🔀 Wildcard Mask Calculator

Enter a CIDR prefix (0-32) or a dotted subnet mask to compute the wildcard mask — the bitwise inverse used in Cisco ACLs and OSPF network statements.

Inverting the mask, octet by octet

The page builds the subnet mask from your prefix, then flips every bit. Because an octet only ever runs 0 to 255, subtracting from 255 is the same operation as a bitwise NOT, which is how the code does it:

mask octets     = 0xFFFFFFFF << (32 - prefix)
wildcard octet  = 255 - mask octet   (identical to NOT)
mask + wildcard = 255.255.255.255

A /26 gives 255.255.255.192, so the wildcard is 0.0.0.63: 255 - 192 is 63, and 192 is 11000000 against 00111111. A /22 gives 255.255.252.0 and 0.0.3.255. A /32 inverts to 0.0.0.0, which is why Cisco writes host 10.1.1.1 as shorthand, and /0 inverts to 255.255.255.255, the any keyword.

Where the flipped mask is required

In a subnet mask a 1 bit means "this bit is network". In a wildcard mask a 1 bit means "ignore this bit". Two places still expect the wildcard form:

The box takes a prefix number only, despite the wording above it. To go the other way from a dotted mask, subtract each octet from 255 by hand - 255.255.240.0 becomes 0.0.15.255.

Frequently asked questions

What is the wildcard mask for a /24?

0.0.0.255. The subnet mask 255.255.255.0 inverts octet by octet, leaving the last octet as the part the device is told to ignore.

Is a wildcard mask the same as an inverse subnet mask?

Usually, but not always. Wildcards are converted from subnet masks most of the time, yet they are allowed to have 1 bits scattered anywhere, while a valid subnet mask must be one unbroken run of 1 bits.

How do I match a single host in an access list?

Use a wildcard of 0.0.0.0, which means every bit must match. On IOS the keyword host expands to exactly that, so host 192.168.5.7 and 192.168.5.7 0.0.0.0 are the same rule.