Subnet Mask Cheat Sheet Generator for Home Labs

August 17, 2026

Subnet Mask Cheat Sheet Generator

Calculate CIDR notation, dotted masks, usable hosts, wildcard masks, network ranges, and VLAN split math for home lab planning.

⚙Cheat Sheet Presets
🖧Subnet Inputs
CIDR mode creates the cheat sheet directly; host mode recommends the smallest safe prefix.
Any address inside the subnet is accepted, such as 192.168.10.42.
Smaller numbers create larger networks; /24 is the common home LAN default.
Used by host mode and shown in the capacity breakdown.
Used to show how many same-size child subnets fit inside a larger block.
Split mode can recommend the child prefix needed for this many networks.
Updates the equipment grid and compares the subnet to typical home-server use.
Adds spare addresses when recommending a prefix from desired hosts.
Changes which line is highlighted in the copy-friendly cheat sheet.
Normal mode is best for LANs; RFC 3021 is useful on routed point-to-point links.
Subnet Mask
255.255.255.0
/24 CIDR
Usable Hosts
254
addresses after reserves
Network Range
192.168.10.0
broadcast 192.168.10.255
Wildcard Mask
0.0.0.255
256 total addresses
💻Equipment and Spec Comparison
254
Typical /24 hosts
Enough space for a flat home LAN, DHCP reservations, printers, and wireless clients.
802.1Q
VLAN tagging
Managed switches and routers use tags to carry multiple subnets over trunks.
DHCP
Scope planning
A practical pool often leaves static addresses at the bottom or top of the range.
ACL
Wildcard masks
Firewall and router rules may use inverse masks such as 0.0.0.255.
📊Common CIDR Cheat Sheet
CIDR Subnet Mask Usable Hosts Total Addresses Home Lab Fit
/16255.255.0.065,53465,536Large private aggregate or routed lab supernet
/20255.255.240.04,0944,096Large virtualization, lab tenants, or campus-style home lab
/22255.255.252.01,0221,024Container host pools, routed VLAN groups, or big wireless labs
/23255.255.254.0510512Expanded LAN or dense Proxmox and Kubernetes testing
/24255.255.255.0254256Standard LAN, management VLAN, or simple DHCP scope
/25255.255.255.128126128Camera VLAN, wired office, or medium IoT segment
/26255.255.255.1926264IoT, guest Wi-Fi, smart-home devices, or small lab VLAN
/27255.255.255.2243032Guest network, WireGuard peer pool, or printer subnet
/28255.255.255.2401416Server management, hypervisor cluster, or small DMZ
/29255.255.255.24868Firewall transit, exposed services, or appliance segment
/30255.255.255.25224Traditional routed point-to-point link
/31255.255.255.25422RFC 3021 point-to-point link when supported
/32255.255.255.25511Single host route, loopback, or firewall object
🔒Private IPv4 Ranges
Range CIDR Block Address Count Common Use
10.0.0.0 to 10.255.255.25510.0.0.0/816,777,216Large routed labs, VPN overlays, lab tenants, and multi-site home networks
172.16.0.0 to 172.31.255.255172.16.0.0/121,048,576Containers, Docker defaults, lab isolation, and nested virtualization
192.168.0.0 to 192.168.255.255192.168.0.0/1665,536Home routers, small offices, wireless networks, and simple VLAN plans
169.254.0.0 to 169.254.255.255169.254.0.0/1665,536Link-local fallback, not a routed subnet plan for normal home-lab design
🔧Wildcard and Block Reference
CIDR Wildcard Mask Last-Octet Block Rule of Thumb
/240.0.0.255256One whole final octet; easy DHCP and VLAN boundary
/250.0.0.127128Two equal halves inside a /24 parent network
/260.0.0.6364Four VLANs from one /24 while keeping 62 usable hosts each
/270.0.0.3132Eight compact networks for small device groups
/280.0.0.1516Sixteen tiny lab, DMZ, or management segments
/290.0.0.78Six usable addresses after network and broadcast reserves
/300.0.0.34Two usable endpoints for router-to-router links
/320.0.0.01Exact host match for firewall objects and host routes
🗂Common Project Sizes
Project Typical Devices Suggested CIDR Notes
Home office LAN20 to 80 clients/24Simple, roomy, easy to remember, and accepted by almost every router UI
Guest Wi-Fi10 to 25 clients/27Small enough to constrain unknown clients while keeping DHCP simple
IoT network30 to 60 devices/26Good fit for smart plugs, voice assistants, sensors, and appliances
Camera VLAN25 to 100 devices/25Leaves room for NVR, management addresses, and future cameras
Server management4 to 14 ports/28Enough for hypervisors, IPMI, NAS, switches, and a firewall interface
Transit network2 endpoints/30 or /31Use /31 only when both routers and firewall policies support it
💡Planning Tips
VLAN sizing: Keep each subnet tied to a purpose: main LAN, guest Wi-Fi, IoT, cameras, lab, management, or transit. That makes DHCP scopes, firewall rules, and documentation much easier to audit later.
Growth buffer: A subnet that is technically large enough can still feel cramped once phones, virtual machines, containers, IPMI ports, and temporary test devices are added. Use a buffer before choosing the prefix.

Your initial network consist of one router that provides DHCP out of the box plus a switch and some PCs. It all just works.

Then you add a few things: a NAS, a server, and some smart bulbs that talk back to an external server. Now you have a hodgepodge of device talking to each other in ways they weren’t designed to do. This is when subnetting comes into play on a home lab; it helps sort through the traffic. It takes those binary ideas and makes them workable IP block.

Why You Need to Split Your Home Network

The calculator does the heavy lifting for you. The subnet mask isn’t a table to be memorized; it’s an expression of bounds. A mask like 255.255.255.0 is just a way of saying that the first twenty-four bits define the network and last eight bits define the hosts. That gives you two hundred fifty-four usable addresses, which is plenty for a flat home LAN.

But if you’re dividing your traffic flow, that block’s too large: you don’t want gaming PC on the same segment as the smart camera or the work laptop on the same one as the IoT devices. The calculator split the block in smaller ones, but not by guesswork. Engineers talk about these slice using CIDR notation. That’s slash twenty-four by default; tighter is a slash twenty-six.

That leaves you with sixty-two usable hosts, restrictive, but fine if this is a VLAN devoted solely to your smart home devices. And of course you don’t need that much room but you don’t want those things hanging out in the same space as your critical infrastructure. With the tool you can play around with prefixes right then and there. See where a slash twenty-eight will fit into small management VLAN with just fourteen usable hosts. It forces you to think about capacity first before you configure the network.

It does not account for reserved addresses. Every subnet have a network and broadcast address that must be included, decreasing available space by two. The calculator does this math for you; no need to deduct it yourself. And it displays the subnet’s wildcard mask (the opposite of the subnet mask), which comes into play when creating an access control list or firewall rule. Those systems often use wildcard notation to define what traffic to allow or deny. Understanding the distinction helps you avoid misconfiguring your firewall.

This goes for VLAN size as well. You might be tempted to make all your VLANs slash twenty-four because “more is better,” but it isn’t. More specific subnets can be more easy secured and audited. Twenty phones on guest Wi-Fi? Twenty-seven will be enough and still keep your address space clean.

Common scenarios like point-to-point links gets their own preset buttons in the calculator. This lets you see how that slash thirty makes sense different than clusters of devices that need a slash twenty-two. It connects theory to practice. When you carve up your IP space, you need to know what lives where. If you’re splitting up your IP space, then you’d better know what goes where!

The tool will output a nice little cheat sheet you can save/print off as a reference to the broadcast address and range of each network. This is super handy if you ever have any connectivity problems down the road. Otherwise, good luck remembering what VLAN is on which subnet… gotta dig around in config files again.

At the end of the day, subnetting is all about control. Who talks to who? And who doesn’t? The calculator take friction out of this decision making so you can spend more time designing your networks instead of doing math. Now you’re confident enough to break up the network in meaningful ways (i.e., into logical segments). Each segment clearly defines how many hosts it’ll support. It breaks down an otherwise complicated procedure into simple, doable steps.

The more machines you have in your lab, the more organized it needs to be. One subnet becomes multiple VLANs. Each one has its own set of security concerns and reasons for existing. What you’ll learn here will apply as you scale up. This isn’t about adding IP addresses. It’s about creating an efficient, orderly, and most importantly, secure network. And the beginning of that is knowing how to define the rules of the road. These rules range from boundaries to masks, so that your digital space stays in line.

It should of been easier if you use the tool. Actually, it makes sense more than anything else. You’ll recieve better results with a moddern approach.

Subnet Mask Cheat Sheet Generator for Home Labs

Related posts

Leave a Comment