Subnetting

Dividing an IP address block into smaller networks by lengthening the network prefix, so that each subnet has its own address range and a routed boundary to the others.

Subnetting splits one IP address block into several smaller networks by taking bits from the host part of the address and adding them to the network prefix. The prefix length, written as a subnet mask such as 255.255.255.0 or in CIDR notation as /24, tells a host which addresses are on its own subnet and which must be reached through a router. In IPv4, a /24 leaves 8 host bits: 256 addresses, of which 254 can be given to hosts, since the first identifies the network and the last is the broadcast address. RFC 950 (1985) standardised the procedure, and IPv6 uses the same prefix idea.

For security, subnetting matters because it creates boundaries. Traffic between subnets is designed to pass a layer-3 device, which is a place where filtering rules can be applied, and where each subnet is its own broadcast domain, smaller subnets limit how far broadcast traffic spreads. A subnet is not a control by itself: two subnets joined by a router with no filtering can reach each other freely. Subnetting is therefore one building block of network segmentation, often paired with a VLAN at layer 2.

Exam relevance: a scenario is likely to use subnets to describe how a network is divided. Candidates are expected to read a prefix length and to understand that separation needs a filter at the boundary, rather than to perform long calculations.