TT Lab
Get started
Learn Learning paths Courses

Addresses, Subnets and Gateways

Why Classes Disappeared

Continue in TT Lab

In one line

The A, B and C classes were the 1981 way of allocating addresses, and in 1993 they were replaced by CIDR. The names survive only because they are convenient for describing private ranges; routers do not look at classes.

Why it was needed

The early internet fixed the size of a network by the first few bits of the address.

Class First octet Network portion Number of hosts
A 1–126 8 bits about 16.78 million
B 128–191 16 bits about 65,000
C 192–223 24 bits 254

The problem was that there were only three sizes. For an organization that needs 300 hosts, C (254) is too small and B (65,534) wastes 65,000 addresses. In the early 1990s this waste made it certain that IPv4 addresses would soon run out.

CIDR (Classless Inter-Domain Routing) removed those fixed boundaries. It sets the length of the network portion bit by bit. /23 gives 510 hosts and /26 gives 62. You hand out only as much as is needed.

How it works

192.168.1.0/24 means "the first 24 bits are the network and the remaining 8 bits are the host."

주소      192.168.1.130  = 11000000.10101000.00000001.10000010
마스크    /24            = 11111111.11111111.11111111.00000000
네트워크                   192.168.1.0
브로드캐스트               192.168.1.255
쓸 수 있는 주소            192.168.1.1 ~ 192.168.1.254   (254개)

The number of hosts is 2^(32-프리픽스) - 2 (2 to the power of 32 minus the prefix length, then minus 2). You subtract 2 because the network address (all zeros) and the broadcast address (all ones) cannot be given to hosts.

/31 and /32 are exceptions. /31 is reserved for links that connect routers, and both addresses are used (RFC 3021); /32 points to a single address.

Common misconception

"Anything starting with 192.168 is class C" — private ranges and classes are separate topics. RFC 1918 defines three private ranges.

Range CIDR Size
10.0.0.0 to 10.255.255.255 10.0.0.0/8 16.78 million
172.16.0.0 to 172.31.255.255 172.16.0.0/12 1.04 million
192.168.0.0 to 192.168.255.255 192.168.0.0/16 65,536

A common mistake is to confuse 172.16.0.0/12 with 172.16.0.0/16 and to take 172.20.x.x for a public address. /12 covers 172.16 through 172.31.

Calculating subnets by hand

Once you know the prefix length, the rest is arithmetic.

/24 → 호스트 비트 8개 → 2^8 = 256 주소 → 쓸 수 있는 것 254
/25 → 7개 → 128 → 126
/26 → 6개 →  64 →  62
/27 → 5개 →  32 →  30
/28 → 4개 →  16 →  14
/30 → 2개 →   4 →   2   (라우터 사이 링크에 쓴다)
/31 → 1개 →   2 →   2   (RFC 3021 — 점대점 링크)

The reason you subtract 2 from the total is that the first address is the network address and the last is the broadcast address. In Kubernetes and in the cloud you subtract a few more — AWS reserves 5 addresses per subnet (network, router, DNS, reserved for future use, broadcast).

Here is how to find the boundary.

10.0.5.130/26 이 속한 대역은?
  /26 → 블록 크기 64
  0, 64, 128, 192 중 130 이 들어가는 것은 128
  → 10.0.5.128 ~ 10.0.5.191, 쓸 수 있는 것은 .129 ~ .190

Designing ranges that do not overlap

This is the most expensive mistake in practice. Once ranges overlap, you can never connect them later.

❌ 흔한 사고
   사무실 VPN   192.168.0.0/24
   클라우드 VPC 192.168.0.0/24    ← 같은 대역. VPN 으로 못 잇는다
   쿠버네티스 파드 10.244.0.0/16
   도커 기본 브리지 172.17.0.0/16  ← 사내망이 172.17 이면 컨테이너가 못 나간다

✅ 처음에 표를 만든다
   본사        10.10.0.0/16
   지사        10.20.0.0/16
   클라우드 A   10.100.0.0/16
   클라우드 B   10.200.0.0/16
   쿠버네티스 파드 10.244.0.0/16, 서비스 10.96.0.0/12

There are only three private ranges (RFC 1918): 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. The 10 range is the widest, so a large organization carves its ranges out of it.

It is worth remembering that Docker's default bridge is 172.17.0.0/16. If the internal network uses that range, containers cannot reach internal servers. In daemon.json, you change it with default-address-pools.

CIDR folds routing

This is the real reason classes disappeared. Adjacent ranges are merged into one (supernetting), which shrinks the routing table.

10.1.0.0/24, 10.1.1.0/24, 10.1.2.0/24, 10.1.3.0/24
  → 10.1.0.0/22 하나로 광고할 수 있다

That is why it pays off later to lay ranges out contiguously when you split them up. If you scatter them randomly, they cannot be merged and the number of routes grows accordingly.

What really matters in practice

Kubernetes stands on top of this arithmetic. If the three CIDRs for Pods, Services and nodes overlap, the cluster behaves strangely, and it is easy to burn days without finding the cause. Checking for overlap comes down to this bit arithmetic.

One more thing — 100.64.0.0/10 is neither private nor public; it is the CGNAT range (RFC 6598). Carriers hand these addresses out to subscribers, so if you use this range on your internal network it collides with the carrier's network. That is also why the network policy in the lab environment blocks this range separately.