Azure CIDR & Subnets: Why You Can Use Only 251 of 256 IPs in a /24

October 5, 2026 · Azure Networking, Packet by Packet: NSGs, Route Tables, ASGs and Azure Firewall

▶ Watch on YouTube & subscribe to The Stack Underflow

Start here. Every other video in this series assumes you can read an address like 10.20.4.0/24, size a subnet, and tell a routing problem from a DNS problem. This video, and this page, give you exactly that. We follow three packets through one Azure virtual network, and stop between packets to do the math.

The one-line version: DNS turns a name into an IP. A route decides where that IP goes. And in Azure, Azure keeps five addresses in every subnet, so you can use 251 of a /24’s 256.

Last verified against Microsoft Learn: 4 October 2026.

From a name to a next hop

An app calls orders.contoso.internal. Before any network security group can allow or deny that request, three things happen:

  1. DNS turns the name into an IP address. Once there is an IP, DNS is done.
  2. Azure checks whether that address is inside your virtual network.
  3. A route decides where the packet goes next.

If the name doesn’t resolve, don’t debug routes. Look the name up first (nslookup orders.contoso.internal). No answer, or the wrong one: a DNS problem. The right answer: check the routes, then the NSGs.

Reading an address and its prefix

10.20.4.25 lives in the subnet 10.20.4.0/24. An IPv4 address has 32 bits; the /24 says the first 24 bits name the network, and the last 8 number the hosts.

In Azure, an address belongs to an IP configuration on a network card. A NIC has one primary IP configuration and can have secondary ones, so one VM can have several addresses. A public IP is a separately allocated resource that you associate with, for example, a NIC’s IP configuration.

For private ranges, Azure recommends the RFC 1918 blocks: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. The shared range 100.64.0.0/10 (RFC 6598) can also be used, and Azure treats it as private.

CIDR: one formula, one table

Addresses in a prefix = 2(32 − prefix). Each +1 on the prefix halves the block; each −1 doubles it. Azure keeps five of them (next section), so:

CIDRTotalAzure usable
/204,0964,091
/212,0482,043
/221,0241,019
/23512507
/24256251
/25128123
/266459
/273227
/281611
/2983

A /29 is the smallest IPv4 subnet Azure allows (the largest is a /2).

Azure keeps five addresses

Azure reserves the first four addresses and the last address of every subnet. In the lab’s data subnet, 10.20.8.128/26:

AddressReserved for
10.20.8.128Network address
10.20.8.129Default gateway
10.20.8.130, 10.20.8.131Azure DNS, mapped into the subnet
10.20.8.191Broadcast address

So the first address a VM can get is .132, and usable = total − 5. Classic networking’s 2n − 2 gives 254 for a /24; Azure gives 251. The .1-style gateway is Azure’s, not a router VM you run: it doesn’t answer ping, and Azure virtual networks don’t support broadcast or multicast.

Find the range in your head

Take the block size, list its multiples, and the one just below your address is the network:

  • 10.10.4.70/26: a /26 is blocks of 64 → 0, 64, 128, 192. 64 ≤ 70 < 128, so the network is 10.10.4.64 and the last address is .127. In Azure, VMs can use .68 to .126: 59 addresses.
  • Below /24, the same walk happens in the third octet: 10.20.37.15/20 → blocks of 16 → 10.20.32.0 to 10.20.47.255.

The lab

One VNet, 10.20.0.0/16, written by hand for this video:

SubnetPrefixContents
web10.20.1.0/24web-1, 10.20.1.4
app10.20.4.0/24app-1, 10.20.4.25 · app-2, 10.20.4.26
data10.20.8.128/26db-1, 10.20.8.132 · NSG data-subnet-nsg: rule 100 Allow-SQL-From-App, TCP 1433 from 10.20.4.0/24
GatewaySubnet10.20.255.0/27empty (gateways come in the hybrid video)

No subnet has a route table, so only Azure’s system routes apply: the VNet’s own address space → Virtual network, 0.0.0.0/0 → Internet, and reserved ranges including 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 and 100.64.0.0/10 → None (dropped). When several routes contain the destination, the longest prefix wins.

Three packets, step by step

Packet 1: a neighbour in the same subnet. app-1 10.20.4.25 → app-2 10.20.4.26, TCP 8080. Three routes contain 10.20.4.26: 10.20.0.0/16 (virtual network), 0.0.0.0/0 and 10.0.0.0/8. The /16 is the most specific, so the packet is delivered inside the VNet. No NSG on the app subnet or either NIC. Allowed. Both addresses are in the same /24, but Azure still uses one route for the whole virtual network.

Packet 2: another subnet, the same route. app-1 → db-1 10.20.8.132, TCP 1433. The same system route, 10.20.0.0/16, delivers it: by default, Azure routes traffic between subnets. At the data subnet, data-subnet-nsg checks inbound rules, lowest number first: rule 100 Allow-SQL-From-App matches all five fields. Allowed by rule 100. Subnets exist so each can have its own NSG and route table, and so services that need a dedicated subnet get one.

Packet 3: a private address outside the network. app-1 → 10.30.5.10 (a server in the office), TCP 443. Two routes contain 10.30.5.10: 0.0.0.0/0 → Internet and 10.0.0.0/8 → None. The /8 is more specific, so it wins, and its next hop is None. Dropped. A private address outside your VNet goes nowhere until a gateway gives Azure a route to it: that’s the hybrid connectivity video.

#PacketRoute chosenVerdictDecided by
1app-1 → app-2, TCP 808010.20.0.0/16 → Virtual networkAllowedno NSG on the path
2app-1 → db-1, TCP 143310.20.0.0/16 → Virtual networkAlloweddata-subnet-nsg 100 Allow-SQL-From-App
3app-1 → 10.30.5.10, TCP 44310.0.0.0/8 → NoneDroppedsystem route None

DNS: the name before the packet

  • By default, a VM asks Azure-provided DNS at 168.63.129.16, a virtual public IP of the Azure platform that’s the same in every region (it also serves DHCP and Load Balancer health probes).
  • Azure Public DNS hosts your domains for the internet.
  • A private DNS zone answers inside every virtual network linked to it, which is how a private name like orders.contoso.internal resolves.
  • DNS Private Resolver lets on-premises DNS servers resolve Azure private names (inbound endpoint) and Azure resolve on-premises names (outbound endpoint + forwarding ruleset), over VPN or ExpressRoute. Each endpoint needs its own delegated subnet, between /28 and /24.

Plan before you connect

  • Size each subnet for its peak: VMs + scale-out + private endpoints + growth + Azure’s five.
  • Never reuse a range your office or partners use. Peered VNets can’t overlap at all, and overlapping ranges break routing the moment you connect a datacenter.

Pause & Prove: the questions from the video

1. How big a subnet?

One subnet must hold 124 addresses: VMs, private endpoints and scale-out instances. What is the smallest Azure subnet that fits?

  • A. /26. 64 addresses, 59 usable in Azure. Far too small.
  • B. /25. The tempting one: classic networking says 128 − 2 = 126. Azure keeps five, so a /25 gives 123, one short.
  • C. /24. ✓ 256 addresses, 251 usable: the smallest that holds 124.
  • D. /23. It fits (507 usable), but it isn’t the smallest, and it spends address space you may need later.

2. Which subnet?

A VM’s address is 10.20.8.150/26. Which subnet is it in?

  • A. 10.20.8.128/26. ✓ Blocks of 64 start at 0, 64, 128 and 192; 150 sits between 128 and 191.
  • B. 10.20.8.150/26. The tempting one: that’s the VM’s own address. A network always starts on a block boundary.
  • C. 10.20.8.64/26. That block ends at .127, below 150.
  • D. 10.20.8.192/26. That block starts at .192, above 150.

3. Which route wins?

A VM in VNet 10.20.0.0/16, with no route table and no gateway, sends a packet to 10.30.5.10. Which system route decides it?

  • A. 0.0.0.0/0 → Internet. The tempting one: it matches, but a /0 is the least specific route there is.
  • B. 10.0.0.0/8 → None. ✓ The longest matching prefix; Azure drops the packet.
  • C. 10.20.0.0/16 → Virtual network. 10.30.5.10 is outside 10.20.0.0/16, so this route doesn’t match.
  • D. The default gateway. The gateway is the VM’s first hop, not a route. Azure still needs a route for the destination.

4. Bonus (the pinned comment): the first address for a VM

In the Azure subnet 10.20.8.128/26, what is the first address you can give a VM?

  • A. .128. The network address, reserved everywhere.
  • B. .129. The tempting one: the classic first host, but Azure reserves it for the default gateway.
  • C. .130. Azure reserves .130 and .131 to map Azure DNS into the subnet.
  • D. .132. ✓ Azure reserves the first four addresses, so .132 is the first a VM can get.

5. The Community poll

How many addresses can you actually use in an Azure /24? 251. It has 256; Azure reserves five. The classic 254 only removes two.

Next in this series

Sources

Read on 4 October 2026:

Change notes

  • 5 Oct 2026: first published.

Not affiliated with or endorsed by Microsoft. Found a mistake? Tell us in the video’s comments and we’ll correct this page.

Found this useful? The deep version lives on YouTube — new breakdowns of how AI dev tools actually work, weekly.

Subscribe on YouTube →

Prefer email? Get the free newsletter: one failure, traced step by step, about once a week.