What is subnetting?
Subnetting is the practice of dividing a single IP network into several smaller, logically separate networks (subnets) by using a subnet mask or CIDR prefix to define which part of an IP address identifies the network and which part identifies the device. Devices in the same subnet talk to each other directly; traffic to another subnet has to pass through a router or firewall. In OT environments, subnetting is therefore the technical foundation of network segmentation: without separate subnets there is nothing between production cells that you can filter.
π§ How is an IPv4 address structured?
An IPv4 address consists of 32 bits, written as four octets from 0 to 255, for example 192.168.10.25. Those 32 bits split into two parts:
- Network portion β identifies the subnet; every device in the same subnet shares the same network portion
- Host portion β identifies the individual device within that subnet, such as a PLC, HMI or industrial switch
The boundary between the two is set by the subnet mask: a 32-bit value with contiguous
ones for the network portion and zeros for the host portion. 255.255.255.0 therefore means
the first 24 bits are network and the last 8 bits are host. CIDR notation (Classless
Inter-Domain Routing) expresses the same thing more compactly as a prefix length: 192.168.10.0/24.
Subnetting was standardised in 1985 in RFC 950. CIDR followed in 1993 (RFC 1519, later replaced by RFC 4632), abandoning the old fixed class A, B and C boundaries and allowing prefixes of any length.
π§ Which subnet masks are used most often?
The number of addresses in a subnet is 2 to the power of the number of host bits. Two addresses are always reserved: the network address (all host bits 0) and the broadcast address (all host bits 1). What remains are the usable host addresses.
| Prefix | Subnet mask | Addresses | Usable hosts | Typical OT use |
|---|---|---|---|---|
| /24 | 255.255.255.0 | 256 | 254 | Large cell, SCADA or server zone |
| /25 | 255.255.255.128 | 128 | 126 | Production line |
| /26 | 255.255.255.192 | 64 | 62 | Production cell or Purdue level |
| /27 | 255.255.255.224 | 32 | 30 | Machine with several controllers |
| /28 | 255.255.255.240 | 16 | 14 | Small machine, management segment |
| /29 | 255.255.255.248 | 8 | 6 | Skid or package unit |
| /30 | 255.255.255.252 | 4 | 2 | Point-to-point link between routers |
A /31 (RFC 3021) is intended only for point-to-point links and has no network or broadcast address. A /32 denotes a single address, for instance in a firewall rule.
π Which private address ranges should you use in an OT network?
Internal networks use the private ranges defined in RFC 1918 (February 1996). These addresses are not routed on the internet and any organisation may use them freely.
| Range | CIDR | Number of addresses | In practice |
|---|---|---|---|
| 10.0.0.0 β 10.255.255.255 | 10.0.0.0/8 | over 16.7 million | Large sites, multi-site address plans |
| 172.16.0.0 β 172.31.255.255 | 172.16.0.0/12 | over 1 million | Often chosen to avoid clashes with IT |
| 192.168.0.0 β 192.168.255.255 | 192.168.0.0/16 | 65,536 | Machine builders, small installations |
Precisely because everyone uses the same ranges, they clash easily: many machine builders ship their
equipment preconfigured in 192.168.0.0/24 or 192.168.1.0/24.
π How do you split a /24 into four subnets? A worked example
Suppose you have been allocated 192.168.10.0/24 for a small plant and want four separate
subnets for the levels of the Purdue Model. This is how you work it out step by step:
- Decide how many subnets you need β four subnets require 2 extra network bits, because 2Β² = 4.
-
Calculate the new prefix β /24 + 2 = /26, subnet mask
255.255.255.192. - Determine the block size β 32 β 26 = 6 host bits, so 2βΆ = 64 addresses per subnet.
- Count in steps of 64 β the subnets start at .0, .64, .128 and .192.
- Assign the network, gateway and broadcast address for each subnet.
| Subnet | Purdue level / zone | Network address | Gateway | Host range | Broadcast |
|---|---|---|---|---|---|
| 192.168.10.0/26 | Level 1 β controllers | .0 | .1 | .1 β .62 | .63 |
| 192.168.10.64/26 | Level 2 β SCADA and HMI | .64 | .65 | .65 β .126 | .127 |
| 192.168.10.128/26 | Level 3 β historian and servers | .128 | .129 | .129 β .190 | .191 |
| 192.168.10.192/26 | Management and engineering | .192 | .193 | .193 β .254 | .255 |
Each subnet has 62 usable addresses, one of which goes to the default gateway: the router or firewall interface through which traffic leaves the subnet. A common convention is to place the gateway consistently on the first (or the last) usable address of every subnet, so engineers can find it without consulting the documentation.
π How do subnets and VLANs relate?
A subnet is a logical division at layer 3 (IP); a VLAN is a separation at layer 2 (Ethernet). Standard practice is one VLAN per
subnet: VLAN 110 carries 192.168.10.0/26, for example, and VLAN 120 carries 192.168.10.64/26. Two subnets sharing one VLAN still share their broadcasts and therefore offer
little real separation. Conversely, a VLAN without its own subnet has no routing boundary at which a
firewall can enforce rules.
π How do you design subnets for an OT network?
- One subnet per zone or cell β this maps onto the zones of the zones and conduits model in IEC 62443; the conduit between two zones then runs through the router or firewall that connects their subnets.
- Firewall rules between subnets β allow only the traffic that is genuinely needed, such as OPC UA from level 3 to level 2, and block everything else.
-
Avoid flat /16 networks β a single
172.16.0.0/16with 65,534 hosts is one broadcast domain and one zone; ransomware or a broadcast storm then reaches the entire plant. - Static addresses and an IP plan β controllers get fixed addresses; DHCP in OT is suitable at most for laptops and clients. Record every subnet, VLAN ID, gateway and address, ideally linked to your asset inventory.
- Reserve room for growth β size each subnet for expected expansion, not for todayβs device count.
-
Resolve overlapping subnets with NAT β ten identical machines that each use
192.168.0.0/24cannot simply be routed. A 1:1 NAT router or firewall per machine translates the internal machine network to a unique external subnet, so the machine builder does not have to change the internal addressing.
π§ͺ What commonly goes wrong with subnetting?
- Wrong subnet mask on a PLC β if the mask is /16 instead of /24, the PLC assumes addresses in other subnets are local and never sends that traffic to the gateway.
- Duplicate IP address β two devices with the same address cause intermittent communication faults that are hard to trace.
- Missing or incorrect gateway β the device works fine locally but cannot be reached from SCADA or the historian.
- Overlap with the IT network β if OT picks the same range as the office network or VPN, routing conflicts appear as soon as the two are connected.
Useful tools include a subnet calculator (such as ipcalc), Wireshark to inspect ARP and
broadcast traffic, IPAM software to maintain the IP plan and passive asset discovery to find duplicate or unknown addresses.
π How does subnetting work in IPv6?
IPv6 uses 128-bit addresses with the same prefix notation. A LAN subnet there is almost always a /64: under RFC 4291 the last 64 bits form the interface identifier. A site with a /48 prefix can therefore create 65,536 subnets of /64 each. IPv6 remains uncommon in OT; most controllers and industrial Ethernet protocols are still deployed on IPv4.
β Frequently asked questions
What is the difference between a subnet mask and a CIDR prefix?
A subnet mask and a CIDR prefix express exactly the same thing: how many bits of an IP address make up the
network portion. The subnet mask 255.255.255.0 is equivalent to prefix /24. CIDR notation is
shorter and is what routers, firewalls and documentation use most.
How many hosts fit in a /24 subnet?
A /24 subnet contains 256 addresses, of which 254 are usable for hosts. The first address is the network address and the last is the broadcast address. One of the 254 host addresses usually goes to the gateway.
Why is subnetting important for OT security?
Subnetting makes it possible to divide an OT network into zones with a router or firewall between them. Only at that boundary can you filter, log and restrict traffic. Without subnetting the network is flat and an infection can spread unhindered.
Should every VLAN have its own subnet?
Yes, in practice you map each VLAN to exactly one subnet. That way the layer 2 separation of the VLAN coincides with the layer 3 boundary where a firewall enforces its rules. Several subnets in one VLAN give a false sense of security, because broadcasts and ARP traffic remain shared.
How do I deal with overlapping IP addresses from machine builders?
Overlapping IP addresses from machine builders are usually resolved with 1:1 NAT on a router or firewall per machine. The internal machine network stays unchanged, while each machine presents a unique subnet to the outside. An alternative is to specify an address range per machine in your purchasing requirements.
Which subnet size should I choose for a production cell?
For a production cell a /26 (62 hosts) or /27 (30 hosts) is usually sufficient. Size the subnet for the expected number of devices including future expansion, and keep a block free per area in your IP plan. A subnet that is too large makes the broadcast domain needlessly big, while one that is too small forces renumbering later.
π In summary
Subnetting divides an IP network into smaller subnets using a subnet mask or CIDR prefix, and forms the foundation for zones, VLANs and firewall rules in an OT network. A well-considered IP plan with one subnet per zone, static addresses and NAT for overlapping machine networks prevents faults and makes segmentation in line with IEC 62443 possible.
