taap.digitalnetwork engineering toolkit

What is the wildcard mask for a /16?

Answer
0.0.255.255 wildcard for /16 (255.255.0.0)

A /16 has the subnet mask 255.255.0.0. Subtract it from 255.255.255.255 and you get the wildcard 0.0.255.255: the last 16 bits are "don't care", so it matches 65,536 consecutive addresses.

wildcard · adjust the values

The calculation

255.255.255.255 − 255.255.0.0 = 0.0.255.255

A /16 block is typically a whole /16 campus or site block, for example every subnet of 10.0.0.0/16 in one ACL entry. With the network 10.0.0.0, the wildcard 0.0.255.255 matches 10.0.0.0 through 10.0.255.255.

Using it in Cisco IOS

! standard ACL
access-list 10 permit 10.0.0.0 0.0.255.255

! named extended ACL
ip access-list extended FROM-SITE
 permit ip 10.0.0.0 0.0.255.255 any

! OSPF
router ospf 1
 network 10.0.0.0 0.0.255.255 area 0

Junos, Arista EOS, MikroTik and Linux use the prefix form instead: 10.0.0.0/16.

Nearby prefixes

PrefixSubnet maskWildcardAddresses
/16255.255.0.00.0.255.25565,536
/17255.255.128.00.0.127.25532,768
/18255.255.192.00.0.63.25516,384

More questions like this

Frequently asked questions

How many addresses does 0.0.255.255 match?

65,536. The wildcard has 16 one-bits, and 216 = 65,536.

Is 0.0.255.255 the same as 255.255.0.0?

No. 255.255.0.0 is the subnet mask; 0.0.255.255 is its bitwise inverse. Putting the subnet mask where IOS expects a wildcard matches the wrong addresses.