IP Subnetting, Troubleshooting IP, and NAT
Chapter 8 — IP Subnetting, Troubleshooting & NAT
Find the interesting octet, calculate the block, prove the path, then translate the address. This study map turns subnet math, VLSM design, IPv4 diagnostics, and NAT/PAT into repeatable exam workflows.
Introduction to Subnetting, Troubleshooting & NAT
Every IPv4 packet begins with a basic decision: is the destination on the local network, or must the packet be sent to another network? Answering that question requires an understanding of the IP address, subnet mask, network boundary, and default gateway. These same concepts form the foundation of IPv4 subnetting, connectivity troubleshooting, and Network Address Translation (NAT).
An IPv4 address is a 32-bit logical address written as four 8-bit octets. The address alone does not show where the network ends and the individual host begins. A subnet mask, commonly expressed as a CIDR prefix such as /24 or /26, separates the address into a network portion and a host portion. The network portion identifies the subnet, while the host portion identifies a particular interface within it.
When a host prepares to send traffic, it compares the destination network with its own. If both addresses belong to the same subnet, the host delivers the frame directly across the local network. If they belong to different subnets, the host forwards the packet to its default gateway, which routes it toward the destination. An incorrect IP address, mask, gateway, VLAN assignment, or route can therefore prevent communication even when the physical connection is working.
Subnetting is the process of dividing a larger IPv4 network into smaller logical networks. Each subnet forms a separate broadcast domain and can represent a department, floor, building, VLAN, routed link, or security zone. Well-planned subnets reduce unnecessary broadcast traffic, organize address allocation, improve fault isolation, and allow security policies to be applied between network segments.
Subnetting knowledge also makes troubleshooting more systematic. By determining the expected network address, broadcast address, valid host range, and gateway, an administrator can identify whether a fault is local to the host, within the local subnet, at the router, or farther along the path. At the Internet edge, NAT and Port Address Translation (PAT) extend this addressing process by translating private IPv4 addresses into publicly routable addresses.
This chapter follows the journey of a packet from its source host to a remote network. It begins with subnet masks and CIDR notation, develops a repeatable method for subnet calculations and VLSM design, applies that knowledge to IP troubleshooting, and concludes with the operation and terminology of NAT and PAT.
How the chapter fits together
- Interpret an IPv4 address, subnet mask, and CIDR prefix.
- Identify the network, broadcast, and valid host addresses.
- Calculate subnet capacity and design address space with VLSM.
- Determine whether traffic is local or must use a default gateway.
- Troubleshoot connectivity from the host toward the remote destination.
- Explain how NAT and PAT translate private traffic at the network edge.
Smaller broadcasts
Fewer hosts process each broadcast, and local traffic remains within a more manageable broadcast domain.
Organized addressing
Predictable address ranges can represent VLANs, departments, buildings, and network functions.
Fault isolation
Smaller network segments make it easier to locate failures and enforce routing or security boundaries.
Efficient allocation
CIDR and VLSM match subnet sizes to actual host requirements while limiting wasted IPv4 space.
Subnet Terms & Formulas
Subnetting becomes easier when every result is tied to the network and host bits rather than memorized as an isolated formula.
A mask contains consecutive binary 1s followed by consecutive binary 0s. The 1s identify the network portion; the 0s identify the host portion. For example, /26 means 26 network bits and 6 host bits. Its last octet is 11000000, which equals 192, producing 255.255.255.192.
1281
640
320
160
80
40
20
1
The network address has all host bits set to 0; the broadcast address has all host bits set to 1. Ordinary hosts fall between them. A device can derive its network address by applying a bitwise logical AND between the IPv4 address and mask.
2ˢ
s is the number of borrowed subnet bits. Modern subnetting includes subnet zero and the all-ones subnet.
2ʰ
h is the number of remaining host bits.
2ʰ − 2
Traditional LAN calculations subtract the network and broadcast addresses.
256 − mask
Subtract the interesting mask octet from 256 to find subnet increments.
CIDR & Mask Explorer
Classless Inter-Domain Routing (CIDR) writes the number of network bits after a slash. Select a prefix to see its mask, address capacity, traditional usable hosts, and block size.
A longer prefix creates a smaller subnet because more bits identify the network and fewer remain for hosts. Moving from /24 to /25 creates two 128-address blocks; moving to /26 creates four 64-address blocks.
The interesting octet is the first mask octet that is neither 255 nor 0. Subtract it from 256 to obtain the block size. Boundaries occur at multiples of that block size in the same octet.
Interactive Subnet Calculator
Enter an IPv4 address and prefix from /8 through /30. Use the result to check manual work—not to replace the reasoning process.
The calculator identifies the block containing the entered address. The lower boundary is the network address; the address immediately before the next boundary is the broadcast; addresses between them form the traditional valid-host range.
The Six-Step Method
A consistent method reduces mistakes under exam pressure. Work from the prefix to the mask, locate the interesting octet, calculate the increment, and identify the boundaries surrounding the given address.
For 192.168.10.77/26, the mask is 255.255.255.192 and the block size is 64. Boundaries are 0, 64, 128, and 192. Since 77 lies in 64–127, the network is .64, broadcast is .127, and usable hosts are .65–.126.
Worked Examples
The examples below apply the same reasoning across different interesting octets. Open each example and verify the mask, block size, containing boundary, next boundary, broadcast, and valid-host range in order.
When the prefix is shorter than /24, the interesting octet may be the second or third octet, and every octet to its right belongs to the host portion. Do not automatically calculate only in the fourth octet.
Host Requirement Shortcut
Network design often starts with a required number of hosts rather than a given prefix. Choose enough host bits for the endpoints plus the network and broadcast addresses.
For 50 hosts, 5 host bits provide only 30 usable addresses. Six host bits provide 64 total and 62 usable, so the prefix is 32 − 6 = /26. Choose the smallest subnet that satisfies the requirement while allowing planned growth.
| Needed hosts | Host bits | Prefix | Usable |
|---|---|---|---|
| 2 | 2 | /30 | 2 |
| 6 | 3 | /29 | 6 |
| 14 | 4 | /28 | 14 |
| 30 | 5 | /27 | 30 |
| 62 | 6 | /26 | 62 |
| 126 | 7 | /25 | 126 |
| 254 | 8 | /24 | 254 |
VLSM Planner
Variable Length Subnet Masking (VLSM) uses different prefixes inside the same address plan so that each segment receives a subnet close to its actual capacity requirement.
Fixed-length subnetting can waste addresses when departments have different sizes. VLSM can assign a /25 to a large LAN and a /28 to a smaller one, provided the routing environment supports classless prefixes.
Allocate the largest requirement first, use aligned contiguous boundaries, and record every network, host range, and broadcast before assigning the next block. Largest-first allocation prevents small networks from fragmenting space required by larger blocks.
| Need | Prefix | Network | Valid hosts | Broadcast |
|---|
Common Subnetting Traps
Most subnetting errors come from confusing address roles, using the wrong octet, or reverting to historical classful assumptions after a CIDR prefix has already been supplied.
Validate every answer by checking that the given host falls inside the calculated range, adjacent subnets do not overlap, and each boundary aligns with the block size. The traditional 2ʰ − 2 rule describes broadcast LANs; /31 point-to-point links and /32 host routes are special cases.
Four Diagnostic Pings
IP troubleshooting should move from the local host outward: stack → interface → local network → remote network.
First inspect the physical link and host configuration: IPv4 address, prefix or mask, default gateway, DNS servers, DHCP status, and VLAN placement. A wrong mask can make a remote address appear local; a wrong gateway prevents off-subnet delivery; DHCP failure may produce an Automatic Private IP Addressing (APIPA) address in 169.254.0.0/16.
Ping 127.0.0.1 to test the TCP/IP stack, the host address to test its interface, the default gateway to test local reachability, and a remote IP to test routing. Then test a hostname to isolate DNS. Each success narrows the fault domain, although ICMP filtering means failure needs supporting evidence.
Symptom-to-Cause Explorer
A symptom is evidence, not a diagnosis. Compare what works with what fails, identify the last proven point, and investigate the components immediately beyond it.
Useful checks include the ARP or neighbor table, routing table, DHCP lease, DNS resolution, switch-port and VLAN configuration, access control lists (ACLs), firewall policy, and the destination return route.
NAT & PAT
Private IPv4 ranges are not routed across the public Internet: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. At the boundary, Network Address Translation (NAT) rewrites addressing so private hosts can communicate through publicly routable addresses.
The router or firewall creates a stateful translation entry as traffic crosses between inside and outside networks. Return traffic matches that entry and is rewritten toward the original host. NAT conserves public IPv4 space and separates internal addressing from the provider, but it changes end-to-end addressing and can complicate protocols that embed address data.
Static NAT
One private address maps to one public address; useful for publishing a server.
Dynamic NAT
Private clients receive temporary one-to-one translations from a public pool.
PAT
Many private sessions share one or a few public IPs and are distinguished by ports.
NAT Address Names & PAT Flow
NAT terminology describes both a host location and the context in which its address is observed. Inside and outside identify location; local and global describe representation.
With Port Address Translation (PAT), also called NAT overload, many sessions share one public address because the device tracks Layer 4 ports. Below, 192.168.1.10:51500 becomes 203.0.113.5:40001. The reply reaches the translated socket, and the PAT table restores the original private address and port.
| Name | Meaning | Example |
|---|---|---|
| Inside local | Inside host before translation | 192.168.1.10 |
| Inside global | Public address representing inside host | 203.0.113.20 |
| Outside global | Outside host on public network | 198.51.100.40 |
| Outside local | Outside host as represented internally | Often same as outside global |
PowerShell 7 Practice
Commands should answer specific questions. Begin with configuration, then verify local state, reachability, routing, neighbor resolution, and DNS separately.
Record the output before changing settings. Confirm that the address and prefix match the intended subnet, the default route points to an on-link gateway, and the neighbor table resolves the gateway MAC address. This evidence-based sequence avoids changing several variables at once.
Get-NetIPConfigurationAddress, gateway, DNS, interfaceGet-NetIPAddress -AddressFamily IPv4IPv4 addresses and prefixesGet-NetRoute -AddressFamily IPv4Connected and default routesGet-NetNeighbor -AddressFamily IPv4ARP stateTest-Connection 127.0.0.1 -Count 2Local stackTest-NetConnection 1.1.1.1Remote IP reachabilityResolve-DnsName example.comDNS separatelyroute print -4IPv4 routing tableExam Check
Use these fifteen questions to check whether you can apply the chapter rather than merely recognize its terms. Calculate subnet answers before selecting an option and explain which part of the path each troubleshooting result proves.
Final review
- A prefix identifies network bits; the remaining bits identify hosts.
- Network and broadcast addresses define a traditional subnet’s endpoints.
- VLSM allocates the largest requirements first using different prefix lengths.
- Troubleshooting moves from local configuration toward gateway, remote IP, and DNS.
- Static NAT, dynamic NAT, and PAT differ in how translations are allocated and shared.