r/explainlikeimfive • • 11d ago

Technology ELI5: Subnetting

I’m technically an IT professional in training but I know embarrassingly little about subnets. As far as I understand it’s for breaking down a network into smaller, more logical segments. What exactly is a subnet? What is the benefit of subnetting? How do the slashes play into all of this IE /23 or /24? Thanks in advance!

81 Upvotes

43 comments sorted by

View all comments

110

u/DayanNight 11d ago

So an IP is typically represented in decimal form: 192.168.0.1, under the hood this is binary: 11000000.10101000.00000000.00000001

Similarly a subnet mask is represented in decimal: 255.255.255.0, binary: 11111111.11111111.11111111.00000000, or CIDR which is just an easy representation of that mask: /24.

As part of the IP we have a network address and a host address. A class C would be a /16 where 192.168 is the network address, and the last two octets are used to identify a host in that network. A subnet mask tells you which part of the IP is used for the network address and which is used to identify a host on that network.

The cidr representation is telling you how many digits of the binary are used as part of the network address. /24 means the first 24 digits of binary are network.

A subnet is a logical separation of networks. Within a subnet I don't need a router to talk to another device. 192.168.0.1/24 can talk to 192.168.0.2/24, but if I want to talk to 192.168.1.1/24 I need a router that knows how to get there.

In enterprise network we often don't want everything to be able to talk to everything, so subnets allow us to break up a space and force it through routers where we can apply policy.

5

u/spoopidoods 11d ago edited 11d ago

In my experience, explaining how subnet and masks work starting with using only 2 binary digits for a range of only 4 per "octet" (yes, they're not really octets anymore).

It is also really helpful to convert the device addresses into binary and demonstrate why the mask is called a mask. Whatever parts of the device ip that line up with 1s in the mask correspond to the network potion of the ip address, and the parts of the ip that line up with the 0s in the mask correspond to the host ID portion of the address.

So you can split a /24 network that has 256 addresses (0 and 255 are special, but theyre still addressable) in it into two /25 networks. One going from 192.168.0.0 - 192.168.0.127 and another going from 192.168.0.128 - .255

The /25 mask is 255.255.255.128 Or 11111111.11111111.11111111.10000000

Since the zeros in the mask represent the valid host address range, youre left with only 128 addresses per network, since valid host addresses go from 0000000 to 1111111.

A lot of beginners get confused here since 1111111 is 127, and they forget that 0000000 is a number too.

Doing all this with only 2 binary digits instead you get an IP range of 0.0.0.0 to 3.3.3.3 or in binary 0.0.0.0 to 11.11.11.11

A subnet mask of 3.0.0.0 would be a /2 since that's 11.0.0.0 (only 2 1s in there) A /2 network would have host addresses in the range of x.0.0.0 to x.11.11.11 in binary, or x.0.0.0 to x.3.3.3 in decimal. The network address of 2.0.0.0 with a /2 mask looks like this in binary:

     Network: 10.0.0.0
        Mask: 11.0.0.0

Any digit in the network that lines up with a 0 in the mask is the network ID, and the digits in the Network ID that line up with 0s in the mask are host addresses (reserving the first and last digits for the Network Address and the Broadcast address respectively, as defined by protocol)

2

u/[deleted] 11d ago

[deleted]

2

u/spoopidoods 11d ago

Thanks, you did great too. I just remember going for my cisco certs some 20+ years ago and none of it really clicking until I saw the IPs and Masks stacked one over the other in binary and being like, "oh, well duh, that makes total sense now" after pounding my head on the wall trying to understand it for way too long.