CIDR planner - Azure Landing Zone CIDR Planner.
Build your hub, spokes and workload networks. See every address accounted for.
Your network, at a glance
65,536 total addresses · 2,304 allocated to network or subnet blocks. Azure reserves 5 IPs per subnet. Unsubnetted addresses sit inside allocated network containers and remain available for child subnets.
Networks & subnets10
Edit any CIDR directly to test scenarios.
| Name / type | CIDR | Parent | Total / usable | Required IPs | Status | Actions |
|---|---|---|---|---|---|---|
1,024/— | Container | Valid | ||||
64/59 | Valid | |||||
64/59 | Valid | |||||
32/27 | Valid | |||||
32/27 | Valid | |||||
1,024/— | Container | Valid | ||||
256/— | Container | Valid | ||||
64/59 | Valid | |||||
32/27 | Valid | |||||
32/27 | Valid |
Validation
Plan checks passedAll allocations fit. No address overlaps.
Azure subnet sizes and required names are valid.
Available address blocks
7 blocks63,232 raw addresses · minimal aligned CIDR blocks
Parent address space
Network address space details
A parent pool is an IP planning boundary. Add dedicated hub, spoke, and workload network containers first, then define child subnets within them.
Microsoft Azure Landing Zone Address Space Architecture
A well-architected Azure Landing Zone network foundation prevents IP exhaustion, eliminates cross-premises overlapping address conflicts with on-premises data centres, and facilitates governed hub-and-spoke routing aligned with the Microsoft Cloud Adoption Framework (CAF).
Connectivity Hub VNet
Houses centralized shared network services including Azure Firewall (/26 or larger), Azure Bastion (/26 or larger), GatewaySubnet (/27 or larger for non-Basic VPN / ExpressRoute), and network management virtual appliances.
Application Spokes
Dedicated VNets housing business workloads, segmented into application, management, and private endpoint subnets. Spokes peer with the Hub VNet and route egress through the central firewall without direct Internet exposure.
Azure Subnet Reservations
Every Azure subnet reserves exactly 5 IP addresses (first 4 and last 1). For example, a /26 has 64 raw addresses but yields 59 usable host IPs. Sizing estimates must always account for this deduction to prevent deployment failures.
Designing Azure Networks for Australian Cloud Regions
Australian enterprises navigating multi-region resiliency commonly design dual-hub topologies across Microsoft Azure Australia East (Sydney) and Australia Southeast (Melbourne), with government workloads leveraging Australia Central (Canberra) under ACSC Essential Eight and IRAP frameworks. When establishing hybrid interconnects via Telstra, Equinix, or NextDC ExpressRoute peering, allocating strict non-overlapping RFC 1918 IPv4 ranges (10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16) is essential to preserve NAT-free private connectivity.
Frequently Asked Technical Questions
Practical answers to Azure subnet allocation, reservation rules, and IP planning questions.
Why does Azure reserve 5 IP addresses per subnet?
In every Azure Virtual Network subnet, Microsoft reserves the first four IP addresses and the last IP address for internal protocol operations: x.x.x.0 (network address), x.x.x.1 (default gateway), x.x.x.2 and x.x.x.3 (Azure DNS mapping), and the final address (network broadcast). These five addresses cannot be assigned to any virtual machine or service instance.
What are the minimum subnet sizes for Azure Firewall and Bastion?
Microsoft specifies that AzureFirewallSubnet and dedicated AzureBastionSubnet must be sized at /26 or larger (e.g. /26, /25, /24, with a smaller prefix number). Sizing these subnets at /27 or smaller will result in deployment failure in the Azure portal or ARM/Bicep template execution.
What is the required subnet size for Azure VPN Gateway?
For production and high-availability non-Basic VPN Gateway configurations, GatewaySubnet must be sized at /27 or larger (/27, /26). While legacy Basic SKUs previously permitted /28, Microsoft enterprise guidance recommends /27 to accommodate active-active gateway instances and future maintenance routing.
How do network containers differ from subnets in this planner?
Network containers (Hub, Spoke, Workload) represent overall virtual network address spaces (VNets). The five Azure reserved IPs are only deducted when a block is allocated as an active subnet, never from a containing VNet or parent address pool.
How do I plan CIDRs for multi-region Australian deployments (e.g. Australia East & Southeast)?
For high-availability disaster recovery across Azure Australia East (Sydney) and Australia Southeast (Melbourne), allocate contiguous non-overlapping address blocks (e.g., /16 carved into two /17s or multiple /20s per region). This ensures seamless cross-region VNet peering, ExpressRoute gateway connectivity, and eliminates route summarisation conflicts with on-premises networks.
How does this tool align with Microsoft Cloud Adoption Framework (CAF)?
This planner adheres strictly to the Microsoft Cloud Adoption Framework (CAF) Enterprise-Scale Landing Zone networking principles: dedicated connectivity subscription hub networks, delegated workload spokes, centralized egress security subnets, and strict prevention of overlapping IPv4 spaces across hybrid cloud interconnects.
Need an Independent Azure Landing Zone Architecture Review?
AgenorIT architects design, implement, and govern multi-subscription Azure Landing Zones aligned with the Microsoft Cloud Adoption Framework (CAF) and Australian ISM/IRAP benchmarks across Melbourne, Sydney, and Brisbane.