Addresses, Subnets and Gateways
Why Classes Disappeared
In one line
The A, B and C classes were the 1981 way of allocating addresses, and in 1993 they were replaced by CIDR. The names survive only because they are convenient for describing private ranges; routers do not look at classes.
Why it was needed
The early internet fixed the size of a network by the first few bits of the address.
| Class | First octet | Network portion | Number of hosts |
|---|---|---|---|
| A | 1–126 | 8 bits | about 16.78 million |
| B | 128–191 | 16 bits | about 65,000 |
| C | 192–223 | 24 bits | 254 |
The problem was that there were only three sizes. For an organization that needs 300 hosts, C (254) is too small and B (65,534) wastes 65,000 addresses. In the early 1990s this waste made it certain that IPv4 addresses would soon run out.
CIDR (Classless Inter-Domain Routing) removed those fixed boundaries. It sets the length of the network portion bit by bit. /23 gives 510 hosts and /26 gives 62. You hand out only as much as is needed.
How it works
192.168.1.0/24 means "the first 24 bits are the network and the remaining 8 bits are the host."
주소 192.168.1.130 = 11000000.10101000.00000001.10000010
마스크 /24 = 11111111.11111111.11111111.00000000
네트워크 192.168.1.0
브로드캐스트 192.168.1.255
쓸 수 있는 주소 192.168.1.1 ~ 192.168.1.254 (254개)
The number of hosts is 2^(32-프리픽스) - 2 (2 to the power of 32 minus the prefix length, then minus 2). You subtract 2 because the network address (all zeros) and the broadcast address (all ones) cannot be given to hosts.
/31 and /32 are exceptions. /31 is reserved for links that connect routers, and both addresses are used (RFC 3021); /32 points to a single address.
Common misconception
"Anything starting with 192.168 is class C" — private ranges and classes are separate topics. RFC 1918 defines three private ranges.
| Range | CIDR | Size |
|---|---|---|
| 10.0.0.0 to 10.255.255.255 | 10.0.0.0/8 |
16.78 million |
| 172.16.0.0 to 172.31.255.255 | 172.16.0.0/12 |
1.04 million |
| 192.168.0.0 to 192.168.255.255 | 192.168.0.0/16 |
65,536 |
A common mistake is to confuse 172.16.0.0/12 with 172.16.0.0/16 and to take 172.20.x.x for a public address. /12 covers 172.16 through 172.31.
Calculating subnets by hand
Once you know the prefix length, the rest is arithmetic.
/24 → 호스트 비트 8개 → 2^8 = 256 주소 → 쓸 수 있는 것 254
/25 → 7개 → 128 → 126
/26 → 6개 → 64 → 62
/27 → 5개 → 32 → 30
/28 → 4개 → 16 → 14
/30 → 2개 → 4 → 2 (라우터 사이 링크에 쓴다)
/31 → 1개 → 2 → 2 (RFC 3021 — 점대점 링크)
The reason you subtract 2 from the total is that the first address is the network address and the last is the broadcast address. In Kubernetes and in the cloud you subtract a few more — AWS reserves 5 addresses per subnet (network, router, DNS, reserved for future use, broadcast).
Here is how to find the boundary.
10.0.5.130/26 이 속한 대역은?
/26 → 블록 크기 64
0, 64, 128, 192 중 130 이 들어가는 것은 128
→ 10.0.5.128 ~ 10.0.5.191, 쓸 수 있는 것은 .129 ~ .190
Designing ranges that do not overlap
This is the most expensive mistake in practice. Once ranges overlap, you can never connect them later.
❌ 흔한 사고
사무실 VPN 192.168.0.0/24
클라우드 VPC 192.168.0.0/24 ← 같은 대역. VPN 으로 못 잇는다
쿠버네티스 파드 10.244.0.0/16
도커 기본 브리지 172.17.0.0/16 ← 사내망이 172.17 이면 컨테이너가 못 나간다
✅ 처음에 표를 만든다
본사 10.10.0.0/16
지사 10.20.0.0/16
클라우드 A 10.100.0.0/16
클라우드 B 10.200.0.0/16
쿠버네티스 파드 10.244.0.0/16, 서비스 10.96.0.0/12
There are only three private ranges (RFC 1918): 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. The 10 range is the widest, so a large organization carves its ranges out of it.
It is worth remembering that Docker's default bridge is 172.17.0.0/16. If the internal network uses that range, containers cannot reach internal servers. In daemon.json, you change it with default-address-pools.
CIDR folds routing
This is the real reason classes disappeared. Adjacent ranges are merged into one (supernetting), which shrinks the routing table.
10.1.0.0/24, 10.1.1.0/24, 10.1.2.0/24, 10.1.3.0/24
→ 10.1.0.0/22 하나로 광고할 수 있다
That is why it pays off later to lay ranges out contiguously when you split them up. If you scatter them randomly, they cannot be merged and the number of routes grows accordingly.
What really matters in practice
Kubernetes stands on top of this arithmetic. If the three CIDRs for Pods, Services and nodes overlap, the cluster behaves strangely, and it is easy to burn days without finding the cause. Checking for overlap comes down to this bit arithmetic.
One more thing — 100.64.0.0/10 is neither private nor public; it is the CGNAT range (RFC 6598). Carriers hand these addresses out to subscribers, so if you use this range on your internal network it collides with the carrier's network. That is also why the network policy in the lab environment blocks this range separately.