metric | 2.4 GHz Band | 5 GHz Band | 6 GHz Band (Wi-Fi 6E/7) |
|---|---|---|---|
| Frequency Range | 2.400 - 2.4835 GHz (region-dependent use) | 5 GHz ranges vary by regulatory domain | 5.925 - 7.125 GHz where the region permits the full band |
| Available Spectrum | About 83.5 MHz of band space | Varies by region and permitted channels | Up to about 1,200 MHz in regions with the full allocation |
| 20 MHz Planning Choices | 1, 6, and 11 are a common North American plan | Count varies by region, DFS, and channel availability | Count varies by region and power class |
| Channel Width | 20 MHz common; 40 MHz may be supported | 20 / 40 / 80 / 160 MHz where permitted | Up to 320 MHz with supported Wi-Fi 7 devices and rules |
| Coverage | Often longer reach in the same environment | Often shorter reach than 2.4 GHz at the same conditions | Often shorter reach than 5 GHz at the same conditions |
| Interference Sources | Neighboring WLANs, microwaves, Bluetooth, and Zigbee | Neighboring WLANs and radar rules on DFS channels | No legacy 2.4/5 GHz clients; other 6 GHz users still contend |
| Theoretical PHY Rate | Depends on Wi-Fi generation, width, streams, and modulation | Depends on Wi-Fi generation, width, streams, and modulation | Wi-Fi 7 advertises multi-gigabit rates; actual throughput varies |
2.4 GHz Channel Planner & 5/6 GHz Bonding
2.4 GHz Channel Overlap Calculator (Channels 1 to 11)20 MHz Width / 5 MHz Spacing
The selected channels are separated by at least five channel numbers in this 20 MHz model. Validate the result against the actual regulatory channel plan and width.
5 GHz & 6 GHz Channel Bonding Hierarchy
Combines contiguous 20MHz channels to multiply throughput at the expense of spectrum density and SNR.
Interactive Wi-Fi Signal & Spectrum Overlap Visualizer
1. Transmitter & Environment
2. AP Channels & Noise
3. Derived Signal Quality
Real-Time RF Spectrum Mask & Signal Shape
Overlapping at 80 MHz (gap 4, needs 16)Understand, Forward & Diagnose Traffic
Read packet structure first, then learn forwarding, filtering, encrypted overlays, diagnostics, and container-networking tradeoffs.
Stage signal
7 labs in scope
14. Packet Encapsulation & Analysis
Every interaction on the internet depends on Packet Encapsulation—the process where raw application data is wrapped layer-by-layer with Transport headers, IP headers, and Ethernet frames before physical transmission over the wire. Understanding header bit fields, stateful TCP handshakes, and PCAP analysis tools like Wireshark is essential for network engineering and security analysis.
1. Interactive OSI vs TCP/IP Layer Stack Inspector
Select any layer to inspect protocol mapping, PDU names, headers attached, and addressing units.
Transport Layer
Provides end-to-end process-to-process data delivery, flow control, error recovery, and multiplexing.
2. Frame, Packet & Segment Header Anatomy
RFC Bit/Byte layout visualizer for Ethernet II Frames (Layer 2), IPv4 Packets (Layer 3), and TCP Segments (Layer 4).
Data Offset (4b) + Reserved (4b) + Flags (8b)
Data Offset defines header size in 32-bit words. The next 4 bits are reserved, followed by the 8 control flags defined in RFC 9293: CWR, ECE, URG, ACK, PSH, RST, SYN, FIN (the 9th 'NS' bit from RFC 3540 was reclassified as Historic by RFC 8311).
3. TCP 3-Way Handshake & Connection Teardown
Step-by-step TCP sequence number arithmetic, flag bitmask inspection, and TCP socket state transitions.
Step Explanation: Client picks an Initial Sequence Number (ISN=1000), sets SYN=1 flag, and sends connection request to Server port 443.
4. Interactive Wireshark PCAP Packet Viewer Simulator
Inspect real network trace packets, expand nested protocol headers, and analyze byte hex dumps.
| No. | Time (s) | Source | Destination | Protocol | Length | Info |
|---|---|---|---|---|---|---|
| 1 | 0.000000 | 192.168.1.50 | 93.184.216.34 | TCP | 74 | 54321 → 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1 |
| 2 | 0.024115 | 93.184.216.34 | 192.168.1.50 | TCP | 74 | 80 → 54321 [SYN, ACK] Seq=0 Ack=1 Win=29200 Len=0 MSS=1460 |
| 3 | 0.024210 | 192.168.1.50 | 93.184.216.34 | TCP | 66 | 54321 → 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0 |
| 4 | 0.025102 | 192.168.1.50 | 93.184.216.34 | HTTP | 162 | GET /index.html HTTP/1.1 |
| 5 | 0.026401 | 192.168.1.50 | 1.1.1.1 | DNS | 75 | Standard query 0x1a2b A api.example.com |
| 6 | 0.038920 | 192.168.1.50 | 8.8.8.8 | ICMP | 68 | Echo (ping) request id=0x1234, seq=1, ttl=64 |
15. Routing & Gateway Protocols
Routers build forwarding decisions by evaluating destination addresses against local routing tables. Explore dynamic IGP & EGP protocols, configured first-hop redundancy with HSRP/VRRP, policy-controlled BGP aggregation, and longest-prefix matching.
Static vs. Dynamic Routing Protocols
OSPF (Open Shortest Path First)
Medium to large enterprise networks requiring fast convergence and hierarchical area design (Backbone Area 0).
Key Technical Highlights
Cisco IOS Default Administrative Distance (Lower = Better)Believability Score (0 - 255)
Administrative distance is a Cisco IOS route-selection construct, not a protocol field: these are the platform defaults and every one of them is configurable. External EIGRP is 170 and an EIGRP summary route is 5.
Gateway Redundancy (HSRP & VRRP Virtual IP Failover)
Interactive Failover Controls
Protocol Event Console Log
BGP Route Summarization & Aggregation
Reducing Global Routing Table Bloat
The global routing table is large and changes over time. Autonomous systems can summarize contiguous, aligned prefixes before advertising to peers, reducing routing state when policy allows.
Bitwise Matching Breakdown (22 Common Bits)Green = Identical Network Bits
Interactive Routing Table Lookup Simulator (Longest Prefix Match)
Matched 6 route entries. Subnet mask /29 won because it has the highest number of contiguous matching network bits (Longest Prefix Match Rule).
Active Router Forwarding Information Base (FIB)
Total Entries: 8| Status | Protocol | Network CIDR | Next Hop IP | Interface | AD / Metric | Action |
|---|---|---|---|---|---|---|
| ★ SELECTED | EIGRP | 10.0.1.48/29 | 10.0.1.49 | Eth1.20 | 90 / 15 | |
| MATCHED (/27) | Static | 10.0.1.32/27 | 10.0.1.1 | Eth1.10 | 1 / 1 | |
| MATCHED (/24) | Connected | 10.0.1.0/24 | 10.0.1.1 | Eth1 | 0 / 0 | |
| MATCHED (/16) | OSPF | 10.0.0.0/16 | 10.255.1.1 | Eth0 | 110 / 10 | |
| MATCHED (/8) | OSPF | 10.0.0.0/8 | 10.255.0.1 | Eth0 | 110 / 20 | |
| NO MATCH | Connected | 192.168.1.0/24 | 192.168.1.1 | Eth2 | 0 / 0 | |
| NO MATCH | BGP | 172.16.0.0/12 | 172.16.0.1 | Eth3 | 20 / 100 | |
| MATCHED (/0) | Static | 0.0.0.0/0 | 203.0.113.1 | WAN0 | 1 / 1 |
Add Custom Route Entry to Table
16. Firewall Rules Between Subnets
Subnets define addressing and broadcast boundaries, but inter-subnet communication also depends on routing. A router or Layer 3 switch may forward traffic when a route exists; firewalls and ACLs then apply the platform's configured policy to permit, deny, or log packets.
Default-DENY (Block)
A default-deny policy drops traffic that does not match an explicit permit rule. The exact default depends on the device and rule direction, so verify it rather than assuming it.
Granular PERMIT (Allow)
Allows specific protocol, source CIDR, destination CIDR, and port combinations (e.g. Web Subnet to DB Subnet on TCP 5432).
Stateful Audit & LOG
Captures dropped connection attempts, port scans, and unauthorized inter-subnet packets to SIEM monitoring tools for incident analysis.
Cisco IOS Inter-Subnet Access Control List (ACL 100)
Extended ACLs filter based on source/destination IPs and TCP/UDP ports. Apply inbound on the router sub-interface closest to the source:
! Cisco Extended Access Control List (ACL 100) ! 1. Allow Web Subnet (VLAN 10) to access Database Subnet (VLAN 20) on PostgreSQL port 5432 access-list 100 remark --- Permit Web to DB Postgres --- access-list 100 permit tcp 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255 eq 5432 ! 2. Allow Web Subnet (VLAN 10) to access Shared HTTPS Services (VLAN 30) access-list 100 remark --- Permit Web to Shared HTTPS --- access-list 100 permit tcp 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255 eq 443 ! 3. Explicitly DENY remaining Web-to-DB traffic and log attempts access-list 100 remark --- Deny other Web to DB packets --- access-list 100 deny ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255 log ! NOTE: Every IOS ACL ends with an implicit 'deny ip any any'. With only the permits ! above, VLAN 10 loses all other egress (including Internet) once this ACL is applied. ! A real deployment adds the further permits it needs, or a trailing 'permit ip any any'. access-list 100 remark --- Implicit deny ip any any follows: add required permits --- ! 4. Apply ACL inbound on VLAN 10 Interface interface GigabitEthernet0/0.10 ip access-group 100 in
🛡️ Home & Small Network Firewall Rule Best Practices
Isolate Guest Wi-Fi Subnet
If the platform supports guest isolation, enable it and apply policy so guests (e.g. 192.168.2.0/24) cannot reach private NAS drives, PCs, or printers on 192.168.1.0/24.
Segregate Smart Home IoT Devices
Place smart TVs, cameras, smart plugs, and voice assistants on an isolated IoT subnet (e.g. 192.168.50.0/24). Explicitly block or restrict traffic from that subnet to the main LAN.
Review UPnP Across Trust Boundaries
Avoid allowing Universal Plug and Play (UPnP) port-mapping requests from less-trusted IoT or guest networks to create exposure into protected subnets; exact controls depend on the router.
Use Stateful Firewall Engines Carefully
When policy and defaults allow outbound sessions, stateful firewall engines can permit matching return traffic without static inbound ports. Verify the product's defaults and rule direction.
17. Network Security & Access Control
Defense in depth combines routing, filtering, identity, encryption, and monitoring. The NACL and security-group comparison below uses AWS-style semantics as a concrete example; other providers and appliances expose different boundaries and defaults.
1. Network ACLs vs. Security Groups
Concrete AWS-style comparison: subnet-level stateless filters versus instance or interface-level stateful rules.
| Architectural Feature | Network ACL (NACL) | Security Group (SG) |
|---|---|---|
| Operating Boundary | Subnet Boundary (VPC Router Level) | Instance / ENI Level (Hypervisor) |
| State Tracking | Stateless In this AWS-style NACL model, return traffic must match an outbound rule because the filter is stateless. | Stateful In this AWS-style security-group model, response traffic for an allowed flow is tracked automatically. |
| Rule Actions Supported | ALLOW and DENY rules (AWS network ACL) | ALLOW rules only in AWS security groups (implicit deny) |
| Evaluation Order | Sequential by rule number; lowest matching number wins | Rules are aggregated; there is no user-visible order |
| Ephemeral Return Ports | Must allow the matching return traffic in the outbound direction; a broad ephemeral range is only one possible policy. | AWS tracks response traffic for an allowed flow |
Return Traffic Flow Breakdown — NACL (Stateless)Step 1 of 3
External client sends HTTP request to web server on port 80 using client ephemeral port 52134.
VPN Tunnels
WireGuard — Modern Lightweight Crypto Tunnel
Designed as a small, simple encrypted tunnel; it can run in the Linux kernel and also has user-space implementations. Performance and overhead depend on platform and configuration.
VXLAN Encapsulation
Virtual Extensible LAN (VXLAN) encapsulates Layer 2 Ethernet frames inside UDP packets. It is used in data-center overlays and some Kubernetes CNI implementations to expand beyond the 4,096 VLAN-ID space up to 16.7 million VNI values.
Contains the 24-bit VXLAN Network Identifier (VNI) providing up to 16,777,216 isolated virtual Layer 2 subnets over a shared L3 fabric.
3. Network Address Translation (NAT) Variants
Understanding SNAT, DNAT, and PAT (NAPT) packet header transformations at boundary gateways.
PAT — Port Address Translation
Maps thousands of internal private host IP addresses onto a single shared public IP address by assigning unique public source ports for each session.
Both source IP and source port are translated to prevent socket collisions on public internet responses.
4. Interactive Security Rule Inspector
Test arbitrary packet parameters (Source IP, Destination Port, Protocol) against custom firewall ACLs.
Testing packet: TCP packet to port 80 from 203.0.113.50.
Matched enabled Rule #100 (Allow inbound HTTP from internet). Evaluation halted (First Match Wins).
Active NACL Rule ConfigurationClick rule checkbox to enable/disable
| Active | Rule # | Protocol | Port Range | Source CIDR | Action | Description |
|---|---|---|---|---|---|---|
| #100 | TCP | 80 | 0.0.0.0/0 | ALLOW | Allow inbound HTTP from internet | |
| #110 | TCP | 443 | 0.0.0.0/0 | ALLOW | Allow inbound HTTPS from internet | |
| #200 | TCP | 22 | 192.168.1.0/24 | ALLOW | Allow SSH only from Admin Subnet | |
| #210 | TCP | 22 | 0.0.0.0/0 | DENY | Deny SSH from everywhere else | |
| #300 | TCP | 3306 | 10.0.1.0/24 | ALLOW | Allow MySQL from Web Subnet | |
| * | ALL | ALL | 0.0.0.0/0 | DENY | Catch-all '*' rule: denies anything no numbered rule matched |
18. Network Diagnostics & CLI Sandbox
Master essential network troubleshooting CLI utilities (ping, traceroute, mtr, iperf3, dig, nmap). Test commands interactively in the simulated bash terminal sandbox, execute instant command presets, and reference the diagnostic cheat sheet.
Instant Execution Presets (Click to Run):
Structured Troubleshooting Workflow Matrix
Layer 3 ICMP Ping Test
Verify IP layer connectivity and physical/link layer reachability.
Hop Path & Delay Pinpoint
Identify exact router hop or provider link dropping packets.
DNS Resolution Audit
Confirm whether issue is IP routing or domain name resolution failure.
Firewall & Port Check
Detect blocked TCP/UDP ports, stateful firewall drops, or down services.
Bandwidth & Throughput
Measure maximum transmission rate, TCP window size, and UDP packet loss.
Diagnostic Tools Command Cheat Sheet
Comprehensive reference of syntax, flags, OSI layers, and practical use-cases.
Sends ICMP Echo Requests to test IP-layer reachability and measure replies, RTT, and loss when the destination and path permit ICMP.
ping [options] <destination_ip_or_hostname>Sends probes with increasing IP TTL values and reports routers that return errors. Missing replies, filtering, load balancing, and asymmetric paths can leave gaps or make the result incomplete.
traceroute [options] <destination_host>Combines the functionality of ping and traceroute into a single continuous real-time network diagnostic tool.
mtr [options] <target_host>Measures observed TCP or UDP throughput between two hosts; UDP mode can report jitter and datagram loss.
iperf3 -c <server_ip> [options] | iperf3 -sFlexible DNS lookup utility that queries Domain Name System servers directly and prints exact response records.
dig [@server] <domain> [type] [options]A port scanner and service-enumeration tool for authorized assessments; results depend on scan type, filtering, and target responses.
nmap [scan_type] [options] <target>19. Troubleshooting Subnet Issues
Subnetting issues can lead to subtle network failures, including host isolation, asymmetric routing, IP conflicts, and cross-subnet packet drops. Master these 6 diagnostic scenarios and follow the 6-step troubleshooting workflow.
6 Common Subnet Misconfigurations & Solutions
1. Misconfigured Subnet Mask (Off-by-One CIDR)
Mask MismatchHost A (192.168.1.50/24) cannot reach Host B (192.168.1.200/25). Host B incorrectly treats Host A as external and sends packets to Gateway.
Verify netmask uniformity across all hosts in the subnet block.
# Windows: Inspect IPv4 Subnet Mask ipconfig /all # Linux: Verify assigned IP & Prefix length ip -4 addr show dev eth0
🩺 6-Step Subnet Diagnostic Workflow
ipconfig /all | ip addrVerify Local IP Address & Subnet Mask
Ensure host has a valid IP address (not 0.0.0.0 or APIPA 169.254.x.x) and correct netmask matching network plan.
ping 127.0.0.1Test Local Loopback & Interface
Ping 127.0.0.1 and local host IP to verify local TCP/IP protocol stack and NIC driver functionality.
ping 192.168.10.1Ping Default Gateway IP
Test ICMP reachability to local subnet router interface (e.g. 192.168.10.1) to confirm Layer 2 switch connectivity.
tracert 192.168.20.50Trace Route Path to Target Destination
Execute traceroute to locate exact router hop where inter-subnet packet forwarding fails or times out.
nslookup domain.com | nc -zv IP PORTTest DNS & Targeted TCP/UDP Ports
Verify whether issue is pure IP layer routing or higher-layer DNS resolution / firewall port blocking.
show vlan brief | show access-listsAudit Switch VLANs & Firewall ACL Rules
Check switchport VLAN assignments, 802.1Q trunk tags, stateful firewall rules, and router ACL drop counters.
20. Cloud-Native & Container Networking
Modern cloud-native systems rely on virtualized network namespaces (netns), virtual ethernet pairs (veth), overlay tunnels, and kernel-level packet manipulation. Discover how Kubernetes CNI plugins, Docker isolation modes, and Layer 4/7 load balancers route microservice traffic at scale.
1. Kubernetes Networking Architecture & CIDR Ranges
Kubernetes defines a Pod networking model: each Pod is assigned an IP by the cluster network plugin, and the plugin is expected to provide Pod-to-Pod connectivity without NAT. Exact routing, encapsulation, and policy behavior depend on the CNI implementation.
Pods receive IP addresses from the cluster network plugin and expose them on the Pod's network interface. Addresses are usually ephemeral: recreating or rescheduling a Pod may change its IP, so Services provide stable discovery.
🔌 CNI (Container Network Interface) Plugins Comparison
Cilium CNI (eBPF)
Project Maintainer: Isovalent / CNCFCilium uses eBPF programs at selected kernel hooks for networking, policy, and observability. It can integrate with or replace kube-proxy in supported modes; Hubble and WireGuard encryption are optional features.
# Cilium L7 HTTP NetworkPolicy Example
apiVersion: "cilium.io/v2"
kind: CiliumNetworkPolicy
metadata:
name: secure-api-access
spec:
endpointSelector:
matchLabels:
app: payment-service
ingress:
- fromEndpoints:
- matchLabels:
app: checkout
toPorts:
- ports:
- port: "8080"
protocol: TCP
rules:
http:
- method: "POST"
path: "/v1/charge"2. Docker Networking Drivers & Modes
Docker uses container network drivers to manipulate Linux network namespaces, iptables NAT tables, and virtual interfaces. Select a mode below to analyze host binding, performance, and packet paths.
Bridge Mode (Default)
docker run --net=bridgeContainers connect to a virtual software bridge (docker0) via virtual ethernet (veth) pairs. Outbound traffic commonly uses IP masquerading. User-defined bridges provide automatic container-name DNS lookup.
✓ Architectural Advantages
- •Isolated container network namespace
- •Automatic container DNS on custom bridges
- •Useful default for standalone single-host containers
⚠ Technical Limitations
- •Port publishing may add NAT and filtering work
- •Multi-host communication needs an overlay or other routing design
3. Layer 4 (L4) vs Layer 7 (L7) Load Balancing & Ingress
Load balancers operate at different OSI layers to distribute traffic across container replicas. Compare transport-level packet routing (L4) with application-level HTTP routing (L7).
🌐 L7 Ingress Controller Mechanics
- ✓Inspection Depth: Terminates the TLS session and decrypts the record stream using the server private key, then parses HTTP methods, URI paths (
/v1/users), Host headers (api.domain.com), and cookies. - ✓Advanced Traffic Controls: Supports Canary deployment traffic splits (90/10 weighted routing), rate-limiting, CORS injection, and Web Application Firewall (WAF) rule sets.
- Endpoint selection: An Ingress controller may watch Service endpoints and proxy to Pod addresses; the exact path depends on the controller and Service configuration.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: production-ingress
annotations:
nginx.ingress.kubernetes.io/rewrite-target: /
nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
ingressClassName: nginx
rules:
- host: api.company.com
http:
paths:
- path: /v1/users
pathType: Prefix
backend:
service:
name: user-service
port:
number: 8080
- path: /v1/orders
pathType: Prefix
backend:
service:
name: order-service
port:
number: 90904. Interactive K8s Service IP Routing Simulator
Test how incoming client packets travel through Kubernetes abstractions (ClusterIP, NodePort, LoadBalancer, Headless, and Ingress) using either an iptables-based or an eBPF-based data path!
Practice & Review
Reinforce the track with guided practice, fast-reference formulas, and a final knowledge check.
Stage signal
3 labs in scope
21. Practice Problems
Master subnetting with real-world scenarios and certification-style drill questions. Test your calculations for network boundaries, host ranges, broadcast addresses, and VLSM allocations, then toggle answers to verify your steps.
Problem 1: Basic Subnetting
You are given the network address 172.16.5.0/24. Calculate the Network ID, Subnet Mask, First Usable Host IP, Last Usable Host IP, Broadcast Address, and Total Usable Hosts.
Problem 2: Subnet Division
Divide the network 10.1.1.0/24 into 4 equal subnets. Determine the new CIDR prefix length, Subnet Mask, Block Size, and list each created subnet with its Network ID, Usable Range, and Broadcast Address.
Problem 3: Find the Network
An engineer discovers a workstation configured with IP address 192.168.10.150/27. Determine the Network ID, Subnet Mask, First & Last Usable Host IPs, and Broadcast Address for the subnet block it belongs to. Is 192.168.10.150 a valid host address?
Problem 4: VLSM Challenge
Given the single base network block 192.168.1.0/24, design a Variable Length Subnet Masking (VLSM) allocation for three subnets: Finance (25 hosts needed), Marketing (12 hosts needed), and WAN Link (2 hosts needed). Allocate from the largest requirement to the smallest so each block stays aligned on its own boundary and the remaining space stays contiguous.
Problem 5: Real-World Scenario
A database server is configured with IP 10.0.5.100/28 and default gateway 10.0.5.113. The server cannot reach anything outside its own subnet. Determine the exact subnet boundary for 10.0.5.100/28 and decide whether 10.0.5.113 can act as this server's default gateway.
22. Subnetting Cheat Sheet
Quick-reference hub containing essential subnet formulas, comprehensive CIDR prefix lookup tables (/8 through /32), and mental math shortcuts for rapid network calculations in exams and production deployments.
📐Core Subnetting Formulas
Total IP Addresses
Calculates total raw IP addresses in block including network & broadcast.
Usable Host Count
Subtracts the conventional network and directed-broadcast addresses; /31 point-to-point and /32 host routes use special semantics.
Block Size (Magic Number)
Determines the exact step size between adjacent network boundaries.
Wildcard Mask (Inverse)
Used in Cisco Access Control Lists (ACLs) and OSPF network commands.
Network Address
Performs bitwise AND matching between IP address and subnet mask.
Broadcast Address
Last address in the subnet block where all host bits equal binary 1.
First Usable Host
First assignable IP address for network interfaces/endpoints.
Last Usable Host
Final assignable IP address before the broadcast boundary.
Subnets Created
Calculates total equal subnets created when extending network prefix.
📊Prefix Quick Reference Table (/8 to /32)
Complete CIDR lookup listing netmasks, host counts, magic numbers, and practical RFC use-cases.
⚡ /31 Prefix Note RFC 3021
RFC 3021 enables 2 usable IP addresses on point-to-point links with zero overhead (no reserved network or broadcast addresses), doubling IPv4 address efficiency on WAN links compared to traditional /30. RFC 3021 scopes this to point-to-point links only (it does not consider the effects on other interface types), and using a /31 requires platform support for 31-bit prefixes.
📌 /32 Prefix Note Single Host Route
A /32 prefix represents a single host route (mask 255.255.255.255). Used for router loopback interfaces (Router IDs in OSPF/BGP) and explicit single-IP host firewall rules.
| CIDR | Subnet Mask | Total IPs | Usable Hosts | Block Size (Increment) | Primary RFC / Production Use Case |
|---|---|---|---|---|---|
/8Historic Class A | 255.0.0.0 | 16,777,216 | 16,777,214 | 1 (Octet 1) / 256 (Octet 2) | Historic classful /8 boundary; modern networks use CIDR |
/9 | 255.128.0.0 | 8,388,608 | 8,388,606 | 128 (Octet 2) | Telco Backbones & Regional Supernets |
/10 | 255.192.0.0 | 4,194,304 | 4,194,302 | 64 (Octet 2) | Carrier-Grade NAT (CGNAT 100.64.0.0/10) |
/11 | 255.224.0.0 | 2,097,152 | 2,097,150 | 32 (Octet 2) | Large Enterprise Data Centers |
/12 | 255.240.0.0 | 1,048,576 | 1,048,574 | 16 (Octet 2) | Cloud VPC Private Allocations (RFC 1918 172.16.0.0/12) |
/13 | 255.248.0.0 | 524,288 | 524,286 | 8 (Octet 2) | Multi-Region Cloud Supernets |
/14 | 255.252.0.0 | 262,144 | 262,142 | 4 (Octet 2) | Large Service Provider Blocks |
/15 | 255.254.0.0 | 131,072 | 131,070 | 2 (Octet 2) | Regional Metro Networks |
/16Historic Class B | 255.255.0.0 | 65,536 | 65,534 | 1 (Octet 2) / 256 (Octet 3) | Historic classful /16 boundary; a /16 can still be chosen by design |
/17 | 255.255.128.0 | 32,768 | 32,766 | 128 (Octet 3) | University & Large Campus LANs |
/18 | 255.255.192.0 | 16,384 | 16,382 | 64 (Octet 3) | Enterprise Office Hubs |
/19 | 255.255.224.0 | 8,192 | 8,190 | 32 (Octet 3) | Regional Corporate Buildings |
/20 | 255.255.240.0 | 4,096 | 4,094 | 16 (Octet 3) | Example cloud or campus allocation; provider limits vary |
/21 | 255.255.248.0 | 2,048 | 2,046 | 8 (Octet 3) | Large Office Campus Subnets |
/22 | 255.255.252.0 | 1,024 | 1,022 | 4 (Octet 3) | Example Kubernetes node or Pod allocation; CNI and cluster sizing vary |
/23 | 255.255.254.0 | 512 | 510 | 2 (Octet 3) | Medium Branch Office Networks |
/24Historic Class C | 255.255.255.0 | 256 | 254 | 1 (Octet 3) / 256 (Octet 4) | Historic classful /24 boundary; common LAN example today |
/25 | 255.255.255.128 | 128 | 126 | 128 (Octet 4) | Half /24 Subnet / Office Department |
/26 | 255.255.255.192 | 64 | 62 | 64 (Octet 4) | Standard Corporate Department Subnet |
/27Popular | 255.255.255.224 | 32 | 30 | 32 (Octet 4) | Small Team Subnet / Wireless Segment |
/28 | 255.255.255.240 | 16 | 14 | 16 (Octet 4) | Server Rack / Database Cluster |
/29 | 255.255.255.248 | 8 | 6 | 8 (Octet 4) | Small infrastructure segment or virtual-router example |
/30Legacy P2P | 255.255.255.252 | 4 | 2 | 4 (Octet 4) | Traditional Point-to-Point Router Link (2 Usable / 2 Reserved) |
/31RFC 3021 | 255.255.255.254 | 2 | 2 | 2 (Octet 4) | Point-to-Point Link (RFC 3021 - 0 Network/Broadcast Overhead) |
/32Host Route | 255.255.255.255 | 1 | 1 | 1 (Octet 4) | Host route, loopback interface, or single-address policy object |
🧠Mental Math Tricks Grid (4 Cards)
1. The Magic 256 Rule
Instant Subnet Increment Step
Subtract the non-255 subnet mask octet from 256 to calculate the exact block size (subnet increment) in seconds.
2. Finger-Counting Bit Borrowing
Double Subnets, Halve Host Capacity
Every bit borrowed doubles the created subnets (2^n) and halves host capacity per subnet. Count on fingers from 1 to 6 bits.
3. Octet Jump Shortcuts
Locate the 'Interesting Octet' Instantly
Quickly map CIDR prefixes to their active working octet without converting binary digits:
4. Quick Wildcard Mask Inversion
Subtract Subnet Mask from 255.255.255.255
Derive Cisco ACL wildcard masks instantly by subtracting each mask octet from 255.
23. Test Your Knowledge
Click an answer to check it. Your score is tracked at the bottom.
Q1 — How many usable hosts does a /26 subnet have?
Q2 — What is the broadcast address of 192.168.1.64/26?
Q3 — Which subnet mask matches /27?
Q4 — In VLSM, why is it conventional to allocate subnets from largest to smallest?
Q5 — What does NAT stand for?
Q6 — How many subnets do you get by borrowing 3 bits from a /24?
Q7 — Which address is outside the conventional host range of 192.168.1.0/30?
Q8 — What is the primary purpose of a VLAN?
Keep practicing! Review the sections above and try again.