Skip to content

172.16.0.0/12: the private range Docker and AWS use

Runs in your browser — nothing you paste leaves this page. How we prove that

Subnet Calculator playground

Examples

IPv4 or IPv6, with or without a prefix — 10.0.0.0/8, 2001:db8::/48, or a dotted netmask like 192.168.1.0 255.255.255.0. A bare address means one host (/32 or /128).

Results update as you type — press Enter to run now.

fig. 10 — subnet-calculator · networking /12 — 1048574 usable hosts
Result
IPv4172.16.0.0/12
Usable hosts1 048 574
Usable range172.16.0.1 – 172.31.255.254
Total addresses1 048 576

Addressing

Network address
172.16.0.0
Broadcast address
172.31.255.255
Usable host range
172.16.0.1 – 172.31.255.254

Masks

Netmask
255.240.0.0
Wildcard maskInverse of the netmask — the match form Cisco ACLs and OSPF expect.
0.15.255.255
Netmask (binary)The mask bit by bit — the 1s are the network part.
11111111.11110000.00000000.00000000

Details

Address type
Private (RFC 1918)
Network (integer)The network address as a single 32-bit number, as scripts and databases store it.
2 886 729 728

172.16.0.0/12 spans 172.16.0.0 to 172.31.255.255: 1,048,576 addresses under mask 255.240.0.0. It is the middle RFC 1918 range, and the one Docker and the AWS default VPC draw from.

Where the range starts and stops

A /12 fixes the first octet and the top four bits of the second, so the mask is 255.240.0.0 and the wildcard 0.15.255.255. The second octet runs from 16 to 31. 172.15.0.1 and 172.32.0.1 are public addresses, a frequent source of firewall rules that are one octet off.

2^20 = 1,048,576 addresses in total, or sixteen /16s: 172.16.0.0/16 through 172.31.0.0/16. The calculator reports the block as "Private (RFC 1918)".

Who already uses it

Docker's default bridge network is 172.17.0.0/16, and user-defined bridge networks take further /16s from the rest of this block before moving on to 192.168 space. Every developer laptop running Docker therefore holds some of these addresses.

AWS creates every default VPC as 172.31.0.0/16, split into one /20 per availability zone. Many corporate networks also chose 172.16/12 precisely because it looked less crowded than 10/8.

Overlap problems

When a corporate VPN pushes routes for, say, 172.17.0.0/16, Docker on the same laptop has to win or lose that route, and containers or the VPN silently break. Fix it on the Docker side with default-address-pools and bip in daemon.json, or keep company subnets out of 172.17–172.31.

For VPC peering and site-to-site VPNs, avoid the AWS default 172.31.0.0/16 in production; any two default VPCs overlap by definition.

Matching the range in rules

An address is in this block when its first octet is 172 and its second is between 16 and 31 inclusive. With the wildcard 0.15.255.255, the ACL entry permit ip 172.16.0.0 0.15.255.255 any matches the whole range. A shortcut that matches any address starting with 172 is wrong, because it also catches public 172.x space owned by real organisations.

For AWS security groups and most cloud firewalls, write the block as 172.16.0.0/12 rather than listing sixteen /16s; the rule is shorter and cannot miss one.

FAQ

Questions, answered.

Tap a question to expand the answer.

No. 172.16.0.0/12 ends at 172.31.255.255; 172.32.0.0 and above are public.

Docker networks default to 172.17.0.0/16 and nearby /16s. If the VPN routes the same range, one of them loses. Change Docker's address pools in daemon.json.

More free, private DevOps tools.

The Subnet Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

New to Networking?  Read the Networking guide →

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

More networking: the IP Address Converter, the CIDR / Subnet Checker and the Subnet Splitter, or browse the full tools directory.

Provided as-is for convenience; always confirm critical network changes against your own authority. OpsCanopy is free and open.