AWS VPC CIDR and Subnet Calculation Explained: How Many IPs and Subnets?
A CIDR block such as 10.0.0.0/16 means the first 16 of the 32 bits are fixed, so the block has 2^(32−16) = 65,536 addresses. A /24 subnet has 256 addresses, but AWS reserves 5 in every subnet, so you can use 251. The formula is: usable IPs = 2^(32 − prefix) − 5, and the number of /24 subnets that fit in a /16 is 2^(24 − 16) = 256.
Come on, friends! When they hear CIDR, many students panic – "/16, /24, what is this maths?" Don't panic. Think of the society's land as plots: /16 is a big plot, /24 is one wing inside it. The bigger the number after the slash, the smaller the plot. Remember one formula and the rest is easy.
चला मित्रांनो! CIDR ऐकलं की खूप students घाबरतात – "/16, /24, हे काय गणित आहे?" घाबरू नका. Society च्या जमिनीचे plot समजा: /16 म्हणजे मोठा plot, /24 म्हणजे त्यातली एक wing. Slash नंतरचा number जितका मोठा, तितका plot लहान. एक formula लक्षात ठेवा, बाकी सगळं सोपं.
चलो दोस्तों! CIDR सुनते ही बहुत students घबरा जाते हैं – "/16, /24, यह कौन सा गणित है?" घबराओ मत. Society की ज़मीन के plot समझो: /16 यानी बड़ा plot, /24 यानी उसमें की एक wing. Slash के बाद का number जितना बड़ा, plot उतना छोटा. एक formula याद रखो, बाकी सब आसान.
Quick answer
Addresses in a block = 2^(32 - prefix)
Usable in AWS subnet = 2^(32 - prefix) - 5
Subnets of size /s in a VPC of /v = 2^(s - v)
/16 = 65,536 /20 = 4,096 (4,091 usable) /24 = 256 (251 usable)
/26 = 64 (59 usable) /27 = 32 (27 usable) /28 = 16 (11 usable)
Check any block on a Linux server with Python (no install needed on Amazon Linux 2023):
python3 -c "import ipaddress as i; n=i.ip_network('10.0.1.0/24'); print(n.num_addresses, n[0], n[-1])"
python3 -c "import ipaddress as i; print([str(s) for s in i.ip_network('10.0.0.0/16').subnets(new_prefix=18)])"
What do I need to know before calculating?
- An IPv4 address has 32 bits, written as four numbers from 0 to 255 (
10.0.1.25). - The number after the slash is the prefix length: how many bits at the start are fixed for the network. The rest are free for hosts.
- AWS allows VPC and subnet CIDR blocks from /16 to /28, and recommends the private (RFC 1918) ranges:
10.0.0.0/8,172.16.0.0/12,192.168.0.0/16.
How does a /16 split into subnets?
A /16 VPC has 65,536 addresses. Split into /24 subnets, each gets 256 addresses, but AWS reserves 5 in every subnet (network, VPC router, DNS, future use, broadcast), so 251 are usable.
/16 VPC मध्ये 65,536 addresses असतात. /24 subnets मध्ये वाटले तर प्रत्येकाला 256 addresses मिळतात, पण AWS प्रत्येक subnet मध्ये 5 राखून ठेवतो (network, VPC router, DNS, future use, broadcast), म्हणून 251 वापरता येतात.
/16 VPC में 65,536 addresses होते हैं. /24 subnets में बाँटने पर हर एक को 256 addresses मिलते हैं, पर AWS हर subnet में 5 रख लेता है (network, VPC router, DNS, future use, broadcast), इसलिए 251 इस्तेमाल हो सकते हैं.
How do I calculate IPs and subnets step by step?
Step 1 — Count the free bits
Free bits = 32 − prefix. For /24: 32 − 24 = 8 free bits.
Step 2 — Turn free bits into addresses
Addresses = 2^free bits. For /24: 2^8 = 256. For /20: 2^12 = 4,096. For /16: 2^16 = 65,536.
Step 3 — Subtract the 5 AWS reserved addresses
In every subnet AWS keeps 5 addresses. For 10.0.1.0/24:
| Address | Reserved for |
|---|---|
10.0.1.0 |
Network address |
10.0.1.1 |
VPC router |
10.0.1.2 |
Amazon DNS server (base of the VPC range + 2) |
10.0.1.3 |
Reserved for future use |
10.0.1.255 |
Network broadcast address (AWS does not support broadcast, so it is reserved) |
Usable: 10.0.1.4 to 10.0.1.254 = 251. This is why the smallest subnet, /28, gives only 16 − 5 = 11 usable IPs.
Step 4 — Count how many subnets fit
Subnets = 2^(subnet prefix − VPC prefix). A /16 VPC holds 2^(24−16) = 256 subnets of /24, or 2^(20−16) = 16 subnets of /20. The default quota is 200 subnets per VPC, so in practice you create far fewer.
Step 5 — Write the plan
| Subnet | CIDR | Range | Usable |
|---|---|---|---|
| web-public-1a | 10.0.1.0/24 |
10.0.1.0 – 10.0.1.255 | 251 |
| app-private-1a | 10.0.2.0/24 |
10.0.2.0 – 10.0.2.255 | 251 |
| db-private-1a | 10.0.3.0/24 |
10.0.3.0 – 10.0.3.255 | 251 |
| web-public-1b | 10.0.11.0/24 |
10.0.11.0 – 10.0.11.255 | 251 |
Leave gaps (for example .11, .12, .13 for the second AZ) so you can grow later without overlaps. 🧮
Ravindra Bagale's Tip
In interviews they always ask: "How many IPs can you use in a /24 subnet?" The answer is not 254; in AWS it is 251 – because AWS keeps 5 IPs. And one mistake: don't take a very small VPC (/24). Take /16 and make the subnets /24, so there is room even if a new tier comes tomorrow.
Ravindra Bagale's Tip – मराठी
Interview मध्ये नेहमी विचारतात: "/24 subnet मध्ये किती IP वापरता येतात?" उत्तर 254 नाही, AWS मध्ये 251 – कारण 5 IP AWS ठेवतो. आणि एक चूक: VPC खूप लहान (/24) घेऊ नका. /16 घ्या आणि subnets /24 करा, उद्या नवीन tier आला तरी जागा असेल.
Ravindra Bagale's Tip – हिंदी
Interview में हमेशा पूछते हैं: "/24 subnet में कितने IP इस्तेमाल कर सकते हैं?" जवाब 254 नहीं, AWS में 251 – क्योंकि 5 IP AWS रख लेता है. और एक गलती: VPC बहुत छोटा (/24) मत लो. /16 लो और subnets /24 बनाओ, कल नया tier आए तब भी जगह होगी.
What are the common CIDR mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
The CIDR '10.0.1.0/24' conflicts with another subnet |
Overlapping subnets | Pick a block that does not overlap, e.g. 10.0.4.0/24 |
The CIDR '10.0.0.0/8' is invalid when creating a VPC |
Bigger than /16 | Use /16 or smaller (/17 … /28) |
The CIDR '10.0.1.0/29' is invalid for a subnet |
Smaller than /28 | Use /28 or bigger |
| Subnet CIDR rejected as invalid | The subnet is not inside the VPC range | Stay inside the VPC block, e.g. 10.0.x.0/24 inside 10.0.0.0/16 |
| VPC peering later fails | Both VPCs use the same range (10.0.0.0/16) |
Plan different ranges per VPC from the start (10.0.0.0/16, 10.1.0.0/16) |
| "Only 11 instances fit" | A /28 subnet |
Use /24 for normal tiers |
Try it at home
Without a calculator: how many usable IPs does a /26 have in AWS, and what are the four /18 subnets of 10.0.0.0/16? Then check your answers with the two python3 commands above.
Learn it properly
Got it? 2 to the power (32 − prefix), minus 5 – that is the whole formula. /16 VPC, /24 subnets, 251 usable IPs. You will get it, slowly slowly you will get it – do one or two examples yourself.
समजलं का? 2 चा घात (32 − prefix), minus 5 – बस एवढाच formula. /16 VPC, /24 subnets, 251 usable IPs. कळेल तुम्हाला, हळू हळू कळेल – एक-दोन examples स्वतः करा.
समझ आया? 2 की घात (32 − prefix), minus 5 – बस इतना ही formula. /16 VPC, /24 subnets, 251 usable IPs. समझ आएगा, धीरे धीरे समझ आएगा – एक-दो examples खुद करो.
Frequently asked questions
How many IP addresses are in a /16?
A /16 has 2^16 = 65,536 addresses. It is the largest CIDR block AWS allows for a VPC.
How many usable IPs does a /24 subnet have in AWS?
251. A /24 has 256 addresses, and AWS reserves 5 in every subnet: the network address, the VPC router, the DNS server, one for future use and the broadcast address.
Which CIDR sizes does AWS allow?
For a VPC and for a subnet, from /16 (65,536 addresses) to /28 (16 addresses). AWS recommends the private ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.
How many subnets can a VPC have?
The default quota is 200 subnets per VPC (adjustable). Mathematically a /16 VPC holds 256 subnets of /24.
Can subnets overlap?
No. Subnets in the same VPC cannot overlap, and every subnet must be inside the VPC CIDR. Plan different ranges for different VPCs too if you may connect them later.
How do I calculate CIDR ranges without a website?
Use Python, available on Amazon Linux 2023: python3 -c "import ipaddress as i; print(i.ip_network('10.0.1.0/24').num_addresses)" prints 256.