Guide

IPv4 wildcard masks explained

Calculate the inverse of an IPv4 subnet mask, interpret its bits, and avoid treating a wildcard as an IP address.

by Tools in a Tab · Published on · Updated

Short answer

For a CIDR subnet, its wildcard mask is the bitwise complement of its subnet mask. Wherever the subnet mask has 1, the wildcard has 0, and vice versa. This is the contiguous-block case calculated here, not every possible ACL wildcard.

subnet mask: 255.255.255.224
wildcard:      0.  0.  0. 31

Octet calculation

For a contiguous subnet mask, subtract every octet from 255:

255 - 255 = 0
255 - 224 = 31
CIDR Subnet mask Wildcard
/16 255.255.0.0 0.0.255.255
/24 255.255.255.0 0.0.0.255
/27 255.255.255.224 0.0.0.31
/32 255.255.255.255 0.0.0.0

The IPv4 subnet calculator displays the subnet mask and wildcard from either a prefix or dotted-decimal mask.

Interpreting the bits

In common matching rules, a 0 wildcard bit requires the corresponding bit to match, while 1 allows it to vary. 192.168.1.32 0.0.0.31 fixes the first 27 bits and lets the last five vary, covering 192.168.1.32–63.

Exact syntax and semantics depend on the network device or configuration language. Do not copy an ACL rule between vendors without checking their documentation.

Some ACLs also allow noncontiguous wildcard bits. Those patterns can match addresses that do not form one CIDR block, so they cannot always be converted to a single subnet mask. The calculator accepts contiguous subnet masks and returns their complements; it does not parse arbitrary ACL wildcards.

Common mistakes

  • Entering the wildcard where a subnet mask is expected.
  • Treating 0.0.0.31 as a host address.
  • Subtracting /27 from 32 and writing that number as the wildcard.
  • Applying ACL semantics to a field that expects a normal subnet mask.

A wildcard describes variable bits. It is neither a universally interchangeable mask nor an assignable address.

Primary sources

RFC 1878 provides IPv4 mask and block-size tables against which the complement used for a wildcard can be checked.

Cisco’s IPv4 access-list documentation explains wildcard matching and explicitly allows noncontiguous wildcard bits.