/28 subnet: mask 255.255.255.240, 14 usable hosts
Runs in your browser — nothing you paste leaves this page. How we prove that
Subnet Calculator playground
IPv4 or IPv6, with or without a prefix — 10.0.0.0/8, 2001:db8::/48, or a dotted netmask like 192.168.1.0 255.255.255.0. A bare address means one host (/32 or /128).
Results update as you type — press Enter to run now.
Addressing
- Network address
- 10.
0. 0. 0 - Broadcast address
- 10.
0. 0. 15 - Usable host range
- 10.
0. 0. 1 – 10. 0. 0. 14
Masks
- Netmask
- 255.
255. 255. 240 - Wildcard maskInverse of the netmask — the match form Cisco ACLs and OSPF expect.
- 0.
0. 0. 15 - Netmask (binary)The mask bit by bit — the 1s are the network part.
- 11111111.
11111111. 11111111. 11110000
Details
- Address type
- Private (RFC 1918)
- Network (integer)The network address as a single 32-bit number, as scripts and databases store it.
- 167 772 160
A /28 is netmask 255.255.255.240: 16 addresses and 14 usable hosts. It is the smallest subnet AWS lets you create, where only 11 addresses remain assignable.
What /28 means
Four host bits remain, so the mask is 255.255.255.240 and the wildcard 0.0.0.15. Networks start at multiples of 16 in the last octet.
2^4 = 16 addresses, 14 after network and broadcast. 10.0.0.0/28 has usable hosts 10.0.0.1 to 10.0.0.14 and broadcast 10.0.0.15.
The cloud minimum
AWS accepts VPC and subnet blocks from /16 down to /28, so /28 is the floor. AWS reserves five addresses in each subnet: the network address, the VPC router at .1, the DNS resolver at .2, .3 held for future use, and the broadcast. That leaves 11 assignable addresses in a /28.
Azure also reserves five per subnet but allows subnets down to /29. AWS suggests a small dedicated subnet, a /28 is enough, for Transit Gateway attachments; EKS or Lambda subnets need far larger blocks.
Uses and splitting
Use /28 for transit or attachment subnets, a pair of NAT instances, or a small block of public IPs from an ISP. A /28 splits into two /29s, and two aligned /28s make a /27. Sixteen /28s fill a /24.
Configuring and pitfalls
Outside the cloud, 10.0.0.0/28 gives hosts 10.0.0.1 through 10.0.0.14 with the usual network and broadcast exclusions. Inside an AWS VPC the first three host addresses belong to AWS, so your own instances start at .4 and the last assignable address is .14.
Running out of addresses is the common failure: a subnet that holds two instances today cannot absorb a rolling deployment that briefly doubles them, or a managed service that adds interfaces. AWS cannot resize a subnet in place, so a too-small subnet means creating a new one and migrating.
Use /28 where the address count is fixed by design, such as an attachment or firewall subnet, and pick something larger wherever compute will scale. Changing a subnet later costs far more than a few idle addresses now.
FAQ
Questions, answered.
Tap a question to expand the answer.
What is the smallest subnet in AWS?
A /28, which has 16 addresses. After AWS reserves five, 11 are assignable.
How many /28s fit in a /24?
Sixteen, each starting on a multiple of 16 in the last octet.
More free, private DevOps tools.
The Subnet Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Networking
Read more about this
- IPv6 subnet calculator: what ipcalc can't do, and how sipcalc handles /64s An IPv6 subnet calculator explained: why classic ipcalc is IPv4-only, how sipcalc adds IPv6 support, and the exact math behind splitting a /48 into /64s.
- The complete guide to private IP address ranges (RFC 1918) The three RFC 1918 private IP ranges, why 172.16.0.0/12 catches people out, the addresses that look private but aren't, and how to pick a range that won't collide.
New to Networking? Read the Networking guide →
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
More networking: the IP Address Converter, the CIDR / Subnet Checker and the Subnet Splitter, or browse the full tools directory.
Provided as-is for convenience; always confirm critical network changes against your own authority. OpsCanopy is free and open.