AgenorIT
AgenorIT
LANDING ZONE/ NETWORK TOOLS
IPv4 · Azure-aware
ADDRESS SPACE DESIGN

CIDR planner - Azure Landing Zone CIDR Planner.

Build your hub, spokes and workload networks. See every address accounted for.

Azure Landing Zone
Total addresses
65,536
10.0.0.0/16
Allocated
2,304
3.5% of this address space
Unallocated
63,232
Raw addresses available to allocate
Azure-usable IPs
285
In defined subnets · 35 reserved
ADDRESS MAP

Your network, at a glance

Azure reserved
35
Subnet usable
285
Unallocated
63,232
Unsubnetted in networks
1,984

65,536 total addresses · 2,304 allocated to network or subnet blocks. Azure reserves 5 IPs per subnet. Unsubnetted addresses sit inside allocated network containers and remain available for child subnets.

10.0.0.010.0.255.255
Each tile = 256 addresses · partial tiles show exact proportionsHatched = reserved · Top-right dark corner = tile contains reservations
10.0.0.0/16 · 65,536 addresses · click an allocation tile or track to zoom
Proportional Allocation Tracks
Hub networkSpoke networkWorkload networkFirewallBastionGatewayManagementApplicationPrivate endpointUnallocated: 63,232Azure reserved: 35Unsubnetted: 1,984
ALLOCATIONS

Networks & subnets10

Edit any CIDR directly to test scenarios.

Name / typeCIDRParentTotal / usableRequired IPsStatusActions
1,024/—
Container
Valid
64/59
Valid
64/59
Valid
32/27
Valid
32/27
Valid
1,024/—
Container
Valid
256/—
Container
Valid
64/59
Valid
32/27
Valid
32/27
Valid

Validation

Plan checks passed

All allocations fit. No address overlaps.

Azure subnet sizes and required names are valid.

Available address blocks

7 blocks

63,232 raw addresses · minimal aligned CIDR blocks

10.0.9.0/24256 IPs
10.0.10.0/23512 IPs
10.0.12.0/221,024 IPs
10.0.16.0/204,096 IPs
10.0.32.0/198,192 IPs
10.0.64.0/1816,384 IPs
10.0.128.0/1732,768 IPs

Parent address space

Network address space details

Canonical CIDR10.0.0.0/16
Subnet mask255.255.0.0
Full address range10.0.0.0 – 10.0.255.255
Addresses in block65,536
Allocation scopeParent address pool
ReservationsApplied per subnet, not per VNet

A parent pool is an IP planning boundary. Add dedicated hub, spoke, and workload network containers first, then define child subnets within them.

Capacity counts unique addresses. Containers and their subnets are never counted twice.Calculations execute client-side in your browser.
Architecture Guide & Best Practices

Microsoft Azure Landing Zone Address Space Architecture

A well-architected Azure Landing Zone network foundation prevents IP exhaustion, eliminates cross-premises overlapping address conflicts with on-premises data centres, and facilitates governed hub-and-spoke routing aligned with the Microsoft Cloud Adoption Framework (CAF).

1

Connectivity Hub VNet

Houses centralized shared network services including Azure Firewall (/26 or larger), Azure Bastion (/26 or larger), GatewaySubnet (/27 or larger for non-Basic VPN / ExpressRoute), and network management virtual appliances.

2

Application Spokes

Dedicated VNets housing business workloads, segmented into application, management, and private endpoint subnets. Spokes peer with the Hub VNet and route egress through the central firewall without direct Internet exposure.

3

Azure Subnet Reservations

Every Azure subnet reserves exactly 5 IP addresses (first 4 and last 1). For example, a /26 has 64 raw addresses but yields 59 usable host IPs. Sizing estimates must always account for this deduction to prevent deployment failures.

Australian Enterprise & Sovereign Cloud Networking

Designing Azure Networks for Australian Cloud Regions

Australian enterprises navigating multi-region resiliency commonly design dual-hub topologies across Microsoft Azure Australia East (Sydney) and Australia Southeast (Melbourne), with government workloads leveraging Australia Central (Canberra) under ACSC Essential Eight and IRAP frameworks. When establishing hybrid interconnects via Telstra, Equinix, or NextDC ExpressRoute peering, allocating strict non-overlapping RFC 1918 IPv4 ranges (10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16) is essential to preserve NAT-free private connectivity.

Frequently Asked Technical Questions

Practical answers to Azure subnet allocation, reservation rules, and IP planning questions.

Why does Azure reserve 5 IP addresses per subnet?

In every Azure Virtual Network subnet, Microsoft reserves the first four IP addresses and the last IP address for internal protocol operations: x.x.x.0 (network address), x.x.x.1 (default gateway), x.x.x.2 and x.x.x.3 (Azure DNS mapping), and the final address (network broadcast). These five addresses cannot be assigned to any virtual machine or service instance.

What are the minimum subnet sizes for Azure Firewall and Bastion?

Microsoft specifies that AzureFirewallSubnet and dedicated AzureBastionSubnet must be sized at /26 or larger (e.g. /26, /25, /24, with a smaller prefix number). Sizing these subnets at /27 or smaller will result in deployment failure in the Azure portal or ARM/Bicep template execution.

What is the required subnet size for Azure VPN Gateway?

For production and high-availability non-Basic VPN Gateway configurations, GatewaySubnet must be sized at /27 or larger (/27, /26). While legacy Basic SKUs previously permitted /28, Microsoft enterprise guidance recommends /27 to accommodate active-active gateway instances and future maintenance routing.

How do network containers differ from subnets in this planner?

Network containers (Hub, Spoke, Workload) represent overall virtual network address spaces (VNets). The five Azure reserved IPs are only deducted when a block is allocated as an active subnet, never from a containing VNet or parent address pool.

How do I plan CIDRs for multi-region Australian deployments (e.g. Australia East & Southeast)?

For high-availability disaster recovery across Azure Australia East (Sydney) and Australia Southeast (Melbourne), allocate contiguous non-overlapping address blocks (e.g., /16 carved into two /17s or multiple /20s per region). This ensures seamless cross-region VNet peering, ExpressRoute gateway connectivity, and eliminates route summarisation conflicts with on-premises networks.

How does this tool align with Microsoft Cloud Adoption Framework (CAF)?

This planner adheres strictly to the Microsoft Cloud Adoption Framework (CAF) Enterprise-Scale Landing Zone networking principles: dedicated connectivity subscription hub networks, delegated workload spokes, centralized egress security subnets, and strict prevention of overlapping IPv4 spaces across hybrid cloud interconnects.

Enterprise Architecture Services

Need an Independent Azure Landing Zone Architecture Review?

AgenorIT architects design, implement, and govern multi-subscription Azure Landing Zones aligned with the Microsoft Cloud Adoption Framework (CAF) and Australian ISM/IRAP benchmarks across Melbourne, Sydney, and Brisbane.

Schedule Architecture Review