taap.digitalnetwork engineering toolkit

What is the wildcard mask for a /17?

Answer
0.0.127.255 wildcard for /17 (255.255.128.0)

A /17 has the subnet mask 255.255.128.0. Subtract it from 255.255.255.255 and you get the wildcard 0.0.127.255: the last 15 bits are "don't care", so it matches 32,768 consecutive addresses.

wildcard · adjust the values

The calculation

255.255.255.255 − 255.255.128.0 = 0.0.127.255

A /17 block is typically half of a /16, typically one of two regions or buildings sharing a site block. With the network 10.0.0.0, the wildcard 0.0.127.255 matches 10.0.0.0 through 10.0.127.255.

Using it in Cisco IOS

! standard ACL
access-list 10 permit 10.0.0.0 0.0.127.255

! named extended ACL
ip access-list extended FROM-SITE
 permit ip 10.0.0.0 0.0.127.255 any

! OSPF
router ospf 1
 network 10.0.0.0 0.0.127.255 area 0

Junos, Arista EOS, MikroTik and Linux use the prefix form instead: 10.0.0.0/17.

Nearby prefixes

PrefixSubnet maskWildcardAddresses
/16255.255.0.00.0.255.25565,536
/17255.255.128.00.0.127.25532,768
/18255.255.192.00.0.63.25516,384
/19255.255.224.00.0.31.2558,192

More questions like this

Frequently asked questions

How many addresses does 0.0.127.255 match?

32,768. The wildcard has 15 one-bits, and 215 = 32,768.

Is 0.0.127.255 the same as 255.255.128.0?

No. 255.255.128.0 is the subnet mask; 0.0.127.255 is its bitwise inverse. Putting the subnet mask where IOS expects a wildcard matches the wrong addresses.