/22 subnet: mask 255.255.252.0, 1,022 usable hosts
Runs in your browser — nothing you paste leaves this page. How we prove that
Subnet Calculator playground
IPv4 or IPv6, with or without a prefix — 10.0.0.0/8, 2001:db8::/48, or a dotted netmask like 192.168.1.0 255.255.255.0. A bare address means one host (/32 or /128).
Results update as you type — press Enter to run now.
Addressing
- Network address
- 10.
0. 0. 0 - Broadcast address
- 10.
0. 3. 255 - Usable host range
- 10.
0. 0. 1 – 10. 0. 3. 254
Masks
- Netmask
- 255.
255. 252. 0 - Wildcard maskInverse of the netmask — the match form Cisco ACLs and OSPF expect.
- 0.
0. 3. 255 - Netmask (binary)The mask bit by bit — the 1s are the network part.
- 11111111.
11111111. 11111100. 00000000
Details
- Address type
- Private (RFC 1918)
- Network (integer)The network address as a single 32-bit number, as scripts and databases store it.
- 167 772 160
A /22 is netmask 255.255.252.0: 1,024 addresses with 1,022 usable hosts, or four /24s glued together. It is a frequent choice for a busy office floor or a medium cloud subnet.
What the /22 mask covers
Twenty-two network bits leave ten host bits. The mask 255.255.252.0 means the third octet moves in steps of 4, and the wildcard 0.0.3.255 is what you would type into a Cisco ACL.
2^10 = 1,024 addresses, 1,022 usable once network and broadcast are removed. In 10.0.0.0/22 hosts run from 10.0.0.1 to 10.0.3.254, and the broadcast address is 10.0.3.255. Note that addresses ending in .0 and .255 in the middle of that range, such as 10.0.1.0, are ordinary hosts here.
One /22 or four /24s
A single /22 keeps one gateway, one DHCP scope and one firewall object. Four /24s give four smaller broadcast domains and finer policy. Choose the /22 when the hosts genuinely share a role and the size is driven by headcount; choose /24s when you want segmentation.
On AWS a /22 subnet offers 1,019 assignable addresses after the five reserved ones, a good size for an EKS node subnet when the VPC CNI hands every pod a real IP.
Gotchas
Legacy software sometimes treats any address ending in .0 or .255 as invalid. Inside a /22 those can be valid hosts, so a device that refuses 10.0.2.255 is wrong, not the plan. Avoid handing those addresses to old embedded gear.
For splitting, a /22 halves into two /23s or quarters into four /24s; two adjacent aligned /22s form a /21.
Configuring a /22
On a router the interface takes 10.0.0.1/22 or the address with 255.255.252.0. DHCP scopes should cover 10.0.0.1 to 10.0.3.254 minus reservations, entered as one range rather than four /24-shaped pieces.
When migrating from four separate /24s to one /22, change the mask on every static host in the same window as the gateway. Hosts still on the old mask reach their own /24 directly but go through the router for the other three, which hides the mistake until the router's ACLs or ICMP redirects get in the way.
FAQ
Questions, answered.
Tap a question to expand the answer.
Can a /22 host address end in .255?
Yes. In 10.0.0.0/22, 10.0.0.255, 10.0.1.255 and 10.0.2.255 are normal hosts; only 10.0.3.255 is the broadcast.
How many usable hosts does a /22 have?
1,022: 1,024 addresses minus the network and broadcast addresses.
More free, private DevOps tools.
The Subnet Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Networking
Read more about this
- IPv6 subnet calculator: what ipcalc can't do, and how sipcalc handles /64s An IPv6 subnet calculator explained: why classic ipcalc is IPv4-only, how sipcalc adds IPv6 support, and the exact math behind splitting a /48 into /64s.
- The complete guide to private IP address ranges (RFC 1918) The three RFC 1918 private IP ranges, why 172.16.0.0/12 catches people out, the addresses that look private but aren't, and how to pick a range that won't collide.
New to Networking? Read the Networking guide →
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
More networking: the IP Address Converter, the CIDR / Subnet Checker and the Subnet Splitter, or browse the full tools directory.
Provided as-is for convenience; always confirm critical network changes against your own authority. OpsCanopy is free and open.