> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CIDR Blocks Explained: AWS VPC and Subnet Planning

> Learn CIDR notation, calculate IPv4 address capacity, plan AWS VPC and subnet ranges, and prevent overlapping networks and exhausted subnets.

A CIDR block describes a continuous range of IP addresses. Cloud providers use CIDR notation to decide which addresses belong to a network, a subnet, or an access rule.

*Updated October 9, 2026.*

You will see values such as `10.0.0.0/16` and `10.0.4.0/24` throughout AWS networking. The address before the slash identifies the range. The number after the slash tells you how many leading bits are fixed.

## Read the slash number

IPv4 addresses contain 32 bits. A `/24` fixes the first 24 bits and leaves 8 bits for addresses inside the range. That gives the block 256 addresses because `2^8 = 256`.

| CIDR block | Total IPv4 addresses | Common use |
| - | -: | - |
| `/16` | 65,536 | A large VPC |
| `/20` | 4,096 | A smaller VPC or large subnet |
| `/24` | 256 | An application subnet |
| `/28` | 16 | A very small subnet |

A smaller slash number means a larger address range. A `/16` contains many `/24` networks. A `/28` is much smaller than a `/24`.

<Note>
  AWS reserves five IPv4 addresses in every VPC subnet. A `/24` therefore has 251 addresses available to resources, not 256.
</Note>

## VPC blocks and subnet blocks

A VPC receives a CIDR block such as `10.20.0.0/16`. Every subnet must use a non-overlapping portion of that VPC range.

For example, you could divide the VPC across two Availability Zones:

```text theme={null}
VPC                10.20.0.0/16
Public subnet A    10.20.0.0/24
Private subnet A   10.20.10.0/24
Public subnet B    10.20.1.0/24
Private subnet B   10.20.11.0/24
```

The public and private labels are not properties of CIDR itself. Route tables decide whether a subnet has a route to an internet gateway, NAT gateway, or private endpoint.

## Why overlap causes problems

Networks use the destination address to choose a route. If two connected networks both claim `10.20.0.0/16`, a router cannot reliably know which network should receive traffic.

Overlap commonly appears when teams create VPCs independently and connect them later through peering, a transit gateway, a VPN, or another private network. Fixing it can require renumbering workloads, which is much harder than reserving ranges early.

<Warning>
  Do not copy the same default CIDR into every environment if those environments may ever communicate. Allocate distinct ranges for production, staging, development, and shared services.
</Warning>

## A practical planning method

1. Reserve a private address range for the organization.
2. Allocate a distinct block to each account, region, or environment.
3. Divide each VPC into subnets by Availability Zone and purpose.
4. Leave unused space between allocations for growth.
5. Record the assignments in one source of truth.

Do not make every subnet as small as possible. ECS tasks, load balancers, databases, VPC endpoints, and temporary deployment capacity all consume addresses. Running out of subnet addresses can stop new tasks from launching even when compute capacity is available.

## What about IPv6?

IPv6 uses 128-bit addresses and much larger ranges. AWS commonly assigns a `/56` IPv6 block to a VPC and uses `/64` blocks for subnets. The planning goal remains the same: use predictable, non-overlapping allocations and understand where routes send traffic.

## The useful mental model

Think of a CIDR block as a boundary, not as a network feature by itself. It answers one question: which IP addresses belong to this range? Route tables, security groups, network ACLs, gateways, and endpoints decide what those addresses can reach.

When Springwinter creates resources in your AWS account, those resources still consume addresses from your VPC and subnets. Understanding CIDR helps you diagnose exhausted subnets, connection failures, and future network integrations without treating the VPC as a black box.

## Frequently asked questions

<AccordionGroup>
  <Accordion title="What does /24 mean in a CIDR block?">
    A `/24` fixes 24 of the 32 bits in an IPv4 address and leaves 8 bits for host addresses. The block contains 256 total addresses. AWS reserves five addresses in each subnet, leaving 251 addresses available to resources.
  </Accordion>

  <Accordion title="How large should an AWS VPC CIDR block be?">
    Size an AWS VPC for current workloads, deployment surge, managed-service ENIs, and expected growth. Leave room for additional subnets and avoid ranges used by networks you may connect later. A `/16` is common, but the correct block depends on the address plan.
  </Accordion>

  <Accordion title="Can two AWS VPCs use the same CIDR block?">
    Two isolated VPCs can use the same CIDR block, but overlapping ranges prevent straightforward routing when you later connect them with peering, Transit Gateway, VPN, or another private network. Allocate unique ranges when future connectivity is plausible.
  </Accordion>
</AccordionGroup>

## Sources and further reading

* [AWS VPC IP addressing](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-ip-addressing.html)
* [Subnet sizing for IPv4 and IPv6](https://docs.aws.amazon.com/vpc/latest/userguide/subnet-sizing.html)
* [RFC 4632: Classless Inter-domain Routing](https://www.rfc-editor.org/rfc/rfc4632)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.