🔀 Wildcard Mask Calculator
Enter a CIDR prefix (0-32) or a dotted subnet mask to compute the wildcard mask — the bitwise inverse used in Cisco ACLs and OSPF network statements.
Inverting the mask, octet by octet
The page builds the subnet mask from your prefix, then flips every bit. Because an octet only ever runs 0 to 255, subtracting from 255 is the same operation as a bitwise NOT, which is how the code does it:
mask octets = 0xFFFFFFFF << (32 - prefix)
wildcard octet = 255 - mask octet (identical to NOT)
mask + wildcard = 255.255.255.255
A /26 gives 255.255.255.192, so the wildcard is 0.0.0.63: 255 - 192 is 63, and
192 is 11000000 against 00111111. A /22 gives 255.255.252.0 and 0.0.3.255. A /32
inverts to 0.0.0.0, which is why Cisco writes host 10.1.1.1 as
shorthand, and /0 inverts to 255.255.255.255, the any keyword.
Where the flipped mask is required
In a subnet mask a 1 bit means "this bit is network". In a wildcard mask a 1 bit means "ignore this bit". Two places still expect the wildcard form:
- IOS access lists:
access-list 10 permit 192.168.1.0 0.0.0.255matches the whole /24. - OSPF network statements:
network 10.0.0.0 0.0.0.255 area 0enables the protocol on interfaces inside 10.0.0.0/24. - Non-contiguous matching, which no subnet mask can express. The wildcard 0.0.254.255 against 10.1.0.0 cares only about the low bit of the third octet, so it matches every even-numbered /24 in 10.1.0.0/16 at once.
Frequently asked questions
What is the wildcard mask for a /24?
0.0.0.255. The subnet mask 255.255.255.0 inverts octet by octet, leaving the last octet as the part the device is told to ignore.
Is a wildcard mask the same as an inverse subnet mask?
Usually, but not always. Wildcards are converted from subnet masks most of the time, yet they are allowed to have 1 bits scattered anywhere, while a valid subnet mask must be one unbroken run of 1 bits.
How do I match a single host in an access list?
Use a wildcard of 0.0.0.0, which means every bit must match. On IOS the keyword
host expands to exactly that, so host 192.168.5.7 and
192.168.5.7 0.0.0.0 are the same rule.