Azure CIDR & Subnets: Why You Can Use Only 251 of 256 IPs in a /24
▶ Watch on YouTube & subscribe to The Stack Underflow
Start here. Every other video in this series assumes you can read an address like 10.20.4.0/24, size a subnet, and tell a routing problem from a DNS problem. This video, and this page, give you exactly that. We follow three packets through one Azure virtual network, and stop between packets to do the math.
The one-line version: DNS turns a name into an IP. A route decides where that IP goes. And in Azure, Azure keeps five addresses in every subnet, so you can use 251 of a
/24’s 256.
Last verified against Microsoft Learn: 4 October 2026.
From a name to a next hop
An app calls orders.contoso.internal. Before any network security group can allow or deny that request, three things happen:
- DNS turns the name into an IP address. Once there is an IP, DNS is done.
- Azure checks whether that address is inside your virtual network.
- A route decides where the packet goes next.
If the name doesn’t resolve, don’t debug routes. Look the name up first (nslookup orders.contoso.internal). No answer, or the wrong one: a DNS problem. The right answer: check the routes, then the NSGs.
Reading an address and its prefix
10.20.4.25 lives in the subnet 10.20.4.0/24. An IPv4 address has 32 bits; the /24 says the first 24 bits name the network, and the last 8 number the hosts.
In Azure, an address belongs to an IP configuration on a network card. A NIC has one primary IP configuration and can have secondary ones, so one VM can have several addresses. A public IP is a separately allocated resource that you associate with, for example, a NIC’s IP configuration.
For private ranges, Azure recommends the RFC 1918 blocks: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. The shared range 100.64.0.0/10 (RFC 6598) can also be used, and Azure treats it as private.
CIDR: one formula, one table
Addresses in a prefix = 2(32 − prefix). Each +1 on the prefix halves the block; each −1 doubles it. Azure keeps five of them (next section), so:
| CIDR | Total | Azure usable |
|---|---|---|
| /20 | 4,096 | 4,091 |
| /21 | 2,048 | 2,043 |
| /22 | 1,024 | 1,019 |
| /23 | 512 | 507 |
| /24 | 256 | 251 |
| /25 | 128 | 123 |
| /26 | 64 | 59 |
| /27 | 32 | 27 |
| /28 | 16 | 11 |
| /29 | 8 | 3 |
A /29 is the smallest IPv4 subnet Azure allows (the largest is a /2).
Azure keeps five addresses
Azure reserves the first four addresses and the last address of every subnet. In the lab’s data subnet, 10.20.8.128/26:
| Address | Reserved for |
|---|---|
| 10.20.8.128 | Network address |
| 10.20.8.129 | Default gateway |
| 10.20.8.130, 10.20.8.131 | Azure DNS, mapped into the subnet |
| 10.20.8.191 | Broadcast address |
So the first address a VM can get is .132, and usable = total − 5. Classic networking’s 2n − 2 gives 254 for a /24; Azure gives 251. The .1-style gateway is Azure’s, not a router VM you run: it doesn’t answer ping, and Azure virtual networks don’t support broadcast or multicast.
Find the range in your head
Take the block size, list its multiples, and the one just below your address is the network:
10.10.4.70/26: a/26is blocks of 64 → 0, 64, 128, 192. 64 ≤ 70 < 128, so the network is10.10.4.64and the last address is.127. In Azure, VMs can use.68to.126: 59 addresses.- Below
/24, the same walk happens in the third octet:10.20.37.15/20→ blocks of 16 →10.20.32.0to10.20.47.255.
The lab
One VNet, 10.20.0.0/16, written by hand for this video:
| Subnet | Prefix | Contents |
|---|---|---|
| web | 10.20.1.0/24 | web-1, 10.20.1.4 |
| app | 10.20.4.0/24 | app-1, 10.20.4.25 · app-2, 10.20.4.26 |
| data | 10.20.8.128/26 | db-1, 10.20.8.132 · NSG data-subnet-nsg: rule 100 Allow-SQL-From-App, TCP 1433 from 10.20.4.0/24 |
| GatewaySubnet | 10.20.255.0/27 | empty (gateways come in the hybrid video) |
No subnet has a route table, so only Azure’s system routes apply: the VNet’s own address space → Virtual network, 0.0.0.0/0 → Internet, and reserved ranges including 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 and 100.64.0.0/10 → None (dropped). When several routes contain the destination, the longest prefix wins.
Three packets, step by step
Packet 1: a neighbour in the same subnet. app-1 10.20.4.25 → app-2 10.20.4.26, TCP 8080.
Three routes contain 10.20.4.26: 10.20.0.0/16 (virtual network), 0.0.0.0/0 and 10.0.0.0/8. The /16 is the most specific, so the packet is delivered inside the VNet. No NSG on the app subnet or either NIC. Allowed. Both addresses are in the same /24, but Azure still uses one route for the whole virtual network.
Packet 2: another subnet, the same route. app-1 → db-1 10.20.8.132, TCP 1433.
The same system route, 10.20.0.0/16, delivers it: by default, Azure routes traffic between subnets. At the data subnet, data-subnet-nsg checks inbound rules, lowest number first: rule 100 Allow-SQL-From-App matches all five fields. Allowed by rule 100. Subnets exist so each can have its own NSG and route table, and so services that need a dedicated subnet get one.
Packet 3: a private address outside the network. app-1 → 10.30.5.10 (a server in the office), TCP 443.
Two routes contain 10.30.5.10: 0.0.0.0/0 → Internet and 10.0.0.0/8 → None. The /8 is more specific, so it wins, and its next hop is None. Dropped. A private address outside your VNet goes nowhere until a gateway gives Azure a route to it: that’s the hybrid connectivity video.
| # | Packet | Route chosen | Verdict | Decided by |
|---|---|---|---|---|
| 1 | app-1 → app-2, TCP 8080 | 10.20.0.0/16 → Virtual network | Allowed | no NSG on the path |
| 2 | app-1 → db-1, TCP 1433 | 10.20.0.0/16 → Virtual network | Allowed | data-subnet-nsg 100 Allow-SQL-From-App |
| 3 | app-1 → 10.30.5.10, TCP 443 | 10.0.0.0/8 → None | Dropped | system route None |
DNS: the name before the packet
- By default, a VM asks Azure-provided DNS at
168.63.129.16, a virtual public IP of the Azure platform that’s the same in every region (it also serves DHCP and Load Balancer health probes). - Azure Public DNS hosts your domains for the internet.
- A private DNS zone answers inside every virtual network linked to it, which is how a private name like
orders.contoso.internalresolves. - DNS Private Resolver lets on-premises DNS servers resolve Azure private names (inbound endpoint) and Azure resolve on-premises names (outbound endpoint + forwarding ruleset), over VPN or ExpressRoute. Each endpoint needs its own delegated subnet, between
/28and/24.
Plan before you connect
- Size each subnet for its peak: VMs + scale-out + private endpoints + growth + Azure’s five.
- Never reuse a range your office or partners use. Peered VNets can’t overlap at all, and overlapping ranges break routing the moment you connect a datacenter.
Pause & Prove: the questions from the video
1. How big a subnet?
One subnet must hold 124 addresses: VMs, private endpoints and scale-out instances. What is the smallest Azure subnet that fits?
- A. /26. 64 addresses, 59 usable in Azure. Far too small.
- B. /25. The tempting one: classic networking says 128 − 2 = 126. Azure keeps five, so a
/25gives 123, one short. - C. /24. ✓ 256 addresses, 251 usable: the smallest that holds 124.
- D. /23. It fits (507 usable), but it isn’t the smallest, and it spends address space you may need later.
2. Which subnet?
A VM’s address is 10.20.8.150/26. Which subnet is it in?
- A. 10.20.8.128/26. ✓ Blocks of 64 start at 0, 64, 128 and 192; 150 sits between 128 and 191.
- B. 10.20.8.150/26. The tempting one: that’s the VM’s own address. A network always starts on a block boundary.
- C. 10.20.8.64/26. That block ends at
.127, below 150. - D. 10.20.8.192/26. That block starts at
.192, above 150.
3. Which route wins?
A VM in VNet 10.20.0.0/16, with no route table and no gateway, sends a packet to 10.30.5.10. Which system route decides it?
- A. 0.0.0.0/0 → Internet. The tempting one: it matches, but a
/0is the least specific route there is. - B. 10.0.0.0/8 → None. ✓ The longest matching prefix; Azure drops the packet.
- C. 10.20.0.0/16 → Virtual network. 10.30.5.10 is outside
10.20.0.0/16, so this route doesn’t match. - D. The default gateway. The gateway is the VM’s first hop, not a route. Azure still needs a route for the destination.
4. Bonus (the pinned comment): the first address for a VM
In the Azure subnet 10.20.8.128/26, what is the first address you can give a VM?
- A. .128. The network address, reserved everywhere.
- B. .129. The tempting one: the classic first host, but Azure reserves it for the default gateway.
- C. .130. Azure reserves
.130and.131to map Azure DNS into the subnet. - D. .132. ✓ Azure reserves the first four addresses, so
.132is the first a VM can get.
5. The Community poll
How many addresses can you actually use in an Azure /24? 251. It has 256; Azure reserves five. The classic 254 only removes two.
Next in this series
- Next: How Azure NSGs Allow or Deny a Packet (priorities, first match, default rules)
- Then: Azure Subnet NSG vs NIC NSG, Azure Route Tables and NVAs, and How Azure Firewall Decides
- Where this packet finally leaves Azure: Why Your Azure VM Can’t Reach On-Premises: VPN vs ExpressRoute (words first: the hybrid networking primer)
Sources
Read on 4 October 2026:
- Azure Virtual Network FAQ: five reserved addresses per subnet, smallest
/29and largest/2, RFC 1918 recommended and RFC 6598 allowed, no overlapping peered VNets,.1gateway doesn’t answer ping, no broadcast or multicast - Azure virtual network traffic routing: system routes and None ranges, longest prefix match, user > BGP > system, routing between subnets by default
- Configure IP addresses for an Azure network interface: primary and secondary IP configurations; public IPs associated with an IP configuration
- What is IP address 168.63.129.16?: Azure-provided DNS, platform virtual IP, same in every region
- What is Azure Public DNS?: a hosting service for DNS domains
- What is Azure Private DNS?: resolving a private zone requires a virtual network link
- What is Azure DNS Private Resolver?: inbound and outbound endpoints, forwarding rulesets,
/28–/24delegated subnets - RFC 1918 (private address ranges) and RFC 4632 (CIDR)
Change notes
- 5 Oct 2026: first published.
Not affiliated with or endorsed by Microsoft. Found a mistake? Tell us in the video’s comments and we’ll correct this page.
Found this useful? The deep version lives on YouTube — new breakdowns of how AI dev tools actually work, weekly.
Subscribe on YouTube →Prefer email? Get the free newsletter: one failure, traced step by step, about once a week.