1Session at a glance
Objectives
- Convert an octet between decimal and binary in both directions.
- Given an address and a mask, give the network address, the broadcast address and the usable range.
- Say whether two addresses are on the same network, and show the reasoning.
- Split a network into a given number of pieces and write out the boundaries.
- Read a site addressing scheme and say what each column means.
Before the session
- A real client site open in the UniFi console, on Settings then Networks, so the subnets and ranges are already on screen.
- Everyone at a machine with a command prompt, and the Learner Guide open.
- Paper and pen at every seat. The splitting block is worked by hand, not typed.
- The place-value row written large on the whiteboard: 128 64 32 16 8 4 2 1.
| Time | Block | What happens |
|---|---|---|
| 0:00 | Open | The same two machines, one mask apart, and one of them cannot reach the other. |
| 0:04 | Concept | Binary (5), the mask (5), slash notation and the host count (4), the private ranges (3), splitting a network (7). |
| 0:28 | Show | Live in the UniFi console: a real site's networks, their subnets, gateways and address ranges. Then ipconfig /all on a machine and tie the two together. |
| 0:37 | Do | Everyone works their own address by hand, then splits a /24 into eight on paper. |
| 0:49 | Check | Six questions. |
| 0:56 | Close | The work before session 03, and what that session covers. |
Splitting a network is the block people fail, and it gets seven minutes because it is the one that has to be worked slowly on the board. If the room is behind, cut the private ranges block to naming the three ranges and move on. Never cut the binary block to save time: everything after it assumes it, and a room that cannot convert an octet cannot follow the mask.
Menu names in the UniFi console move between versions. Confirm the path in the version the site is actually running before the session rather than in front of the room.
2Open (0:00, 4 minutes)
Two machines. One is 192.168.10.15 and the other is 192.168.10.200. Look at those two addresses and tell me whether they are on the same network. You cannot. Neither can the machines, from the addresses alone. Change one setting on both, a setting most people skim past when they read a ticket, and the answer flips from yes to no. Everything about how those two machines behave changes with it, and nothing about the addresses changed at all. That setting is the subnet mask, and today is what it does.
- Write both addresses on the board and leave them there. You come back to them in the concept block and again at the end.
- Say where this lands on the job: the most common addressing fault is not a wrong address, it is a right address with a wrong mask, and it reports as an intermittent fault because most things still work.
3Concept (0:04, 24 minutes)
Binary, the part they need (5 min)
- Write the place values large: 128 64 32 16 8 4 2 1. Everything in this block comes off that row.
- Convert 192 out loud, subtracting as you go: 128 fits, 64 left, 64 fits exactly, done.
11000000. - Convert 15 the same way, and let the room see that the four small positions carry it:
00001111. - Go backwards once:
11001000is 128 plus 64 plus 8, which is 200. - Then the two consequences, because both get used within ten minutes. All eight positions set is 255, which is why an octet stops there. And the only numbers that can appear in a mask are the running totals from the left: 128, 192, 224, 240, 248, 252, 254, 255.
Somebody always says they know binary already. Do it anyway, out loud, both directions. The block takes five minutes and it is the only reason the mask makes sense rather than being memorized.
The subnet mask (5 min)
- State it plainly before any arithmetic: the mask is not an address, it is a marker. A 1 marks a bit that names the network. A 0 marks a bit that names the device.
- Work the table in section 3 of the Learner Guide on the board: 192.168.10.15 against 255.255.255.0, both in binary, lined up.
- Land the reading: the first three octets name the network, the last one names the machine.
- Then the two reserved addresses, and derive each rather than asserting it. All host bits 0 is 192.168.10.0, the network address. All host bits 1 is
11111111, which is 255, so 192.168.10.255, the broadcast address. - Which leaves .1 to .254, so 254 usable.
Slash notation and the host count (4 min)
- 255.255.255.0 is eight plus eight plus eight 1 bits, so /24. Write 192.168.10.15/24.
- Derive the host count a second way so it is not a memorized number: 32 bits total, 24 spent on the network, 8 left, 2 to the power of 8 is 256, minus the network address and the broadcast address is 254. Same answer as the counting a minute ago.
- Only now state the rule: usable hosts is 2 to the power of (32 minus the prefix), minus 2.
- Walk the mask table in section 4 of the Learner Guide once, and give them the reading that makes it memorable: every bit taken from the hosts halves the number of devices that fit.
The private ranges (3 min)
- The three ranges, and why they exist: not routed on the internet, so every office can use them at once.
- Point at the one people get wrong. 172.16.0.0/12 runs to 172.31.255.255, not to 172.16.255.255.
- Then 169.254, restated as a thing to recognize and never configure: it means the machine asked for an address and nothing answered.
Splitting a network (7 min)
This is the block that needs the board. Work it slowly and let them write it down.
- Start from the requirement, not the answer: take 192.168.10.0/24 and make four networks out of it.
- Four needs two bits, because two bits give four combinations. Say the four out loud: 00, 01, 10, 11.
- 24 plus 2 borrowed is 26, so each piece is a /26. Six host bits left, 2 to the power of 6 is 64 addresses per piece, 62 usable.
- Write the four boundaries on the board, stepping 64 each time: 0, 64, 128, 192. Fill in the first usable, last usable and broadcast for each, and let the room call out the numbers.
- Then the cost, out loud: four times 62 is 248 against the 254 they started with. Six addresses went on the three extra network addresses and three extra broadcast addresses. That is why nobody splits further than they need to.
- Finish with the shortcut, after the long way, not before: 256 minus the last octet of the mask gives both the step and the width. 256 minus 192 is 64.
Back to the two machines (in the same 7 minutes)
- Return to 192.168.10.15 and 192.168.10.200 on the board. With /24 both are in 192.168.10.0, so the first machine delivers straight to the second and the router never sees it.
- With /26, the first falls in 192.168.10.0/26 which stops at .63, and the second falls in 192.168.10.192/26 which starts at .193. Different networks, so it goes to the gateway, and whether it arrives depends on the router and the rules between them.
- Say the line the open set up: the addresses never changed, only the mask did.
4Show (0:28, 9 minutes)
- Open the site in the UniFi console, Settings then Networks. Read the list out loud. Each entry has a name, a subnet and a gateway address, and every one of those is now readable from the concept block.
- Open one network. Point at the subnet and its prefix, the gateway address, and the automatic address range. Say the host count for that prefix out loud before anyone works it out, then ask the room to confirm it.
- Point at the range boundaries. The automatic range and any fixed addresses do not overlap. Say what happens when they do: two devices handed the same address, which reports as both of them working unreliably.
- Switch to a machine and run
ipconfig /all. Put the address, the mask and the gateway next to what is on screen in the console. They are the same numbers from two directions, and that is the point of the demo. - One more, if there is time. Pick a second network at the same site and ask the room whether a machine in the first could reach a machine in the second directly. The answer is no, and the reason is the mask, and what happens next is the router and the rules, which is the session after this one.
5Do (0:37, 12 minutes)
Paper first, then screens. Circulate, and look at what people write rather than asking whether they have it.
- Their own machine.
ipconfig /all, write down address, mask and gateway. Convert the mask to slash notation. Work out the network address, the broadcast address and the usable count by hand. - The gateway check. Write their own address and their gateway in binary and confirm the network bits match. Say why it matters: if they did not match, the machine could not reach its own gateway.
- The split. Take 10.20.30.0/24 and make eight networks. Eight needs three bits, so /27, 32 addresses each, 30 usable, boundaries every 32. Let them work it before you confirm anything.
- Check the first boundary with the shortcut. Mask 255.255.255.224, and 256 minus 224 is 32. It agrees with the long way, which is how they will know they can trust it.
Two mistakes come up every time. People write the last usable address as the broadcast address, so they lose an address per network. And people step the boundaries by the usable count rather than the block size, so they step by 30 instead of 32 and every network after the first is wrong. Watch for both on the paper rather than waiting for the answers.
6Check (0:49, 7 minutes)
A machine is
192.168.5.70with mask255.255.255.0. What is its network address, its broadcast address, and how many usable addresses does that network hold?AnswerNetwork address 192.168.5.0, broadcast address 192.168.5.255, 254 usable addresses. The mask marks the first three octets as the network, so the last octet is the only part that varies.
Write
/27as a full subnet mask, and say how many usable addresses each/27holds.Answer255.255.255.224. Twenty-seven network bits leaves five host bits, 2 to the power of 5 is 32 addresses, minus the network and broadcast addresses is 30 usable.Two machines are
10.10.4.30and10.10.4.80. With mask255.255.255.0on both, can they reach each other directly? With mask255.255.255.192on both, can they? Show the reasoning for each.AnswerWith
/24, both are in 10.10.4.0, so yes, directly, and the router is not involved. With/26the blocks are 64 wide: .30 falls in 10.10.4.0/26, which runs .0 to .63, and .80 falls in 10.10.4.64/26, which runs .64 to .127. Different networks, so both machines hand the traffic to their gateway and whether it arrives is the router's decision.A laptop is handed
192.168.10.15with mask255.255.0.0while every other machine on the network has mask255.255.255.0. The gateway is192.168.10.1. Describe what the laptop can and cannot reach, and why the fault will be reported as intermittent.AnswerThe laptop believes every address starting 192.168 is a neighbor it can reach directly. Its own network still works, because those machines really are neighbors. The internet still works, because those addresses do not start 192.168, so it correctly hands them to the gateway, which it can reach. What breaks is every other 192.168 network at the site, the voice network, the guest network, the cameras, and anything at another site in that range: for those the laptop tries to deliver directly instead of handing them to the gateway, and gets no answer.
The obvious answer is that a wrong mask breaks the machine. It does not. It breaks one specific class of destination while leaving the two the user tests first, their own network and the internet, working perfectly. That is the whole reason it gets reported as intermittent, and why the mask is worth reading on every addressing ticket.
Split
172.20.8.0/24into four. Give the four network addresses and the broadcast address of the third one.AnswerFour pieces needs two borrowed bits, so
/26, 64 addresses each. The four networks are 172.20.8.0/26, 172.20.8.64/26, 172.20.8.128/26 and 172.20.8.192/26. The third runs .128 to .191, so its broadcast address is 172.20.8.191.A site uses
192.168.1.0/24and needs a permanent connection to another site that also uses192.168.1.0/24. What is the problem, and what has to happen before the connection can work?AnswerEvery address exists at both ends, so a machine asking for 192.168.1.50 has named two different devices and neither end can tell which. One site has to be renumbered onto a different range before the connection is built.
The obvious answer is that the connection can be built and the routing sorted out afterwards. It cannot: no routing decision can resolve an address that is ambiguous, which is why the range at a site is chosen deliberately rather than left at whatever the router shipped with.
7Close (0:56, 4 minutes)
Work before the next session
- The practice steps in section 9 of the Learner Guide, with the eight-network split written out and brought along.
- The mask table in section 4 learned to the point where a prefix gives a host count without working it out.
- The Network+ companion, chapter 2, the IPv4 addressing section.
Next session
03 - Switching and VLANs. How a switch decides where to send a frame, what a VLAN, a virtual local area network, changes, and how access ports and trunk ports carry them. It uses this session's networks directly, because a VLAN and a subnet travel together.
Open items to settle
- Which client site is used for the console demo, and whether the room sees it read-only.
- Whether the addressing scheme table in section 8 gets built for real for the sites that do not have one, and where it lives in the client documentation.
8Sources
- Internet Engineering Task Force, RFC 791, Internet Protocol, for the 32-bit address and the network and host split.
- Internet Engineering Task Force, RFC 4632, Classless Inter-domain Routing (CIDR), for slash notation and variable-length masks.
- Internet Engineering Task Force, RFC 1918, Address Allocation for Private Internets, for the three private ranges.
- Internet Engineering Task Force, RFC 3927, Dynamic Configuration of IPv4 Link-Local Addresses, for the 169.254 range.
- Ubiquiti, Creating Virtual Networks (VLANs), for where a network's subnet, gateway and address range are set in the console.
- Kodi A. Cochran, CompTIA Network+ (N10-009) Certification Companion (Apress, 2026), chapter 2, IPv4 addressing.
9After the session
| Delivered on | |
| Attendance | |
| What landed | |
| What did not | |
| Changes for next time | |
| Backlog items created |