Skip to content

192.168.0.0/16: the home and small-office private range

Runs in your browser — nothing you paste leaves this page. How we prove that

Subnet Calculator playground

Examples

IPv4 or IPv6, with or without a prefix — 10.0.0.0/8, 2001:db8::/48, or a dotted netmask like 192.168.1.0 255.255.255.0. A bare address means one host (/32 or /128).

Results update as you type — press Enter to run now.

fig. 10 — subnet-calculator · networking /16 — 65534 usable hosts
Result
IPv4192.168.0.0/16
Usable hosts65 534
Usable range192.168.0.1 – 192.168.255.254
Total addresses65 536

Addressing

Network address
192.168.0.0
Broadcast address
192.168.255.255
Usable host range
192.168.0.1 – 192.168.255.254

Masks

Netmask
255.255.0.0
Wildcard maskInverse of the netmask — the match form Cisco ACLs and OSPF expect.
0.0.255.255
Netmask (binary)The mask bit by bit — the 1s are the network part.
11111111.11111111.00000000.00000000

Details

Address type
Private (RFC 1918)
Network (integer)The network address as a single 32-bit number, as scripts and databases store it.
3 232 235 520

192.168.0.0/16 is the smallest RFC 1918 range: 65,536 addresses from 192.168.0.0 to 192.168.255.255, mask 255.255.0.0. Nearly every home router hands out a /24 from it.

Size and structure

The mask 255.255.0.0 fixes 192.168 and leaves the last two octets: wildcard 0.0.255.255, 2^16 = 65,536 addresses. The calculator classifies it as "Private (RFC 1918)".

In practice the third octet is a subnet number. The block holds 256 /24s, 192.168.0.0/24 to 192.168.255.0/24, and almost no one uses it as a single /16 network.

Where it shows up

Consumer routers ship with 192.168.0.0/24 or 192.168.1.0/24 as the LAN, with the router at .1. Phone hotspots, printers in setup mode and lab appliances use other low 192.168 subnets. Calico's default Kubernetes pod pool is 192.168.0.0/16, and Docker falls back to /20s from this range once its 172 pool is exhausted.

Why to keep company networks out of it

Because every home network is a 192.168 /24, a corporate subnet in the same range collides with remote workers' LANs. If an office uses 192.168.1.0/24 and an employee's router does too, the VPN client cannot tell which 192.168.1.20 is meant; local traffic usually wins and the office server becomes unreachable.

Use 10/8 or 172.16/12 for anything that must be reached over a VPN, and if 192.168 is unavoidable, pick a high, unusual third octet such as 192.168.213.0/24.

Using it in firewall rules

As an ACL wildcard, the block is 192.168.0.0 0.0.255.255. Filters at the network edge commonly drop packets from the internet that carry RFC 1918 source addresses, since a packet claiming to come from 192.168 space on a public interface is spoofed or leaked.

Inside a network, a blanket rule allowing 192.168.0.0/16 is usually broader than intended. Allow the specific /24 a service needs, so a guest or IoT subnet elsewhere in the block does not inherit access by accident.

The same caution applies to split-tunnel VPN profiles. Sending all of 192.168.0.0/16 through the tunnel hijacks the user's own home LAN, so their printer and router vanish while connected; push only the specific subnets the company actually uses.

FAQ

Questions, answered.

Tap a question to expand the answer.

256, from 192.168.0.0/24 to 192.168.255.0/24.

The remote network probably uses the same /24. Your computer sends that traffic to the local LAN instead of through the tunnel.

More free, private DevOps tools.

The Subnet Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

New to Networking?  Read the Networking guide →

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

More networking: the IP Address Converter, the CIDR / Subnet Checker and the Subnet Splitter, or browse the full tools directory.

Provided as-is for convenience; always confirm critical network changes against your own authority. OpsCanopy is free and open.