/25 subnet: mask 255.255.255.128, 126 usable hosts
Runs in your browser — nothing you paste leaves this page. How we prove that
Subnet Calculator playground
IPv4 or IPv6, with or without a prefix — 10.0.0.0/8, 2001:db8::/48, or a dotted netmask like 192.168.1.0 255.255.255.0. A bare address means one host (/32 or /128).
Results update as you type — press Enter to run now.
Addressing
- Network address
- 10.
0. 0. 0 - Broadcast address
- 10.
0. 0. 127 - Usable host range
- 10.
0. 0. 1 – 10. 0. 0. 126
Masks
- Netmask
- 255.
255. 255. 128 - Wildcard maskInverse of the netmask — the match form Cisco ACLs and OSPF expect.
- 0.
0. 0. 127 - Netmask (binary)The mask bit by bit — the 1s are the network part.
- 11111111.
11111111. 11111111. 10000000
Details
- Address type
- Private (RFC 1918)
- Network (integer)The network address as a single 32-bit number, as scripts and databases store it.
- 167 772 160
A /25 is half of a /24: netmask 255.255.255.128, 128 addresses, 126 usable hosts. Every /24 contains exactly two of them, starting at .0 and .128.
The /25 mask
The 25th bit is the top bit of the last octet, so the mask is 255.255.255.128 and the wildcard 0.0.0.127. That single bit picks the lower half (.0–.127) or the upper half (.128–.255).
2^7 = 128 addresses, 126 usable. In 10.0.0.0/25 hosts go from 10.0.0.1 to 10.0.0.126, and the broadcast is 10.0.0.127. The upper half, 10.0.0.128/25, has network .128 and broadcast .255.
When to split a /24 in two
A /25 pair is the minimum segmentation of an existing /24: servers on one half, clients on the other, or production and staging side by side, each with its own gateway and ACLs. It costs two more unusable addresses than the single /24.
In the cloud, a /25 subnet offers 123 assignable addresses after the five reserved per subnet on AWS and Azure, comfortable for a tier of virtual machines that will never autoscale into the hundreds.
Common mistakes
The gateway for the upper half is often configured as .1 out of habit, which sits in the lower half and is unreachable on-link. In 10.0.0.128/25 the first usable address is .129.
Smaller still, a /26 quarters the /24; larger, two /25s rejoin as the original /24.
Configuring both halves
The lower half takes a gateway such as 10.0.0.1 and a DHCP scope ending at 10.0.0.126; the upper half needs its own gateway at .129 and its own scope. Each half needs its own VLAN or router interface: two /25s on one switch segment with no router between them gain nothing over the original /24.
Firewall rules that referred to the full /24 still match both halves, which is convenient during a migration but means the split adds no isolation until those rules are rewritten per /25.
Plan the split around the gateway you already have. If the existing router sits at .1 it stays in the lower /25, so the upper half is the one that gets a new gateway address and a DHCP change, and its hosts are the ones that move.
FAQ
Questions, answered.
Tap a question to expand the answer.
What are the two /25 networks in 192.168.1.0/24?
192.168.1.0/25 (hosts .1 to .126, broadcast .127) and 192.168.1.128/25 (hosts .129 to .254, broadcast .255).
How many usable hosts does a /25 have?
126, from 128 total addresses.
More free, private DevOps tools.
The Subnet Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Networking
Read more about this
- IPv6 subnet calculator: what ipcalc can't do, and how sipcalc handles /64s An IPv6 subnet calculator explained: why classic ipcalc is IPv4-only, how sipcalc adds IPv6 support, and the exact math behind splitting a /48 into /64s.
- The complete guide to private IP address ranges (RFC 1918) The three RFC 1918 private IP ranges, why 172.16.0.0/12 catches people out, the addresses that look private but aren't, and how to pick a range that won't collide.
New to Networking? Read the Networking guide →
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
More networking: the IP Address Converter, the CIDR / Subnet Checker and the Subnet Splitter, or browse the full tools directory.
Provided as-is for convenience; always confirm critical network changes against your own authority. OpsCanopy is free and open.