10.0.0.0/16 and 10.0.4.0/24 throughout AWS networking. The address before the slash identifies the range. The number after the slash tells you how many leading bits are fixed.
Read the slash number
IPv4 addresses contain 32 bits. A/24 fixes the first 24 bits and leaves 8 bits for addresses inside the range. That gives the block 256 addresses because 2^8 = 256.
A smaller slash number means a larger address range. A
/16 contains many /24 networks. A /28 is much smaller than a /24.
AWS reserves five IPv4 addresses in every VPC subnet. A
/24 therefore has 251 addresses available to resources, not 256.VPC blocks and subnet blocks
A VPC receives a CIDR block such as10.20.0.0/16. Every subnet must use a non-overlapping portion of that VPC range.
For example, you could divide the VPC across two Availability Zones:
Why overlap causes problems
Networks use the destination address to choose a route. If two connected networks both claim10.20.0.0/16, a router cannot reliably know which network should receive traffic.
Overlap commonly appears when teams create VPCs independently and connect them later through peering, a transit gateway, a VPN, or another private network. Fixing it can require renumbering workloads, which is much harder than reserving ranges early.
A practical planning method
- Reserve a private address range for the organization.
- Allocate a distinct block to each account, region, or environment.
- Divide each VPC into subnets by Availability Zone and purpose.
- Leave unused space between allocations for growth.
- Record the assignments in one source of truth.
What about IPv6?
IPv6 uses 128-bit addresses and much larger ranges. AWS commonly assigns a/56 IPv6 block to a VPC and uses /64 blocks for subnets. The planning goal remains the same: use predictable, non-overlapping allocations and understand where routes send traffic.
The useful mental model
Think of a CIDR block as a boundary, not as a network feature by itself. It answers one question: which IP addresses belong to this range? Route tables, security groups, network ACLs, gateways, and endpoints decide what those addresses can reach. When Springwinter creates resources in your AWS account, those resources still consume addresses from your VPC and subnets. Understanding CIDR helps you diagnose exhausted subnets, connection failures, and future network integrations without treating the VPC as a black box.Frequently asked questions
What does /24 mean in a CIDR block?
What does /24 mean in a CIDR block?
A
/24 fixes 24 of the 32 bits in an IPv4 address and leaves 8 bits for host addresses. The block contains 256 total addresses. AWS reserves five addresses in each subnet, leaving 251 addresses available to resources.How large should an AWS VPC CIDR block be?
How large should an AWS VPC CIDR block be?
Size an AWS VPC for current workloads, deployment surge, managed-service ENIs, and expected growth. Leave room for additional subnets and avoid ranges used by networks you may connect later. A
/16 is common, but the correct block depends on the address plan.Can two AWS VPCs use the same CIDR block?
Can two AWS VPCs use the same CIDR block?
Two isolated VPCs can use the same CIDR block, but overlapping ranges prevent straightforward routing when you later connect them with peering, Transit Gateway, VPN, or another private network. Allocate unique ranges when future connectivity is plausible.