taap.digitalnetwork engineering toolkit

Wildcard mask calculator

Enter a network and a mask, a prefix like /27 or an existing wildcard. You get the inverse value, the range it matches and the IOS lines that use it.

wildcard

What a wildcard mask is

A wildcard mask tells Cisco IOS which bits of an address to ignore. A 0 bit means "must match", a 1 bit means "don't care". For contiguous masks it is simply the bitwise inverse of the subnet mask:

wildcard = 255.255.255.255 − subnet mask

For a /27 (mask 255.255.255.224): 255 − 224 = 31, so the wildcard is 0.0.0.31, which matches 32 addresses.

Where wildcards are used

  • Cisco ACLs (standard and extended): permit 10.1.1.0 0.0.0.255.
  • OSPF network statements on IOS: network 10.1.1.0 0.0.0.255 area 0 enables OSPF on interfaces whose address matches.
  • EIGRP network statements with the same syntax.

Junos, NX-OS ACLs, Arista EOS, MikroTik and Linux firewalls use prefix notation (10.1.1.0/24) instead. IOS XR and NX-OS accept both forms in many places.

Worked example

Network 192.168.1.0 with mask 255.255.255.0:

  255.255.255.255
− 255.255.255.0
= 0.0.0.255

access-list 10 permit 192.168.1.0 0.0.0.255
router ospf 1
 network 192.168.1.0 0.0.0.255 area 0

Common values

PrefixSubnet maskWildcardMatches
/32255.255.255.2550.0.0.01 (use host)
/30255.255.255.2520.0.0.34
/28255.255.255.2400.0.0.1516
/26255.255.255.1920.0.0.6364
/24255.255.255.00.0.0.255256
/22255.255.252.00.0.3.2551,024
/16255.255.0.00.0.255.25565,536

Non-contiguous wildcards

Unlike subnet masks, wildcards do not need contiguous bits. 10.0.0.0 0.0.254.255 matches every 10.0.x.0/24 with an even third octet, a trick sometimes used to select even VLANs or odd/even sites with one ACE. The calculator accepts these and flags them in yellow because they cannot be expressed as a prefix. Use them sparingly: they are hard to read, and on some hardware they consume more TCAM entries.

Gotchas

  • IOS silently corrects the address to match the wildcard in some versions (permit 10.1.1.5 0.0.0.255 becomes 10.1.1.0) and not in others. Always enter the network address.
  • Entering a subnet mask where a wildcard is expected (0.0.0.255 vs 255.255.255.0) is a classic CCNA mistake: permit 10.1.1.0 255.255.255.0 matches almost anything ending in .0.
  • The tool treats a dotted input that starts with a 1-bit as a subnet mask and anything else as a wildcard.
  • Every ACL ends with an implicit deny any. After writing your permit lines with the right wildcard, verify hit counters with show access-lists before relying on the rule.
  • For OSPF, the most precise style is one statement per interface with a 0.0.0.0 wildcard (network 10.1.1.1 0.0.0.0 area 0), or ip ospf 1 area 0 directly under the interface.

Quick answers

Frequently asked questions

Is a wildcard mask always the inverse of the subnet mask?

For contiguous masks, yes. Wildcards can also be non-contiguous, which has no subnet-mask equivalent.

What does 0.0.0.0 mean as a wildcard?

Every bit must match, so it selects a single host. IOS lets you write host 10.1.1.1 instead of 10.1.1.1 0.0.0.0.

And 255.255.255.255?

No bit has to match, so it matches any address. IOS shows it as the keyword any.

Does Junos use wildcard masks?

Firewall filters and policies use prefixes. Junos does support non-contiguous matches with an explicit address/mask syntax, but you rarely need it.

Study and design tool. Validate any configuration in a lab and against vendor documentation before applying it in production.