Ravindra BagaleCourses & study guides Track your progress

Guides

AWS VPC CIDR and Subnet Calculation Explained: How Many IPs and Subnets?

A CIDR block such as 10.0.0.0/16 means the first 16 of the 32 bits are fixed, so the block has 2^(32−16) = 65,536 addresses. A /24 subnet has 256 addresses, but AWS reserves 5 in every subnet, so you can use 251. The formula is: usable IPs = 2^(32 − prefix) − 5, and the number of /24 subnets that fit in a /16 is 2^(24 − 16) = 256.

Come on, friends! When they hear CIDR, many students panic – "/16, /24, what is this maths?" Don't panic. Think of the society's land as plots: /16 is a big plot, /24 is one wing inside it. The bigger the number after the slash, the smaller the plot. Remember one formula and the rest is easy.

Quick answer

Addresses in a block  = 2^(32 - prefix)
Usable in AWS subnet  = 2^(32 - prefix) - 5
Subnets of size /s in a VPC of /v = 2^(s - v)

/16 = 65,536   /20 = 4,096 (4,091 usable)   /24 = 256 (251 usable)
/26 = 64 (59 usable)   /27 = 32 (27 usable)   /28 = 16 (11 usable)

Check any block on a Linux server with Python (no install needed on Amazon Linux 2023):

python3 -c "import ipaddress as i; n=i.ip_network('10.0.1.0/24'); print(n.num_addresses, n[0], n[-1])"
python3 -c "import ipaddress as i; print([str(s) for s in i.ip_network('10.0.0.0/16').subnets(new_prefix=18)])"

What do I need to know before calculating?

  • An IPv4 address has 32 bits, written as four numbers from 0 to 255 (10.0.1.25).
  • The number after the slash is the prefix length: how many bits at the start are fixed for the network. The rest are free for hosts.
  • AWS allows VPC and subnet CIDR blocks from /16 to /28, and recommends the private (RFC 1918) ranges: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16.

How does a /16 split into subnets?

Splitting a /16 VPC into /24 subnets The VPC 10.0.0.0/16 has 65,536 addresses. It is split into /24 subnets of 256 addresses each: 10.0.1.0/24, 10.0.2.0/24 and 10.0.3.0/24, up to 256 such subnets. In every subnet AWS reserves 5 addresses: .0 network, .1 VPC router, .2 DNS, .3 future use and .255 broadcast, so 251 are usable. VPC 10.0.0.0/16 16 fixed bits · 2^16 = 65,536 addresses 10.0.1.0/24256 addresses 10.0.2.0/24256 addresses 10.0.3.0/24256 addresses … up to 256 /24 blocks(default quota 200 subnets) Inside 10.0.1.0/24, AWS keeps 5 addresses: 10.0.1.0network 10.0.1.1VPC router 10.0.1.2DNS 10.0.1.3future use 10.0.1.255broadcast Usable: 10.0.1.4 – 10.0.1.254 = 256 − 5 = 251 IPs

A /16 VPC has 65,536 addresses. Split into /24 subnets, each gets 256 addresses, but AWS reserves 5 in every subnet (network, VPC router, DNS, future use, broadcast), so 251 are usable.

How do I calculate IPs and subnets step by step?

Step 1 — Count the free bits

Free bits = 32 − prefix. For /24: 32 − 24 = 8 free bits.

Step 2 — Turn free bits into addresses

Addresses = 2^free bits. For /24: 2^8 = 256. For /20: 2^12 = 4,096. For /16: 2^16 = 65,536.

Step 3 — Subtract the 5 AWS reserved addresses

In every subnet AWS keeps 5 addresses. For 10.0.1.0/24:

Address Reserved for
10.0.1.0 Network address
10.0.1.1 VPC router
10.0.1.2 Amazon DNS server (base of the VPC range + 2)
10.0.1.3 Reserved for future use
10.0.1.255 Network broadcast address (AWS does not support broadcast, so it is reserved)

Usable: 10.0.1.4 to 10.0.1.254 = 251. This is why the smallest subnet, /28, gives only 16 − 5 = 11 usable IPs.

Step 4 — Count how many subnets fit

Subnets = 2^(subnet prefix − VPC prefix). A /16 VPC holds 2^(24−16) = 256 subnets of /24, or 2^(20−16) = 16 subnets of /20. The default quota is 200 subnets per VPC, so in practice you create far fewer.

Step 5 — Write the plan

Subnet CIDR Range Usable
web-public-1a 10.0.1.0/24 10.0.1.0 – 10.0.1.255 251
app-private-1a 10.0.2.0/24 10.0.2.0 – 10.0.2.255 251
db-private-1a 10.0.3.0/24 10.0.3.0 – 10.0.3.255 251
web-public-1b 10.0.11.0/24 10.0.11.0 – 10.0.11.255 251

Leave gaps (for example .11, .12, .13 for the second AZ) so you can grow later without overlaps. 🧮

Ravindra Bagale's Tip

In interviews they always ask: "How many IPs can you use in a /24 subnet?" The answer is not 254; in AWS it is 251 – because AWS keeps 5 IPs. And one mistake: don't take a very small VPC (/24). Take /16 and make the subnets /24, so there is room even if a new tier comes tomorrow.

What are the common CIDR mistakes?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
The CIDR '10.​0.​1.​0/​24' conflicts with another subnet Overlapping subnets Pick a block that does not overlap, e.g. 10.0.4.0/24
The CIDR '10.​0.​0.​0/​8' is invalid when creating a VPC Bigger than /16 Use /16 or smaller (/17 … /28)
The CIDR '10.​0.​1.​0/​29' is invalid for a subnet Smaller than /28 Use /28 or bigger
Subnet CIDR rejected as invalid The subnet is not inside the VPC range Stay inside the VPC block, e.g. 10.0.x.0/24 inside 10.0.0.0/16
VPC peering later fails Both VPCs use the same range (10.0.0.0/16) Plan different ranges per VPC from the start (10.0.0.0/16, 10.1.0.0/16)
"Only 11 instances fit" A /28 subnet Use /24 for normal tiers

Try it at home

Without a calculator: how many usable IPs does a /26 have in AWS, and what are the four /18 subnets of 10.0.0.0/16? Then check your answers with the two python3 commands above.

Got it? 2 to the power (32 − prefix), minus 5 – that is the whole formula. /16 VPC, /24 subnets, 251 usable IPs. You will get it, slowly slowly you will get it – do one or two examples yourself.

Frequently asked questions

How many IP addresses are in a /16?

A /16 has 2^16 = 65,536 addresses. It is the largest CIDR block AWS allows for a VPC.

How many usable IPs does a /24 subnet have in AWS?

251. A /24 has 256 addresses, and AWS reserves 5 in every subnet: the network address, the VPC router, the DNS server, one for future use and the broadcast address.

Which CIDR sizes does AWS allow?

For a VPC and for a subnet, from /16 (65,536 addresses) to /28 (16 addresses). AWS recommends the private ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.

How many subnets can a VPC have?

The default quota is 200 subnets per VPC (adjustable). Mathematically a /16 VPC holds 256 subnets of /24.

Can subnets overlap?

No. Subnets in the same VPC cannot overlap, and every subnet must be inside the VPC CIDR. Plan different ranges for different VPCs too if you may connect them later.

How do I calculate CIDR ranges without a website?

Use Python, available on Amazon Linux 2023: python3 -c "import ipaddress as i; print(i.ip_network('10.0.1.0/24').num_addresses)" prints 256.