Subnets & CIDR
The methodology partitioning IP spaces into smaller, isolated networks using subnet mask notation.
Last reviewed: July 25, 2026
Subnets and CIDR (Classless Inter-Domain Routing) notation together form the system used to divide a large block of IP address space into smaller, manageable segments — the foundational addressing scheme underlying how virtual networks are structured in every major cloud provider.
CIDR Notation
CIDR notation expresses an IP address range as a base address followed by a slash and a number, like 10.0.0.0/16, where the number indicates how many bits of the address are fixed (the “network” portion) versus how many bits are available to be assigned to individual hosts or further subdivided (the “host” portion). A /16 fixes the first 16 bits, leaving 16 bits free — enough for 65,536 individual addresses — while a /24 fixes 24 bits, leaving only 8 bits free for 256 addresses. Smaller numbers after the slash mean a larger address range; larger numbers mean a smaller, more specific range.
Why Subnetting Matters
A cloud VPC is typically allocated one large CIDR block (like 10.0.0.0/16), which is then subdivided into smaller subnets (like 10.0.1.0/24 and 10.0.2.0/24) for specific purposes — commonly separating public-facing resources (a subnet with a route to an internet gateway) from private resources (a subnet with no direct internet route, reachable only internally or through a NAT gateway). This segmentation is both an organizational tool and a security boundary: security groups and network ACLs can be applied differently to different subnets, and routing rules can be scoped per-subnet.
Practical Planning
Choosing CIDR ranges when first setting up a VPC deserves real upfront thought, since resizing a VPC’s address space or subnet boundaries later, after resources have already been provisioned within them, is disruptive — most teams plan for meaningfully more address space than their current needs to leave room for growth, and deliberately choose non-overlapping ranges across VPCs that might eventually need to be peered or connected via Transit Gateway, since overlapping CIDR blocks make that connectivity impossible without a redesign.
Reserved Addresses Within Every Subnet
It’s worth knowing that cloud providers reserve a handful of addresses within every subnet for internal networking purposes — typically the network address, the broadcast address, and a few addresses reserved for the VPC router and DNS — meaning the actual number of usable host addresses in a subnet is slightly fewer than the raw CIDR math would suggest. A /24 subnet nominally offering 256 addresses, for example, might only have around 251 actually assignable to resources once these reservations are accounted for, a detail worth remembering when sizing subnets for a specific expected number of resources.
Historical figures and technical concepts for informational purposes only. Not technical, professional, legal, or financial advice. Sources: Official Documentation.