The /24 in an IP range isn't arbitrary — it's a precise statement about how many addresses you have and where they start. Once the slash number clicks, subnetting stops being scary.
You're setting up a cloud network and it asks for a CIDR block: 10.0.0.0/16. You type something that looks right, and either it works or you get a range that's mysteriously too small or overlaps something else. CIDR notation feels like arcana, but it's actually a compact, precise way of describing a block of IP addresses — and the moment you see what the slash number is doing in binary, subnetting turns from guesswork into arithmetic.
Where CIDR came from
CIDR exists because the old system was running out of room. Wikipedia explains the origin:
"Classless Inter-Domain Routing is a method for allocating IP addresses for IP routing. The Internet Engineering Task Force introduced CIDR in 1993 to replace the previous classful network addressing architecture on the Internet."
— Wikipedia, "Classless Inter-Domain Routing" (CC BY-SA 4.0)
The old "classful" system only offered fixed, wasteful block sizes. CIDR let networks be carved at any size, which is exactly why you now specify that size with a slash number.
What the slash number counts
An IPv4 address is 32 bits — four groups of 8 (the dotted numbers you see, each 0–255). The number after the slash says how many of those 32 bits are fixed as the network part; the rest are free for hosts. So /24 means the first 24 bits are locked and the last 8 are yours to assign. Eight free bits means 2⁸ = 256 addresses. That's the whole trick: the host bits are 32 minus the slash number, and the number of addresses is 2 to that power.
/24→ 8 host bits → 256 addresses (a typical small subnet)./16→ 16 host bits → 65,536 addresses (a big block, common for a whole VPC)./32→ 0 host bits → exactly one address (a single host).
Smaller slash number = bigger network. That inverse relationship is the thing that trips beginners: /16 is far larger than /24, even though 24 is the bigger number.
Reading the range
Because the split happens at a bit boundary, the range is predictable. 10.0.0.0/24 covers 10.0.0.0 through 10.0.0.255 — the last octet runs the full 0–255 because all 8 of those bits are free. 10.0.0.0/25 splits that in half: 10.0.0.0–10.0.0.127 (7 host bits, 128 addresses). The reason binary makes this easy is that the network part is the fixed prefix and the host part counts up from all-zeros to all-ones. See the address in binary once and the range stops being mysterious — it's just "count up in the free bits."
The two addresses you don't get to use
Here's the off-by-one that breaks real deployments. In most contexts, two addresses in every subnet are reserved: the network address (all host bits zero — 10.0.0.0 in a /24) identifies the subnet itself, and the broadcast address (all host bits one — 10.0.0.255) is for sending to everyone on it. So a /24 gives you 256 addresses but only 254 usable ones for actual hosts. Cloud providers often reserve a few more on top for the gateway and internal services. If you size a subnet to fit "exactly 256 devices," you'll come up short — always account for the reserved addresses when you carve a block.
Why VPC blocks overlap (and shouldn't)
The other common failure is overlap. If you give two networks that need to talk to each other overlapping CIDR blocks — say both use 10.0.0.0/16 — routing between them becomes ambiguous and breaks. The fix is planning: allocate non-overlapping blocks from the private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and leave room to grow. Pick blocks that are big enough for expansion but don't collide with anything you might peer with later.
Let the tool do the bit math
You don't have to convert 32-bit masks in your head. A CIDR calculator takes a block like 10.0.0.0/22 and hands you the exact first address, last address, usable host count, and mask — instantly, and correctly including the reserved addresses. To build intuition for why the ranges fall where they do, a number base converter lets you flip an octet between decimal and binary and watch the host bits count up. And if you're validating IP or CIDR strings in code, a regex tester helps you get the pattern right against real sample addresses. Subnetting isn't hard once you stop treating the slash number as a label and start treating it as what it is: a count of fixed bits.