CIDR Notation Explained
Learn how to use CIDR (Classless Inter-Domain Routing) notation to authorize ranges of IP addresses in KnoxCall.What is CIDR?
CIDR (pronounced “cider”) is a way to represent a range of IP addresses using a single notation.Format
192.168.1.0- Network address (base IP)/24- Prefix length (how many IPs in range)
Why Use CIDR?
The Problem Without CIDR
Imagine authorizing an office with 200 employees:The Solution With CIDR
How CIDR Works
The Prefix Number
The number after the/ tells you how many IPs are in the range.
Formula:
Common CIDR Ranges
| CIDR | IPs | Common Use | Example |
|---|---|---|---|
/32 | 1 | Single host | 52.123.45.67/32 |
/30 | 4 | Point-to-point | 10.0.0.0/30 |
/28 | 16 | Small subnet | 192.168.1.0/28 |
/24 | 256 | Office network | 192.168.1.0/24 |
/20 | 4,096 | Large network | 172.31.0.0/20 |
/16 | 65,536 | Corporate VPN | 10.0.0.0/16 |
/8 | 16M+ | Very large | 10.0.0.0/8 |
/24 - Most Common (256 IPs)
Example: Office Network
- Last octet (number): 0 to 255
- Everything else stays the same
/16 - Large Networks (65,536 IPs)
Example: Corporate VPN
- Last TWO octets: 0.0 to 255.255
- First two stay the same: 10.8
/20 - Cloud Subnets (4,096 IPs)
Example: AWS VPC Subnet
- Last octet: Full range (0-255)
- Third octet: Partial range (0-15)
/32 - Single IP (Don’t Use CIDR)
Example: Single Server
52.123.45.67 without /32. It’s implied.
Calculating CIDR Ranges
Quick Method
Step 1: Look at the prefixCIDR Calculator Tools
Online calculators: Example:Common Scenarios
Scenario 1: Office Wi-Fi
Need: Authorize all 50 office computers Solution:- Office has 50 devices now
- Room to grow to 254 devices
- Typical office network size
Scenario 2: Corporate VPN
Need: Authorize 500 remote employees Solution:- VPN has 500 users now
- Room for 65,000+ connections
- Standard VPN range
Scenario 3: AWS Subnet
Need: Authorize EC2 instances in subnet Solution:- AWS VPC subnet
- ~4,000 IPs
- Multiple microservices
Scenario 4: Partner Network
Need: Authorize partner company’s entire network Solution:- Partner has small office
- ~100 employees
- /24 covers them
Testing CIDR Ranges
How to Test
Step 1: Create client with CIDRPrivate IP Ranges
Reserved Private Networks
These IP ranges are for internal networks only (not internet-routable): Class A (Large):- Office networks (devices behind router)
- VPNs (tunnel private network over internet)
- Cloud private subnets
- Public internet servers (use public IPs)
Public vs Private IPs
Public IPs (Internet)
- Production servers
- Partner webhooks
- Public APIs
Private IPs (Internal Networks)
- Office networks
- VPN access
- Internal testing
Common Mistakes
❌ Mistake 1: Using /32 for Networks
❌ Mistake 2: Too Broad Range
❌ Mistake 3: Wrong Base IP
❌ Mistake 4: Prefix Doesn’t Match Network
CIDR Cheat Sheet
| Prefix | IPs | Typical Use |
|---|---|---|
/32 | 1 | Single server (don’t use CIDR) |
/30 | 4 | Point-to-point link |
/29 | 8 | Very small subnet |
/28 | 16 | Small office |
/27 | 32 | Small network |
/26 | 64 | Medium office |
/25 | 128 | Large office |
/24 | 256 | Standard office network |
/23 | 512 | Large office/campus |
/22 | 1,024 | Campus network |
/21 | 2,048 | Large network |
/20 | 4,096 | Cloud subnet (AWS) |
/19 | 8,192 | Large cloud network |
/18 | 16,384 | Very large network |
/17 | 32,768 | Enterprise |
/16 | 65,536 | Corporate VPN, large enterprise |
/15 | 131,072 | ISP |
/14 | 262,144 | Large ISP |
/13 | 524,288 | Very large ISP |
/12 | 1M+ | Regional network |
/11 | 2M+ | National network |
/10 | 4M+ | Continental network |
/9 | 8M+ | Very large network |
/8 | 16M+ | Class A network |
Tools & Resources
CIDR Calculators
IP Address Guide: https://www.ipaddressguide.com/cidr CIDR.xyz: https://cidr.xyz/ Subnet Calculator: https://www.subnet-calculator.com/Command Line Tools
Test if IP is in CIDR range:Best Practices
✅ Do
-
Use smallest range needed
-
Use .0 as base
-
Document what’s in range
-
Test before production
-
Use private IPs for internal
❌ Don’t
-
Don’t use 0.0.0.0/0
-
Don’t over-authorize
-
Don’t forget private vs public
-
Don’t mix ranges
Quick Reference
| Your Network | Recommended CIDR | IPs |
|---|---|---|
| Single server | 52.123.45.67 (no /32) | 1 |
| Small office (< 20) | 192.168.1.0/28 | 16 |
| Medium office (< 100) | 192.168.1.0/24 | 256 |
| Large office (< 500) | 192.168.0.0/23 | 512 |
| VPN (< 1000) | 10.8.0.0/22 | 1,024 |
| Large VPN (< 10k) | 10.0.0.0/18 | 16,384 |
| Enterprise VPN | 10.0.0.0/16 | 65,536 |
| AWS Subnet | 172.31.0.0/20 | 4,096 |
Next Steps
What are Clients?
Client basics and IP whitelisting
Client Types
Server, User, and Network types
Managing Clients
Create and assign clients
IP Issues
Troubleshoot IP problems
Quick Tip: For most offices,
/24 (256 IPs) is perfect. For VPNs, /16 (65,536 IPs) gives plenty of headroom. When in doubt, use a CIDR calculator!