What a wildcard mask is
A wildcard mask tells Cisco IOS which bits of an address to ignore. A 0 bit means "must match", a 1 bit means "don't care". For contiguous masks it is simply the bitwise inverse of the subnet mask:
For a /27 (mask 255.255.255.224): 255 − 224 = 31, so the wildcard is 0.0.0.31, which matches 32 addresses.
Where wildcards are used
- Cisco ACLs (standard and extended):
permit 10.1.1.0 0.0.0.255. - OSPF network statements on IOS:
network 10.1.1.0 0.0.0.255 area 0enables OSPF on interfaces whose address matches. - EIGRP network statements with the same syntax.
Junos, NX-OS ACLs, Arista EOS, MikroTik and Linux firewalls use prefix notation (10.1.1.0/24) instead. IOS XR and NX-OS accept both forms in many places.
Worked example
Network 192.168.1.0 with mask 255.255.255.0:
255.255.255.255 − 255.255.255.0 = 0.0.0.255 access-list 10 permit 192.168.1.0 0.0.0.255 router ospf 1 network 192.168.1.0 0.0.0.255 area 0
Common values
| Prefix | Subnet mask | Wildcard | Matches |
|---|---|---|---|
| /32 | 255.255.255.255 | 0.0.0.0 | 1 (use host) |
| /30 | 255.255.255.252 | 0.0.0.3 | 4 |
| /28 | 255.255.255.240 | 0.0.0.15 | 16 |
| /26 | 255.255.255.192 | 0.0.0.63 | 64 |
| /24 | 255.255.255.0 | 0.0.0.255 | 256 |
| /22 | 255.255.252.0 | 0.0.3.255 | 1,024 |
| /16 | 255.255.0.0 | 0.0.255.255 | 65,536 |
Non-contiguous wildcards
Unlike subnet masks, wildcards do not need contiguous bits. 10.0.0.0 0.0.254.255 matches every 10.0.x.0/24 with an even third octet, a trick sometimes used to select even VLANs or odd/even sites with one ACE. The calculator accepts these and flags them in yellow because they cannot be expressed as a prefix. Use them sparingly: they are hard to read, and on some hardware they consume more TCAM entries.
Gotchas
- IOS silently corrects the address to match the wildcard in some versions (
permit 10.1.1.5 0.0.0.255becomes 10.1.1.0) and not in others. Always enter the network address. - Entering a subnet mask where a wildcard is expected (
0.0.0.255vs255.255.255.0) is a classic CCNA mistake:permit 10.1.1.0 255.255.255.0matches almost anything ending in .0. - The tool treats a dotted input that starts with a 1-bit as a subnet mask and anything else as a wildcard.
- Every ACL ends with an implicit
deny any. After writing your permit lines with the right wildcard, verify hit counters withshow access-listsbefore relying on the rule. - For OSPF, the most precise style is one statement per interface with a
0.0.0.0wildcard (network 10.1.1.1 0.0.0.0 area 0), orip ospf 1 area 0directly under the interface.