The /28 subnet

A /28 subnet uses the mask 255.255.255.240 and holds 16 addresses, 14 of them usable.

Reference data last reviewed:

/28
Prefix length
255.255.255.240
Subnet mask
0.0.0.15
Wildcard mask
14
Usable hosts

The /28 mask is 28 network bits followed by 4 host bits, for a total of 32 bits.

28 network bits (the 1s)4 host bits (the 0s)

A /28 splits a /24 into smaller pieces: 16 addresses and 14 usable hosts, with the mask 255.255.255.240. It is a tidy size for a small VLAN, a DMZ, or a rack of servers.

Right-sizing a subnet to a /28 avoids wasting a full /24 on a handful of hosts. The wildcard mask 0.0.0.15 is the form you use in access lists and firewall rules to match this range.

Below you can see the exact network, broadcast, and host range for any /28 you enter, calculated instantly in your browser.

Calculate a /28 network

Accepts CIDR (192.0.2.0/24), IP + mask (192.0.2.0 255.255.255.0), or a bare IP (defaults to /24).

Network address192.0.2.0
Usable host range192.0.2.1 - 192.0.2.14
Broadcast address192.0.2.15
Usable hosts14
Subnet mask255.255.255.240
Wildcard mask0.0.0.15
CIDR notation192.0.2.0/28
Total addresses16
IP (binary)11000000.00000000.00000010.00000000
Mask (binary)11111111.11111111.11111111.11110000
Try:

Example: 192.0.2.0/28

Taking 192.0.2.0/28 as a worked example, the block breaks down like this:

Network address192.0.2.0
Usable range192.0.2.1 - 192.0.2.14
Broadcast address192.0.2.15
Total addresses16
Usable hosts14
Size1/16 of a class C block

A note on the example: 192.0.2.0 is in 192.0.2.0/24, documentation (test-net-1) space under RFC 5737. Reserved for examples and documentation. Safe to print, never routed. Every example on this site uses reserved space on purpose, so nothing here points at somebody's real network.

Splitting a /28 into smaller subnets

Borrowing bits from the host part doubles the number of subnets and halves the size of each one. This is what a /28 looks like at the next 4 prefix lengths.

How a /28 block divides into longer prefixes
Split intoSubnetsMaskUsable hosts each
/292255.255.255.2486
/304255.255.255.2522
/318255.255.255.2542
/3216255.255.255.2551

Each subnet has to start on a multiple of its own size, which is what keeps the blocks from overlapping. Working the other way, from a host count back to a prefix, is what subnet by host count is for.

Do this from the terminal

The same numbers are available as keyless JSON, and there are good local tools that need no network at all. Naming them costs nothing and is more useful than pretending this page is the only option.

curl -s https://subnetkit.dev/api/cidr/28.json | jq

# or locally, with no network at all:
ipcalc 192.0.2.0/28
sipcalc 192.0.2.0/28

ipcalc ships in most Linux distributions and sipcalc handles IPv4 and IPv6. The SubnetKit API is the one to reach for in a build step or a script that wants the same values this page shows.

Frequently asked questions

What is the subnet mask for a /28?

A /28 uses the subnet mask 255.255.255.240. Its wildcard mask, used in access lists, is 0.0.0.15.

How many hosts are in a /28 subnet?

A /28 has 16 total addresses and 14 usable hosts (the total minus the network and broadcast addresses, except for /31 and /32).

What is a /28 used for?

Small subnet. It is equivalent to 1/16 of a class C block.

How do I calculate a /28 network?

Set the host bits to zero for the network address and to one for the broadcast address. The calculator on this page does it for any /28 block you enter.

How many /29 subnets fit in a /28?

2, each with 6 usable hosts and the mask 255.255.255.248. Every extra bit you borrow doubles the number of subnets and halves the size of each one.

Opening a port on a /28

A firewall rule needs two halves: the range and the port. The wildcard mask 0.0.0.15 matches this whole block in an access list. For the other half, the port number reference lists what each TCP and UDP port carries and whether it is encrypted by default, so you can tell what you are about to expose to 14 addresses.

Sources

The arithmetic on this page follows the documents below. Every number is computed from the prefix length rather than stored, and the calculation is covered by tests over all 33 prefixes.

Spotted something wrong? Tell us and it gets corrected. How the data is maintained is described on the about page.