A branch office is getting a proper switch stack, and with it the end of the flat network. Head office has allocated you exactly one block — 192.168.40.0/24 — and you need to fit users, VoIP phones, printers, cameras and a management VLAN into it. Get the boundaries wrong and you find out weeks later, when a phone pulls an address that the router thinks belongs to the printer subnet. This guide walks the plan from headcount to SVI config, using LizardSystems LanCalculator to verify each block and a short PowerShell check to catch the classic errors before anything touches a switch.
Step 1 — Count hosts, then add headroom
Write down each VLAN with its realistic device count, then add growth. A reasonable rule is 30–50% headroom for user and phone VLANs and a little less for infrastructure. Don’t forget per-subnet overhead: the network and broadcast addresses, the default gateway, and a second and third address if you run HSRP/VRRP.
| VLAN | Purpose | Devices today | Target usable |
|---|---|---|---|
| 10 | Users | 70 | ≥ 100 |
| 20 | Voice | 35 | ≥ 50 |
| 30 | Printers & MFPs | 12 | ≥ 20 |
| 50 | Cameras | 8 | ≥ 12 |
| 99 | Switch/AP management | 6 | ≥ 10 |
Step 2 — Pick the smallest prefix that fits
Usable hosts for a prefix are 2^(32−prefix) − 2. The ones you’ll use inside a /24:
| Prefix | Block size | Usable hosts | Mask |
|---|---|---|---|
| /25 | 128 | 126 | 255.255.255.128 |
| /26 | 64 | 62 | 255.255.255.192 |
| /27 | 32 | 30 | 255.255.255.224 |
| /28 | 16 | 14 | 255.255.255.240 |
| /29 | 8 | 6 | 255.255.255.248 |
So: Users need a /25, Voice a /26, Printers a /27, Cameras and Management a /28 each. Add up the block sizes — 128 + 64 + 32 + 16 + 16 = 256 — and you know before drawing anything that the plan fills the /24 exactly. If the sum is over 256, the plan doesn’t fit; if it’s well under, keep the leftover as one contiguous spare block.
Step 3 — Allocate largest-first
Variable-length plans only stay clean if you place the biggest blocks first, each starting on a multiple of its own size:
- VLAN 10 Users —
192.168.40.0/25: hosts .1–.126, broadcast .127 - VLAN 20 Voice —
192.168.40.128/26: hosts .129–.190, broadcast .191 - VLAN 30 Printers —
192.168.40.192/27: hosts .193–.222, broadcast .223 - VLAN 99 Management —
192.168.40.224/28: hosts .225–.238, broadcast .239 - VLAN 50 Cameras —
192.168.40.240/28: hosts .241–.254, broadcast .255
Allocating smallest-first is how you end up with a /26 that has to start at .72 — which isn’t a valid /26 boundary.
Step 4 — Verify each block in LanCalculator
LanCalculator is a Windows subnet calculator that accepts both masks and prefixes, handles IPv4 and IPv6, and can subnet a network by prefix, by number of subnet bits, by maximum number of subnets or by maximum hosts per subnet. It can also build and export a list of the subnets, or of every address in a subnet.
- Get it from the vendor’s product page on lizardsystems.com (see where to get it). Personal use is free; using it at work falls under the per-machine Business licence (US$49.95 at the time of writing — check the vendor’s current pricing).
- Enter each planned network with its prefix, e.g.
192.168.40.128/26, and confirm the calculated network address, first/last host and broadcast match your table. If you typed.130/26, the calculator will show the real network as.128— a sign your plan has an off-by-something. - For an equal-size split — say, four /26s for a second site — enter the parent
/24and subnet by maximum subnets = 4, then export the subnet list for the documentation. - Export the per-subnet address lists for the VLANs where you pre-assign static IPs (printers, management), and paste them into your IPAM sheet.
Note that LanCalculator’s product page doesn’t describe a VLSM wizard, so for mixed-size plans like this one the tool’s job is verification, not layout.
Step 5 — Double-check with PowerShell
A second, independent check costs nothing. This script flags any network that isn’t on its block boundary and any pair that overlaps:
function ConvertTo-UInt32([string]$ip) {
$b = ([ipaddress]$ip).GetAddressBytes(); [array]::Reverse($b)
[BitConverter]::ToUInt32($b, 0)
}
$plan = @(
@{ Vlan = 10; Net = '192.168.40.0'; Prefix = 25 }
@{ Vlan = 20; Net = '192.168.40.128'; Prefix = 26 }
@{ Vlan = 30; Net = '192.168.40.192'; Prefix = 27 }
@{ Vlan = 99; Net = '192.168.40.224'; Prefix = 28 }
@{ Vlan = 50; Net = '192.168.40.240'; Prefix = 28 }
)
$ranges = foreach ($p in $plan) {
$size = [uint32][math]::Pow(2, 32 - $p.Prefix)
$start = ConvertTo-UInt32 $p.Net
if ($start % $size) { "VLAN $($p.Vlan): $($p.Net)/$($p.Prefix) is not on a boundary" }
[pscustomobject]@{ Vlan = $p.Vlan; Start = $start; End = $start + $size - 1 }
}
$sorted = $ranges | Where-Object { $_ -isnot [string] } | Sort-Object Start
for ($i = 1; $i -lt $sorted.Count; $i++) {
if ($sorted[$i].Start -le $sorted[$i-1].End) {
"VLAN $($sorted[$i].Vlan) overlaps VLAN $($sorted[$i-1].Vlan)"
}
}
No output means no boundary or overlap errors.
Step 6 — Configure gateways and DHCP
Use the first usable address as the gateway in every VLAN, consistently. On a Cisco-style layer 3 switch:
interface Vlan20
description VOICE
ip address 192.168.40.129 255.255.255.192
ip helper-address 10.0.0.10
!
interface Vlan99
description MGMT
ip address 192.168.40.225 255.255.255.240
Build DHCP scopes that exclude the gateway and any static range — for Voice, perhaps .140–.190, leaving .130–.139 for statics. For ACLs, the wildcard mask is the inverse of the subnet mask: a /26 is 0.0.0.63, a /28 is 0.0.0.15.
Common mistakes
- Forgetting the two reserved addresses. A /27 holds 30 hosts, not 32.
- Starting a block off-boundary.
.100/26is not a network; the switch will quietly use.64/26. - Filling the /24 with no spare. This plan uses every address. If growth is likely, drop Cameras into a /29 or request a second block now, not later.
- DHCP scopes that overrun the subnet. A scope ending at
.191in a /26 that starts at.128hands out the broadcast address. - Mask/prefix mismatch between switch and firewall. Paste from one documented source, never retype.
Related
After the cut-over, sweep each VLAN to CSV to confirm devices landed where the plan says. The LanCalculator review covers licensing and limits in more detail, and other planning tools sit in Diagnostic & Planning Utilities.