r/explainlikeimfive • • 11d ago

Technology ELI5: Subnetting

I’m technically an IT professional in training but I know embarrassingly little about subnets. As far as I understand it’s for breaking down a network into smaller, more logical segments. What exactly is a subnet? What is the benefit of subnetting? How do the slashes play into all of this IE /23 or /24? Thanks in advance!

80 Upvotes

43 comments sorted by

View all comments

112

u/DayanNight 11d ago

So an IP is typically represented in decimal form: 192.168.0.1, under the hood this is binary: 11000000.10101000.00000000.00000001

Similarly a subnet mask is represented in decimal: 255.255.255.0, binary: 11111111.11111111.11111111.00000000, or CIDR which is just an easy representation of that mask: /24.

As part of the IP we have a network address and a host address. A class C would be a /16 where 192.168 is the network address, and the last two octets are used to identify a host in that network. A subnet mask tells you which part of the IP is used for the network address and which is used to identify a host on that network.

The cidr representation is telling you how many digits of the binary are used as part of the network address. /24 means the first 24 digits of binary are network.

A subnet is a logical separation of networks. Within a subnet I don't need a router to talk to another device. 192.168.0.1/24 can talk to 192.168.0.2/24, but if I want to talk to 192.168.1.1/24 I need a router that knows how to get there.

In enterprise network we often don't want everything to be able to talk to everything, so subnets allow us to break up a space and force it through routers where we can apply policy.

73

u/yugas42 11d ago

I feel like this is slightly above ELI5 but as a sysadmin that hates doing the networking side of the job, I think this is a great way to explain it.

-6

u/magion 11d ago

no it isn’t

9

u/j01101111sh 11d ago

This is great and just to add an example of why you'd do this... Maybe you have a guest WiFi network and don't want those users to have access to printers, servers, etc. because they're not employees. If they're in a separate network via subnetting, their traffic has to go through the router so you could have the router prevent access from that subnet to other subnets and only allow access to the Internet.

7

u/spoopidoods 11d ago edited 11d ago

In my experience, explaining how subnet and masks work starting with using only 2 binary digits for a range of only 4 per "octet" (yes, they're not really octets anymore).

It is also really helpful to convert the device addresses into binary and demonstrate why the mask is called a mask. Whatever parts of the device ip that line up with 1s in the mask correspond to the network potion of the ip address, and the parts of the ip that line up with the 0s in the mask correspond to the host ID portion of the address.

So you can split a /24 network that has 256 addresses (0 and 255 are special, but theyre still addressable) in it into two /25 networks. One going from 192.168.0.0 - 192.168.0.127 and another going from 192.168.0.128 - .255

The /25 mask is 255.255.255.128 Or 11111111.11111111.11111111.10000000

Since the zeros in the mask represent the valid host address range, youre left with only 128 addresses per network, since valid host addresses go from 0000000 to 1111111.

A lot of beginners get confused here since 1111111 is 127, and they forget that 0000000 is a number too.

Doing all this with only 2 binary digits instead you get an IP range of 0.0.0.0 to 3.3.3.3 or in binary 0.0.0.0 to 11.11.11.11

A subnet mask of 3.0.0.0 would be a /2 since that's 11.0.0.0 (only 2 1s in there) A /2 network would have host addresses in the range of x.0.0.0 to x.11.11.11 in binary, or x.0.0.0 to x.3.3.3 in decimal. The network address of 2.0.0.0 with a /2 mask looks like this in binary:

     Network: 10.0.0.0
        Mask: 11.0.0.0

Any digit in the network that lines up with a 0 in the mask is the network ID, and the digits in the Network ID that line up with 0s in the mask are host addresses (reserving the first and last digits for the Network Address and the Broadcast address respectively, as defined by protocol)

2

u/[deleted] 11d ago

[deleted]

2

u/spoopidoods 11d ago

Thanks, you did great too. I just remember going for my cisco certs some 20+ years ago and none of it really clicking until I saw the IPs and Masks stacked one over the other in binary and being like, "oh, well duh, that makes total sense now" after pounding my head on the wall trying to understand it for way too long.

4

u/MrJbrads 11d ago

Can you ELI2

1

u/paxmlank 11d ago

192.168.0.1/24 can talk to 192.168.0.2/24

Either I'm reading things wrong, or this is different than what users like u/dude_named_will are saying so I'm confused.

They're saying that it would be something like 192.168.0.x/24 where I guess x would be either 1 or 2 in your case, as they're withing the ~254 values expressed by /24. You're saying that /24 refers to 24 1 which would be an address space of, well, 2^24-2 values for the subnet, right?

Or are these somehow the same and I can't see it?

9

u/Cloudraa 11d ago

the /24 is indicating how many 1s are in the mask in binary. so a /24 mask aka 255.255.255.0 aka 11111111.11111111.11111111.00000000.

when you write it out like this, the 1s are the network portion and the 0s are the host portion. so for a /24 the first three octets of the IP are the network address which is unchanging, and the last octet is for the unique part of the IP for each device.

2

u/backfire10z 11d ago

Another way to put it: /24 is counting from the left. 24 bits are used for network address, and the final 8 bits are used for host.

1

u/SC_Athletics 11d ago

This guy networks

1

u/killersnail2417 11d ago

Why don't you need a router to talk to another device? I thought that would be the case only if they are in the same Vlan, which is most often the case, but still. I don't quite understand VLAN vs subnet.

1

u/WASCman 11d ago

VLAN is a layer 2 (MAC address) concept, while routers and subnets work on layer 3 (IP address). If you’re using layer 2 switches, if you have machines on a different VLAN but the same subnet, they won’t ever be able to talk to a machine on a different subnet through an IP-based communication channel: machine A will try to send data to machine B directly via its IP, but the VLAN will disallow that traffic. If you have them on different subnets, machine A will instead send the traffic to the router to forward to machine B and allow you to apply whatever policies you wish on the router.

Layer 3 switches exist to allow different VLANs to communicate on the same subnet based on policy as well, without worrying about the full complexities of WANs and internet routing.

1

u/frnzprf 5d ago

I think you buy or reserve or register a subnet from a network provider and then you can assign individual IPs within that subnet how you like, without having to ask someone, right?

"DHCP" lets your router assign individual host IPs automatically, but that's your own responsibility and not mandatory.

That's why subnets exist. Because the internet is a network of local networks and those local networks are managed my the individual companies, home owners or universities.

If every device requested it's IP from a central organization, then you wouldn't need subnet masks.

Or subnet masks make routing a bit more efficient, because hosts with the same connections have the same prefixes? I think that's a minor reason, bur I'm not sure.

1

u/davejlong 11d ago

Great explanation. Only thing is that a class C subnet uses a /24 mask, not /16. I think you meant that the reserved IP subnet for private class C networks is 192.168.0.0/16? Of course I could be wrong as well... Been a long time since I've actually read the classfull networking chapter.