IP Addressing and Subnetting Questions
Working with IP address space: IPv4 and IPv6 addressing, subnet masks and CIDR notation (including why classful addressing was abandoned), VLSM calculation, route summarization from an addressing standpoint, private (RFC1918), ULA, link-local (including 169.254 self-assigned) and public ranges, and multicast address ranges. Covers designing hierarchical addressing schemes for sites, VLANs, security zones, DMZs and data centers, laying out prefixes so ACL and QoS policy stays compact, NAT and CGNAT for address conservation, static versus DHCP-assigned addressing, IPAM practice, renumbering after mergers or overlaps, and IPv4-to-IPv6 transition (dual-stack, tunneling, NAT64/DNS64). Boundary: routing protocol operation, cloud VPC topology, DNS and DHCP service operation, and firewall design are covered elsewhere.
What is the difference between public and private IPv4 address space? When would you put hosts on private addresses behind translation, when would you give them public addresses, and what do those choices mean for security and visibility?
Sample Answer
Direct answer
Public IPv4 addresses are globally unique, allocated through the regional internet registries (the non-profit bodies such as ARIN and RIPE NCC that hand out public blocks) and ISPs, and routable across the internet. Private addresses are the three blocks RFC 1918 sets aside for anyone to reuse inside their own network: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. They are not routed on the public internet, so a host using one needs address translation (NAT) to reach the internet. Default to private addresses behind translation for clients and most servers, and give a host a public address only when the outside world must initiate connections to it directly and a reverse proxy (a server that accepts outside connections and passes them on to the real servers behind it) or load balancer in front is not enough.
The two kinds of space
| Public | Private (RFC 1918) | |
|---|---|---|
| Uniqueness | Globally unique | Reused by everyone, unique only inside one network |
| Routable on the internet | Yes | No: ISPs do not route them |
| Cost | Scarce, leased from an ISP or registry | Free |
| Size | The rest of the 4,294,967,296 IPv4 addresses (minus reserved ranges) | 16,777,216 + 1,048,576 + 65,536 = 17,891,328 addresses, about 0.42% of the total |
How translation works, with an example
500 laptops in 10.20.0.0/22 all browse the web through one firewall that holds a single public address, say 203.0.113.10 (a documentation address). PAT (port address translation, the many-to-one form of NAT) rewrites each outbound connection's source to 203.0.113.10 with a distinct source port, and keeps a table of "inside 10.20.1.57 port 51432 is outside 203.0.113.10 port 40001" so replies can be sent back to the right laptop. One public address therefore serves hundreds of hosts at once. Replies are only accepted when they match a table entry, which is a side effect of statefulness (the device remembers each connection it has seen leave), not a policy.
Which choice when
- Private behind translation (default): laptops, phones, printers, internal servers, databases, and cloud workloads in private subnets that reach the internet through a NAT gateway (a cloud-provider service that does PAT for them). It conserves scarce public space and lets you renumber the inside without telling the world.
- Public address, directly: internet-facing services such as a mail server (other mail servers check that the sending address has a matching reverse DNS record (a PTR record, which maps the address back to a name) and a reputation, which needs a stable address of its own), VPN gateways, a DNS server for your zone, and load balancers or reverse proxies. Usually only the proxy or load balancer gets the public address, and the application servers behind it stay private.
- Private with static (destination) NAT: a published service on an internal host reached through a public address and a port mapping. This is a middle path, but it still depends on the translation device being configured per service.
- Public on every host: rarely right for clients; it only makes sense if you have the space and a firewall policy that is genuinely default-deny inbound.
Security and visibility consequences
- NAT is not a firewall. Hiding an address is not access control. A private host is protected because a stateful firewall (one that tracks connections and only lets in traffic that belongs to one that started inside) only admits traffic that matches an outbound connection or an explicit rule. Put the same host on a public address behind the same default-deny rule and it is no more exposed; put a private host behind a NAT with an inbound mapping and it is as exposed as that mapping allows. Address privacy is a small benefit (attackers learn nothing about the internal layout from packets), not the control.
- External visibility loses detail. Remote sites see all 500 laptops as 203.0.113.10: rate limits, blocklists and abuse reports hit everyone behind it, and one infected laptop can get the shared address blocked.
- Internal visibility needs translation logs. To answer "which laptop made this connection?" you need the NAT table (inside address and port, outside address and port, timestamps) exported to your logging system; without it, an abuse report naming 203.0.113.10 at 14:02 cannot be traced to a host. Flow records on the inside interface (per-connection summaries of source, destination, ports and bytes that routers and firewalls can export, such as NetFlow) also keep the real source address.
- Overlap hazard: because everyone reuses private space, two companies that merge, or a VPN to a partner, may both use 10.0.0.0/8 subnets. A unique internal plan, kept in IPAM (IP address management), avoids this.
- Inbound reachability: private hosts cannot be reached from outside without an explicit mapping, and peer-to-peer or protocols that embed addresses in their payload can break under translation.
Pitfalls
- Calling NAT "the firewall" and leaving the inbound policy open.
- Assuming 172.16.0.0/12 means "172.16.x.x only": the block runs 172.16.0.0 to 172.31.255.255.
- Giving servers public addresses "because they are servers" with no inbound policy.
Describe how an IPv6 address is written and structured, and what kinds of addresses a single IPv6 interface typically holds at once. How does that differ from the IPv4 picture you are used to?
Sample Answer
Direct answer
An IPv6 address is 128 bits written as eight groups of four hexadecimal digits separated by colons, usually split into a 64-bit network prefix and a 64-bit interface identifier (the part that names the host on that network). A single interface normally holds several addresses at once: a link-local address, one or more global (or unique local) addresses, and a set of multicast group memberships. IPv4 usually gives an interface one address and uses broadcast.
Notation
Full form: 2001:0db8:0000:0000:0000:ff00:0042:8329. Two rules shorten it:
- Leading zeros in each group can be dropped:
2001:db8:0:0:0:ff00:42:8329. - One run of consecutive all-zero groups becomes
::, only once per address:2001:db8::ff00:42:8329.
The recommended text form (RFC 5952, the standard that defines one canonical way to write an address so logs and searches agree) is lowercase, shortens the longest zero run (the first if tied) and never uses :: for a single zero group. Prefix length is written like IPv4: 2001:db8:0:1::/64.
Structure
- A /64 is the standard subnet size. The low 64 bits are the interface identifier, which stateless address autoconfiguration (SLAAC, where a host builds its own address from the prefix a router announces in a router advertisement message) relies on.
- Typical allocation: an ISP gives a site a /48 or /56, and each VLAN gets a /64 from it.
Address types an interface holds
| Type | Range | Role |
|---|---|---|
| Link-local | fe80::/10 | Mandatory on every IPv6 interface, valid on one link only, used for neighbor discovery (how IPv6 hosts find other hosts and routers on the link and learn their MAC addresses) and often as the router next hop |
| Global unicast (GUA) | 2000::/3 | Routable on the internet; usually one stable plus temporary privacy addresses |
| Unique local (ULA) | fc00::/7, in practice fd00::/8 | Private, internal addressing (RFC 4193); locally assigned prefixes use fd00::/8 |
| Multicast | ff00::/8 | Every host joins all-nodes ff02::1 and a solicited-node group, which is ff02::1:ff followed by the last 24 bits of the unicast address (a small multicast group used to look up that address's owner) |
| Loopback | ::1 | Local host |
Temporary addresses (RFC 8981) are randomized and by default prefer a 1-day lifetime and expire after 2 days, used for outgoing connections to resist tracking.
In daily work the link-local address, the global unicast address and the all-nodes multicast membership are present on essentially every interface; ULA and loopback appear in specific designs.
Worked example
A laptop on VLAN 20 (illustrative addresses) might show: fe80::1c2b:3dff:fe44:5566 (link-local), 2001:db8:0:20:1c2b:3dff:fe44:5566 or a stable-random variant (global), 2001:db8:0:20:9a7e:41d2:6b0c:e5f1 (temporary), plus ff02::1 and the solicited-node groups described below. In the two addresses ending 1c2b:3dff:fe44:5566, the first four groups are the network part (fe80:0:0:0 for link-local, 2001:db8:0:20 for global) and the last four groups, 1c2b:3dff:fe44:5566, are the interface identifier. Here the identifier comes from the NIC's MAC address 1e:2b:3d:44:55:66: ff:fe is inserted in the middle and one bit in the first byte is flipped (1e becomes 1c), which is the modified EUI-64 method. The stable-random variant and the temporary address use random identifiers instead, so they show no ff:fe. The solicited-node group for the first two addresses is ff02::1:ff44:5566, the fixed prefix plus the last 24 bits (44:5566). Because the group is derived from each address's own last 24 bits, the temporary address (ending 6b0c:e5f1) joins a different group, ff02::1:ff0c:e5f1, so this interface holds two solicited-node memberships (one shared by the first two addresses, one for the temporary address) next to ff02::1. That is three unicast addresses plus the multicast memberships on one interface, which is normal.
Difference from IPv4
- Multiple addresses per interface by design, versus usually one.
- No broadcast: multicast and NDP (Neighbor Discovery Protocol, the neighbor discovery described above) replace broadcast and ARP.
- Address scarcity disappears, so NAT is not needed for conservation, and routers do not fragment packets in transit.
- Autoconfiguration (SLAAC) or DHCPv6 instead of DHCP alone.
Pitfalls
- Using
::twice in one address (ambiguous and invalid), or writing the same address in different compressed forms, which makes searching logs unreliable. - Subnetting smaller than /64 and breaking SLAAC.
- Blocking all ICMPv6 at a firewall, which breaks neighbor discovery.
Explain what a subnet mask is and how it differs from CIDR (prefix) notation. Include examples: convert 255.255.255.0 and 255.255.255.192 to their CIDR equivalents, explain network vs host bits, and describe how these notations are used in routing, access lists, and documentation.
Sample Answer
Direct answer
A subnet mask and a prefix length say the same thing in two spellings. Both mark where the network part of an IPv4 address ends and the host part begins. The mask writes it as a 32-bit pattern in dotted decimal (255.255.255.0). The CIDR (Classless Inter-Domain Routing) prefix writes it as a count of leading 1 bits (/24). 255.255.255.0 is /24 and 255.255.255.192 is /26.
Network bits vs host bits
An IPv4 address is 32 bits. The mask has 1s over the network bits and 0s over the host bits. A device ANDs the address with the mask to get the network address. AND works bit by bit and gives 1 only when both bits are 1, so wherever the mask has a 1 the address bit is kept, and wherever the mask has a 0 the result is 0. For the last octet of 192.168.10.77 with mask 255.255.255.192: 01001101 AND 11000000 = 01000000, which is 64. Two addresses are on the same subnet when that result is equal. Host bits then number 32 minus the prefix, and an ordinary subnet holds 2^(host bits) addresses, of which two are reserved (all-zeros network address, all-ones broadcast).
| Dotted mask | Binary of the last non-255 octet | Prefix | Host bits | Usable hosts |
|---|---|---|---|---|
| 255.255.255.0 | 00000000 | /24 | 8 | 254 |
| 255.255.255.192 | 11000000 | /26 | 6 | 62 |
How to convert 255.255.255.192: the first three octets are 255, which is 8 ones each, so 24. The last octet 192 = 128 + 64 = binary 11000000, two more ones, so 24 + 2 = 26. Going the other way, /26 means 26 ones then 6 zeros, so the last octet is 11000000 = 192.
What differs between the notations
- Information: none. A valid mask is always a run of ones followed by a run of zeros, so it maps to exactly one prefix length. (Old gear allowed non-contiguous masks such as 255.0.255.0; modern practice and CIDR do not.)
- Readability: the prefix is shorter, is easier to compare (a /26 is smaller than a /24) and attaches to the address (10.1.2.64/26).
- Where each appears is mostly vendor habit, as shown below.
How each notation is used
- Routing tables and documentation: a route is a prefix, for example 10.1.2.0/24. When several routes match a destination, a router picks the one with the longest prefix, meaning the most leading bits fixed, because it is the most specific. With routes 10.1.2.0/24 and 10.1.2.64/26 and a packet for 10.1.2.70, both match (70 falls inside 64 to 127), and the /26 wins because it matches 26 bits instead of 24. Many CLIs show prefix form (Linux
ip route, NX-OS, Junos); classic Cisco IOS static routes take a dotted mask (ip route 10.1.2.0 255.255.255.0 192.0.2.1). - Access lists (ACLs): Cisco IOS standard and extended ACLs use a wildcard mask, which is the inverse of the subnet mask: subtract each octet of the mask from 255. For 255.255.255.192 that gives 0.0.0.63 (255 - 192 = 63), and for 255.255.255.0 it gives 0.0.0.255, so 0.0.0.255 matches a /24 and 0.0.0.63 matches a /26 (a 1 bit means "do not care"). Firewalls, cloud security groups and most modern syntaxes take the prefix form directly (
10.1.2.0/24). Confusing a wildcard with a subnet mask is a classic mistake that silently matches the wrong range. - Documentation and IPAM (IP address management) records: write prefix form. It is unambiguous, sorts well and is what tools and APIs expect.
Worked example
Host 192.168.10.77 with mask 255.255.255.192 (/26). Last octet 77 = 01001101; keeping the top 2 bits gives 01000000 = 64, so the network is 192.168.10.64/26. Host bits are the remaining 001101 = 13, so the host sits 13 addresses above the network address. The subnet runs 192.168.10.64 to 192.168.10.127, with 127 as broadcast.
Pitfalls
- Reading 255.255.255.192 as "a /25 or a /27" by guessing: count the bits.
- Using a subnet mask where an ACL wants a wildcard (or the reverse).
- Assuming the mask depends on the address range. It does not, only the configured prefix does.
Given the IPv4 network example 192.168.10.0 with netmask 255.255.255.192, calculate the CIDR prefix length, the number of usable hosts per subnet, the block size, and show the network and broadcast addresses for the first two subnets. Explain the method you used.
Sample Answer
Direct answer
For 192.168.10.0 with mask 255.255.255.192: the prefix is /26, each subnet has 64 addresses of which 62 are usable hosts, the block size is 64 in the last octet, and the first two subnets are 192.168.10.0/26 (broadcast .63) and 192.168.10.64/26 (broadcast .127).
Method
- Mask to prefix. 255.255.255 is 24 ones. The last octet 192 is binary 11000000, which adds 2 ones. Prefix = 26.
- Host bits. 32 - 26 = 6 host bits.
- Addresses and usable hosts. 2^6 = 64 addresses. An ordinary subnet reserves the first (network address) and the last (broadcast address), so usable hosts = 64 - 2 = 62.
- Block size. Find the octet where the mask is neither 255 nor 0 (here the last one, 192; the "interesting octet" is just that one, because it is the only octet the subnet boundary falls inside). Subtract its value from 256: 256 - 192 = 64. Subnets start at multiples of 64 in that octet: 0, 64, 128, 192. This gives four /26 subnets inside the /24 (2^(26-24) = 4).
- Network, broadcast, range. Network = the multiple of 64. Broadcast = next network minus 1. Usable range = network + 1 to broadcast - 1.
Result table
| Subnet | Network | First usable | Last usable | Broadcast |
|---|---|---|---|---|
| 1 | 192.168.10.0/26 | 192.168.10.1 | 192.168.10.62 | 192.168.10.63 |
| 2 | 192.168.10.64/26 | 192.168.10.65 | 192.168.10.126 | 192.168.10.127 |
The remaining two are 192.168.10.128/26 (broadcast .191) and 192.168.10.192/26 (broadcast .255).
Pitfalls
- Counting 64 usable hosts (forgetting network and broadcast).
- Starting the second subnet at .63 or .65 instead of .64: networks must start on a multiple of the block size, or the address bits below the prefix are not all zero.
- Applying the 256 - mask shortcut to the wrong octet. Example: with 255.255.240.0 the boundary falls inside the third octet, so the block size is 256 - 240 = 16 counted in the third octet (subnets 10.0.0.0, 10.0.16.0, 10.0.32.0 ...), not in the last octet. Always find the octet where the mask is neither 255 nor 0 first, and count blocks in that octet.
- /31 (point-to-point links, RFC 3021) and /32 (a single host or loopback) do not follow the minus-2 rule, but they are not what this mask produces.
That is every published IP Addressing and Subnetting question for Cloud Engineer so far. Browse the other topics in this category, or practice this one interactively.