Hermetic Networks Hermetic Networks

CompTIA Network+ (N10-009) - Session 02 - Learner Guide

IP Addressing and Subnetting

What the two halves of an IP address mean, how to read a subnet mask, and how to say in one step whether two machines can reach each other directly.

1What an IP address is made of

This is your copy to keep. The gold Going deeper boxes go past what the session covers, for anyone sitting the CompTIA Network+ exam or who wants the fuller picture.

An IP address (internet protocol address) is the address a network hands a device, written as four numbers from 0 to 255 separated by dots, for example 192.168.10.15. Each of those four numbers is called an octet. An octet is eight bits, and four octets together make the 32-bit address.

An address on its own is only half the information. 192.168.10.15 does not say which other machines are its neighbors, and that is the question a device has to answer before it can send anything. The other half is the subnet mask, and every device carries both. The mask marks where the address stops naming the network and starts naming the device on it.

That split is what this session is about, because almost every addressing fault is the same fault: two machines that look like neighbors are not, or a device is handed a mask that does not match the network it is plugged into.

The example network

The addresses on this page, in the 192.168.10.0 range, are an example written for training. They are not a client network.

2Binary, the part you need

The mask only makes sense in binary, so here is the minimum. A computer stores each octet as eight bits, and a bit is a single 1 or 0. Each position in those eight has a fixed value, and the octet is the sum of the positions holding a 1.

The eight place values in one octet
Position12345678
Worth1286432168421

Take 192. Starting from the left: 128 fits, leaving 64. Then 64 fits exactly, leaving 0. Nothing else is needed. So positions 1 and 2 hold a 1 and the rest hold 0, which is 11000000.

Take 15. 128 does not fit, 64 does not fit, 32 does not fit, 16 does not fit. 8 fits, leaving 7. 4 fits, leaving 3. 2 fits, leaving 1. 1 fits, leaving 0. So the last four positions hold a 1, which is 00001111.

Going the other way is addition. 11001000 holds a 1 at the 128, 64 and 8 positions, and 128 plus 64 plus 8 is 200.

Two consequences follow from that table, and the mask section below uses both. The largest an octet can be is all eight positions set, 128 plus 64 plus 32 plus 16 plus 8 plus 4 plus 2 plus 1, which is 255. And the values that appear in a subnet mask are always the running totals from the left: 128, 192, 224, 240, 248, 252, 254, 255. No other number can appear in a mask, because a mask is always a run of 1s followed by a run of 0s with nothing mixed in.

3The subnet mask

The mask is written like an address, four octets, but it is not an address. It is a marker. Every position holding a 1 marks a bit of the address that names the network. Every position holding a 0 marks a bit that names the host, meaning the individual device on that network.

Work one all the way through. A workstation has address 192.168.10.15 and mask 255.255.255.0.

192.168.10.15 with mask 255.255.255.0
Octet 1Octet 2Octet 3Octet 4
Address1921681015
In binary11000000101010000000101000001111
Mask2552552550
Mask in binary11111111111111111111111100000000
What it marksnetworknetworknetworkhost

So the first three octets, 192.168.10, name the network, and the last octet, 15, names this particular machine on it. Every other device on that network shares 192.168.10 and differs only in the last octet.

Two addresses in every network are reserved and cannot be given to a device.

  • The network address, which is the address with all host bits set to 0. Here that is 192.168.10.0. It names the network itself, which is what a router's table holds.
  • The broadcast address, which is the address with all host bits set to 1. Here that is 192.168.10.255, because 11111111 is 255. Anything sent there goes to every device on the network at once.

That leaves 192.168.10.1 through 192.168.10.254 for actual devices, which is 254 addresses.

4Slash notation, and counting the hosts

Writing the mask out in full is slow, so it is usually written as a slash and the number of 1 bits in it. The mask 255.255.255.0 is 8 plus 8 plus 8 plus 0, so 24 bits of network, written /24. The full address is then written 192.168.10.15/24. That style is called CIDR notation (classless inter-domain routing), and it is what you will see in documentation and in every network console.

The host count follows from the same arithmetic that was just done by hand. An address is 32 bits in total. A /24 spends 24 of them on the network, leaving 8 for hosts. Eight bits gives 2 to the power of 8, which is 256 combinations, and two of those are the network address and the broadcast address, leaving 254. That is the 254 counted above, arrived at a second way.

Stated as the rule: usable hosts = 2(32 minus the prefix) minus 2.

The masks you will actually meet
PrefixMaskHost bitsUsable hostsWhere it shows up
/24255.255.255.08254The default for most office networks and most VLANs
/25255.255.255.1287126A /24 split in half
/26255.255.255.192662A /24 split in four
/27255.255.255.224530A small segment, such as a handful of servers
/28255.255.255.240414A block of public addresses from an internet provider
/30255.255.255.25222A point-to-point link between two routers, one address each

Read the table the other way and the pattern is easier to hold: every bit taken away from the hosts halves the number of devices that fit.

5The private ranges

Three ranges of addresses are set aside for use inside private networks. They are not routed on the internet, which is why every office in the world can use them at the same time without colliding. Everything you will configure inside a client site comes out of one of these.

The private address ranges
RangeFirst to last addressWhere you see it
10.0.0.0/810.0.0.0 to 10.255.255.255Larger sites and anywhere somebody wanted room to grow
172.16.0.0/12172.16.0.0 to 172.31.255.255Less common, and the one people misread. It stops at 172.31, not 172.16
192.168.0.0/16192.168.0.0 to 192.168.255.255Most small offices, and the default on nearly every consumer router

One more range is worth recognizing and never configuring. An address starting 169.254 is one a Windows machine gave itself because it asked for an address and nothing answered. Seeing it means the addressing service did not reach the machine, which is a fault to find rather than an address to work with.

Going deeper

Because 192.168.0.0/16 and 192.168.1.0/24 are the defaults on consumer equipment, two sites that both use 192.168.1.0/24 cannot be joined by a site-to-site connection without renumbering one of them. The addresses would be ambiguous at both ends. That is the practical reason a client site gets a deliberately chosen range rather than whatever the router shipped with.

6Splitting a network

Separating traffic means separating networks, and that means taking one range and cutting it into smaller ones. Take 192.168.10.0/24 and cut it into four.

Four pieces needs two extra bits borrowed from the host side, because two bits give four combinations: 00, 01, 10, 11. Twenty-four network bits plus two borrowed is 26, so each piece is a /26. Six host bits are left, and 2 to the power of 6 is 64 addresses per piece, of which 62 are usable.

Each piece starts 64 higher than the last, because each piece is 64 addresses wide.

192.168.10.0/24 split into four /26 networks
Network addressFirst usableLast usableBroadcast addressUsable
192.168.10.0/26192.168.10.1192.168.10.62192.168.10.6362
192.168.10.64/26192.168.10.65192.168.10.126192.168.10.12762
192.168.10.128/26192.168.10.129192.168.10.190192.168.10.19162
192.168.10.192/26192.168.10.193192.168.10.254192.168.10.25562

Four networks times 62 usable is 248 devices, against 254 in the single /24 they came from. Six addresses were spent on the three extra network addresses and three extra broadcast addresses the split created. Splitting always costs addresses, and that cost is the reason nobody splits a network further than they need to.

Going deeper

The width of a piece is always the same as the step between pieces, and both are 256 minus the last octet of the mask. A /26 has mask 255.255.255.192, and 256 minus 192 is 64, so the pieces sit at 0, 64, 128 and 192. A /28 has mask 255.255.255.240, and 256 minus 240 is 16, so the pieces sit at 0, 16, 32, 48 and so on. That one subtraction gets you the boundaries without writing any binary.

7The question a device answers before it sends anything

Every time a device sends a packet it decides one thing first: is the destination on my own network, or not. On its own network it delivers directly. Anywhere else, it hands the packet to its default gateway, the router address it was given for exactly this purpose, and the router takes it from there.

It decides by applying its own mask to both addresses and comparing what is left. Work both cases on the same pair of machines.

Case one, mask 255.255.255.0

The workstation is 192.168.10.15/24 and it wants to reach 192.168.10.200. With a /24, the first three octets are the network. The workstation's network is 192.168.10. The destination's first three octets are also 192.168.10. Same network, so the workstation delivers directly. It resolves the destination's hardware address on the local network and sends the frame straight to it, and the router is never involved.

Case two, same addresses, mask 255.255.255.192

Now both machines have a /26 mask. From the split above, 192.168.10.15 falls in 192.168.10.0/26, which runs to .63. And 192.168.10.200 falls in 192.168.10.192/26, which starts at .193. Different networks. The workstation now hands the packet to its default gateway, and whether it arrives depends on the router and on whatever rules sit between the two networks.

The addresses did not change. Only the mask did, and it changed the behavior completely. This is why a mask typed wrong during a manual configuration produces a machine that reaches some things and not others, which reads as an intermittent fault and is not one.

8Reading a client's addressing scheme

A documented site lists its networks in a table like this one. Everything in it is now readable from what is above. The VLAN column holds a VLAN (virtual local area network) number, which is how one physical switch is divided into separate networks by configuration. One VLAN carries one subnet, and session 03 is how that works.

An example site addressing scheme
NetworkVLANSubnetGatewayAutomatic rangeReserved for fixed addresses
Staff10192.168.10.0/24192.168.10.1.100 to .199.2 to .99
Voice20192.168.20.0/24192.168.20.1.100 to .199.2 to .99
Guest30192.168.30.0/24192.168.30.1.50 to .250none
Cameras40192.168.40.0/24192.168.40.1none.10 to .99

Four things are worth reading off it deliberately.

  • Every network is a /24, so each one holds 254 devices and the third octet is the only thing that differs. A scheme built this way is readable at a glance, which is most of the reason people build them this way.
  • The gateway is .1 on every network. That is a convention rather than a rule, and the convention is worth following because it means anybody can guess it correctly at any site.
  • The automatic range and the fixed range do not overlap. If they did, the addressing service could hand out an address a printer is already using, and two devices with the same address is a fault that looks like neither of them works reliably.
  • The cameras network hands out nothing automatically. Every camera has an address set deliberately, which is normal for equipment that should always be findable at the same address.

When you are handed a site with no such table, building one is the first useful thing you can do for it, and it belongs in the client's documentation rather than in your notes.

9Practice on your own machine

  1. Run ipconfig /all on Windows, or ip addr and ip route on Mac or Linux. Write down your IPv4 address, your subnet mask and your default gateway.
  2. Convert your mask to slash notation, then work out the network address, the broadcast address and the number of usable hosts on your own network. Check the host count against the mask table in section 4.
  3. Write your own address and your gateway's address in binary, and confirm that the bits the mask marks as network are identical in both. If they are not, your machine cannot reach its own gateway, which is a fault.
  4. Pick one address from your automatic range and one from outside your network entirely. For each, say whether your machine would deliver it directly or hand it to the gateway, and why.
  5. Take 10.20.30.0/24 and split it into eight networks. Write out the network address, the first and last usable address, and the broadcast address for each. Check your first boundary with the 256 minus the mask octet shortcut.

10Check for understanding

  1. A machine is 192.168.5.70 with mask 255.255.255.0. What is its network address, its broadcast address, and how many usable addresses does that network hold?

  2. Write /27 as a full subnet mask, and say how many usable addresses each /27 holds.

  3. Two machines are 10.10.4.30 and 10.10.4.80. With mask 255.255.255.0 on both, can they reach each other directly? With mask 255.255.255.192 on both, can they? Show the reasoning for each.

  4. A laptop is handed 192.168.10.15 with mask 255.255.0.0 while every other machine on the network has mask 255.255.255.0. The gateway is 192.168.10.1. Describe what the laptop can and cannot reach, and why the fault will be reported as intermittent.

  5. Split 172.20.8.0/24 into four. Give the four network addresses and the broadcast address of the third one.

  6. A site uses 192.168.1.0/24 and needs a permanent connection to another site that also uses 192.168.1.0/24. What is the problem, and what has to happen before the connection can work?

11Before the next session

  • Do the practice steps in section 9 on your own machine, and bring the eight-network split written out.
  • Learn the mask table in section 4 to the point where you can go from a prefix to a host count without working it out.
  • Read the Network+ companion, chapter 2, the IPv4 addressing section.

Next session. 03 - Switching and VLANs. How a switch decides where to send a frame, and what a VLAN actually changes.

12Glossary

IP address
The address a network hands a device, written in IPv4 as four numbers from 0 to 255. 32 bits in total.
Octet
One of the four numbers in an IPv4 address. Eight bits, so 0 to 255.
Bit
A single 1 or 0. Eight of them make one octet.
Subnet mask
The marker saying which bits of an address name the network and which name the device. Always a run of 1s followed by a run of 0s.
Network address
The address with every host bit set to 0. It names the network itself and is never given to a device.
Broadcast address
The address with every host bit set to 1. Anything sent to it reaches every device on that network, and it is never given to a device.
Host
An individual device on a network.
CIDR notation
Classless inter-domain routing. Writing the mask as a slash and the number of network bits, such as /24.
Prefix
The number after the slash. The count of network bits.
Default gateway
The router address a device sends traffic to when the destination is not on its own network.
Private address range
One of 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16, set aside for use inside private networks and not routed on the internet.
Subnetting
Cutting one network into smaller ones by borrowing bits from the host side.
IPv4
The 32-bit addressing scheme described on this page, and the one in use at every site we run.
IPv6
The 128-bit addressing scheme built to replace IPv4, written in hexadecimal with colons. Not covered in this session.

13Sources