Skip to content
Glossary

CIDR

CIDR is the notation and allocation scheme that writes a block of IP addresses as an address followed by a prefix length, such as 203.0.113.0/24.

CIDR is the notation and allocation scheme that writes a block of IP addresses as an address followed by a prefix length, such as 203.0.113.0/24. The number after the slash counts the leading bits that are fixed; every bit after it varies across the addresses in the block.

#Reading a prefix

An IPv4 address is 32 bits, so a /24 fixes 24 bits and leaves 8 free. Each bit given back to the host part doubles the block. The arithmetic is the whole of it, and it is worth being able to do in your head.

Prefix Fixed bits Addresses in the block
/32 32 1
/28 28 16
/24 24 256
/16 16 65,536

An IPv6 address is 128 bits, so the same rule runs over a far larger space and the prefixes people quote are different: a single link is normally a /64.

#Why it matters when buying proxies

Filtering is frequently applied to a prefix rather than to a single address. If a block of addresses shares a /24, one decision by one target can remove all of them at once. Address count alone therefore tells you little about a pool. Spread across prefixes and across networks is the property that survives a block, and neither is visible from a price list.

How many distinct prefixes a given provider holds is not something we can state, because providers do not publish it and it changes. Sample the addresses you are actually issued and count the prefixes yourself.

#Checking which block an address sits in

whois 203.0.113.7 | grep -Ei 'route|cidr|netname|origin'

The route or CIDR line gives the registered block, and origin gives the ASN announcing it. The registry answer is the one that filtering systems tend to use.

#Commonly confused with

CIDR replaced the old fixed class boundaries, so that a prefix may be any length rather than 8, 16 or 24 bits. A subnet is a division made inside an allocation. The notation is shared; the two words describe different activities.

Frequently asked questions

What does the number after the slash actually mean?
It is the count of leading bits that are the same for every address in the block. For IPv4 the address is 32 bits, so a /24 fixes 24 bits and leaves 8 to vary, giving 256 addresses. A smaller number after the slash means a larger block.
Why do proxy sellers quote address counts instead of prefixes?
Because an address count is a bigger number and needs no explanation. A prefix count is the more useful figure, since a target that blocks a /24 removes every address inside it at once. Sample the addresses you are issued and count distinct prefixes yourself.
Is a /32 a valid CIDR block?
Yes. In IPv4 it describes exactly one address, and it is the normal way to write a single host in routing tables, firewall rules and allowlists. Proxy control panels that accept CIDR input usually accept /32 for adding one address to an IP whitelist.

Sources

  1. RFC 4632: Classless Inter-Domain Routing, the prefix notation and allocation plan
  2. RFC 4291: IPv6 addressing architecture, prefix notation over 128 bits

Related terms