IP Addresses and Subnets for Absolute Beginners
Hyperscaler Network Engineer · Module 1: Data Centers from Zero
Lesson 6 of 8
Prerequisites: What Is a Network, Really?
What you'll be able to do: Read any IPv4 address, explain what the "/24" means, and carve one network into smaller subnets on paper.
Imagine you live at apartment 14. There are a thousand apartment 14s in your city — yours is findable only because the rest of your address narrows it down first: the building, the street, the zip code. The mail carrier finds your building before ever looking for your door.
Every device on a network has the same problem. Its number is only meaningful inside its own "building," and the network needs a way to know which building to deliver to before it hunts for the door. Get this wrong in a real data center and a server's messages walk down the wrong hallway — silent, maddening failures that eat whole afternoons.
The fix is a tiny piece of arithmetic you can do on paper, and it starts with learning to read the address.
Here's the puzzle.
Scenario. You're the new technician at a small Tulsa company. The boss bought one block of addresses — 192.168.10.0/24, all 256 of them — and four server racks that must stay separated: the web rack (40 servers), the database rack (12 servers), the management rack (6 servers), and a spare rack for future growth. The boss wants each rack on its own subnet so a misbehaving web server can't wander into the database's hallway. You get to carve the block into 4 equal pieces.
Given artifacts. The address block and the four racks:
Address block: 192.168.10.0/24 → addresses 192.168.10.0 through 192.168.10.255 (256 total)
Rack WEB: 40 servers — needs its own subnet
Rack DB: 12 servers — needs its own subnet
Rack MGMT: 6 servers — needs its own subnet
Rack SPARE: future growth — needs its own subnet
Four servers already have addresses — after carving, say which rack each belongs to:
192.168.10.17 192.168.10.66 192.168.10.130 192.168.10.200
Rule of thumb (given): the first usable address in a subnet is traditionally the gateway —
the "front door" every device in that hallway uses to leave it.
Your task: Carve 192.168.10.0/24 into 4 equal subnets (one per rack, in WEB / DB / MGMT / SPARE order), state each subnet in CIDR form with its gateway address, and place each of the four given server addresses into its rack.
Workspace: Analyze-and-answer. Type your four CIDR blocks, four gateways, and four placements. Then open the site's subnet calculator tool and check your arithmetic against it — the tool confirms or corrects, but the reasoning must be yours first.
Hint 1 — where to look
This is arithmetic, not memorization. Start by counting: how many addresses does a /24 hold? Now divide that pile into 4 equal piles — how big is each pile?Hint 2 — what to compare
Each pile's size must be a power of two (that's how the splitting math works). You found each pile holds 64 addresses — now, which slash notation describes a 64-address block? Compare: /24 = 256, /25 = 128, so /26 = ?Hint 3 — the mechanism
Splitting means borrowing 2 bits from the host portion of the address, which cuts the block into 4. New block boundaries always land on multiples of the block size — with 64-address blocks, the four subnets start at .0, .64, .128, and .192. The gateway is the first usable address in each.Commitment ritual: ☐ "I've attempted this challenge and thought it through." Check the box (your answer above is recorded either way) and the worked answer in S7 reveals. Nothing is graded — the struggle is the point.
Checking the box reveals the worked answer in S7 below. Returning learners stay unlocked.
Four numbers, three dots
An IPv4 address (the classic network address label — four numbers separated by dots, like 192.168.10.17) is the street address from the last lesson, written in the format the whole internet agreed on. Each of the four numbers is called an octet (one of the four numbers in an IPv4 address — "octet" because each one is 8 binary digits, ranging 0–255). Four octets, each 0 to 255, gives about 4.3 billion possible addresses — plenty for 1983, and the reason the world later needed a longer format you'll meet in Module 2.
Why this matters for the challenge: before you can carve 192.168.10.0/24, you must read it: four octets, each 0–255. The carving happens inside those numbers.
The building number and the door number
Here's the key insight: every IPv4 address is really two addresses glued together. The front part names the network — the building. The back part names the device inside it — the door. The network portion (the front part of an address, identifying which network the device belongs to) is what routers read to pick the right building; the host portion (the back part, identifying the specific device inside that network) picks the door once you're in the right hallway. Two devices with the same network portion are neighbors — same building, different doors.
Why this matters for the challenge: carving one network into subnets means redrawing the line between "building" and "door" — stealing digits from the door numbers to make more building numbers.
The slash tells you where the line is
How does anyone know where the network portion ends and the host portion begins? The subnet mask (a second label, written alongside every address, that marks which octets are "building" and which are "door") draws that line — and engineers almost always write it in shorthand called CIDR notation (pronounced "cider" — a slash plus a number, like /24, counting how many of the address's 32 binary digits belong to the network portion). /24 means the first 24 digits (three full octets) are the building, leaving 8 digits for doors: 2⁸ = 256 addresses. /16 leaves 16 digits for doors: 65,536 addresses. Bigger slash number, smaller building, fewer doors.
Why this matters for the challenge: the "/24" in your block is the starting line. Carving means moving that line — and every move doubles the number of buildings while halving the doors in each.
Why carve at all: hallways, not ballrooms
Why not put all 256 devices in one big happy network? Because networks, like apartment buildings, work better with hallways. A subnet (a smaller network carved out of a bigger one — one hallway inside the building) keeps groups separated: the web servers chatter among themselves without their noise reaching the database servers, and a misconfigured web server can't accidentally claim to be the database. Broadcasts — messages shouted to everyone in the hallway — stay in their hallway instead of bothering the whole building. At hyperscale this isn't tidiness, it's survival: thousands of subnets keep millions of servers manageable.
Why this matters for the challenge: the boss's four racks are four hallways. Your carve is what builds the walls between them.
The front door of every hallway
One address in each subnet has a special job: the gateway (the address every device in a subnet uses as its "front door" — the router it sends packets to when the destination is outside its own hallway). By tradition it's the first usable address in the subnet. A device that wants to reach another hallway doesn't need the whole map — it just walks to the front door and hands its packet to the gateway, which knows the way out. Without a gateway configured, a server can talk to its hallway neighbors and nobody else — the network equivalent of a building with no exit.
Why this matters for the challenge: the deliverable asks for each subnet's gateway. It's always the first usable address — the .1 of whatever block you carved.
Watching a carve happen (a different example)
Let's carve once together — on different numbers than your challenge, so the reasoning stays yours. Take 10.20.30.0/24 and split it into two equal subnets for an office and a lab. A /24 holds 256 addresses; half is 128; the slash for 128-address blocks is /25 (one more network digit borrowed from the doors). The two blocks start at multiples of 128: 10.20.30.0/25 (doors .1–.126, gateway 10.20.30.1) and 10.20.30.128/25 (doors .129–.254, gateway 10.20.30.129). Notice .0 and .127/.255 are reserved as the hallway's "name" and "shout to everyone" addresses — never assigned to devices. Same recipe you'll use in the challenge — we'll solve that one in the worked answer.
- Step 1 of 5: Start with 10.20.30.0/24 — the first three octets are the network portion (blue bar), the whole last octet is host doors, 0–255.
- Step 2 of 5: Borrowing one digit from the host portion moves the line: the blue network bar grows by one bit, the orange host bar shrinks — the mask is now /25.
- Step 3 of 5: A divider drops through the middle of the last octet: two blocks, .0–127 for the office and .128–255 for the lab. One borrowed digit always makes exactly two.
- Step 4 of 5: Each block's first usable address is its gateway — the front door: 10.20.30.1 for the office hallway, 10.20.30.129 for the lab hallway.
- Step 5 of 5: Same recipe, any numbers: count the addresses, divide by the hallways you need, and the slash — plus the boundary rule — does the rest. Your challenge uses this recipe on four racks.
🔒 Revealed after the commitment ritual in S2 — attempt the challenge first. (Honor system: the page hides this until you check the box.)
Step 1 — Count, then divide. A /24 holds 256 addresses (2⁸). Four equal racks → 256 ÷ 4 = 64 addresses per subnet. Each subnet must hold its servers plus the reserved addresses, so check: WEB needs 40 servers, and 64 covers 40 with room to spare. Good — equal quarters work.
Step 2 — Name the slash. /24 = 256, /25 = 128, so /26 = 64. Borrowing 2 digits from the host portion gives 4 subnets. If you answered /25, you'd only get 2 subnets — here's the evidence that rules it out: the boss asked for four racks, and /25 yields two.
Step 3 — Find the boundaries. Block boundaries land on multiples of the block size: .0, .64, .128, .192. The four subnets, in WEB / DB / MGMT / SPARE order:
| Rack | Subnet (CIDR) | Gateway (first usable) | Usable doors |
|---|---|---|---|
| WEB | 192.168.10.0/26 | 192.168.10.1 | .1–.62 |
| DB | 192.168.10.64/26 | 192.168.10.65 | .65–.126 |
| MGMT | 192.168.10.128/26 | 192.168.10.129 | .129–.190 |
| SPARE | 192.168.10.192/26 | 192.168.10.193 | .193–.254 |
Step 4 — Place the four servers. Read the last octet and find which block it's inside: 17 → WEB (0–63); 66 → DB (64–127); 130 → MGMT (128–191); 200 → SPARE (192–255). A tempting wrong turn: putting 192.168.10.64 in WEB — but .64 is the start of DB's block (it's DB's reserved network address), not WEB's last door.
Verify it worked: Open the subnet calculator and enter 192.168.10.0/26. Expected: network 192.168.10.0, 62 usable hosts (.1–.62), broadcast 192.168.10.63. Repeat for .64/26, .128/26, .192/26 — four clean blocks, no overlaps, every server address inside exactly one.
Check yourself — nothing here is graded. Wrong answers are the useful ones; each explains why.
Question 1. In the address 10.20.30.40/24, which part is the network portion?
Question 2. How many usable device addresses does 192.168.1.0/26 provide? (Remember: the first and last address of a block are reserved.)
Question 3. Which subnet does 10.0.5.200 belong to?
Question 4. A new hire configures a server as 192.168.10.75 with mask /25 on a network the team carved as 192.168.10.64/26. The server can reach some neighbors but not others. What's the most likely cause?
Question 5. Your team outgrows the MGMT subnet: 70 devices need addresses but 192.168.10.128/26 only holds 62 usable. You can't renumber the other racks. What do you do?
- An IPv4 address is two addresses glued together — the network portion (which building) and the host portion (which door) — and the slash tells you where the line is.
- CIDR notation counts network bits: each extra bit doubles the number of subnets and halves the addresses in each.
- A subnet is a hallway with walls: it keeps groups separated and keeps shout-to-everyone traffic from bothering the whole building.
- The gateway — traditionally the first usable address — is each hallway's front door; without it, a device can only talk to its own neighbors.
- New subnet boundaries always land on multiples of the block size — if your boundary isn't a multiple, your arithmetic slipped.
Next: Your First Lab — Make Two Servers Talk — you can read addresses and carve subnets on paper; now you'll hand two real servers their addresses and make them actually speak to each other. Try it live in the subnet calculator first if you want a warm-up.