IPv4 Subnet Mask Table
One A4 page: every IPv4 prefix, mask, wildcard, address count, subnet boundaries and special-range reminders.
Search practical guides, command references and printable cheat sheets.
131 entries
No matching entries. Clear filters or browse all tools.
One A4 page: every IPv4 prefix, mask, wildcard, address count, subnet boundaries and special-range reminders.
Work through original subnetting examples for boundaries, host capacity and address allocation.
Recognize common private, shared, loopback, documentation and local address ranges.
Common service ports and transport choices in a printable reference.
Understand common DNS record types, TTLs and frequent configuration mistakes.
A one-page A4 reference for IPv6 notation, prefix sizes, address types, multicast and reverse DNS.
A one-page A4 reference for frame size, VLAN overhead, IP MTU, TCP MSS and tunnel budgeting.
One A4 page explaining Wi-Fi generations, channel widths, spatial streams and PHY rates without promising Internet speeds.
One A4 page of current /interface/wifi band selectors, package distinctions and channel-width syntax.
One A4 field reference for selected European-relevant LTE and NR bands, duplex modes, frequency ranges and RouterOS selectors.
Build a wired WAN-to-LAN setup with DHCP, a bridge, DNS, masquerade and explicit firewall protection.
Fix same-subnet hairpin NAT with a LAN destination rule and a scoped return-path translation; check external forwarding separately.
Allow LAN Internet access, restrict SSH and WinBox to one administrator, and apply separate IPv4 and IPv6 firewall rules.
Stage RouterOS bridge VLANs and diagnose a management lockout: CPU-port membership, PVID, tagged uplinks, input policy and Safe Mode recovery.
Fix commands copied for the wrong wireless driver and set a supported channel width in the correct RouterOS menu.
Choose the correct LTE/5G restriction and undo a band, cell or operator lock without confusing the three settings.
Select or restore LTE and NR bands with supported RouterOS properties while accounting for carrier aggregation and NSA anchors.
Read the serving LTE cell, scan supported modems and collect the EARFCN/PCI pair needed for cell locking.
Choose the documented LTE cell-lock family, query supported locks and understand reset, handover and carrier-aggregation limits.
Lock a supported modem to a measured 5G SA cell, query or clear the lock, and avoid applying it to an NSA connection.
Fix an ignored manual APN on an MBIM modem, restore registration after a bad lock, or separate LTE service from LAN forwarding.
Find the fix for client DNS, hairpin NAT, lost VLAN management, FastTrack, WireGuard, LTE APN and device-mode errors.
Fix legacy IoT connection failures, congested channels, unintended speed limits and poor client coverage with the relevant UniFi setting.
Configure the SSID VLAN and trace missing DHCP through AP native/tagged ports, switch uplinks and the gateway while preserving AP management.
Block Guest access across VLANs and between clients on the same VLAN, while keeping intentional Trusted-to-IoT exceptions.
Create a specific trusted-to-IoT service allowance, order stateful replies and blocks, and keep gateway services separate.
Trace failed UniFi port forwards through CGNAT or double NAT, WAN selection, the server listener and the return route.
Convert an existing route-based FortiGate tunnel to IKEv2: phase 1 changes, peer IDs, Child SA selectors and common negotiation failures.
Check VDOM, inherited filters, log-filter versus log filter syntax and whether a negotiation is actually starting.
Trace one new protected network through Child SA selectors, routing, policy, NAT and the destination host’s return path.
Troubleshoot FortiGate management access using interface services, trusted hosts and local-in rule order, with a scoped CLI example.
Apply Fortinet’s scoped IPS-update memory workaround on 2 GB models and identify the related fixed high-CPU defect.
Check model and port-group limits when H is missing, routing loads the CPU, or full L3 hardware offload bypasses firewall rules.
Diagnose simple queues that do not limit traffic, missing packet marks and connections taking the wrong WAN when FastTrack is enabled.
Trace allowed-address, routes, input versus forward rules and the return path when a RouterOS WireGuard peer handshakes but cannot reach the remote LAN.
Use local-address-as-src-ip on RouterOS 7.17+ when the DHCP server path expects the relay address instead of the transit source.
Check DHCP-advertised DNS, allow-remote-requests, TCP and UDP 53, static records and application DNS when RouterOS resolves names but LAN clients fail.
Check Network application compatibility, management VLAN, TCP 8080 reachability and previous management before resetting an AP or switch.
Investigate “Multiple devices are using the same IP address”, static addresses inside DHCP pools and DHCP Guarding without blocking the legitimate server.
Use AP uptime, PoE events and link changes to distinguish power loss, cable faults and management connectivity failures.
Separate service discovery from the application connection, scope the mDNS proxy and diagnose IoT discovery without opening every inter-VLAN service.
Distinguish normal RSTP redundancy from Loop Protection or BPDU Guard shutdown, inspect wired and mesh paths, and recover without disabling loop protection globally.
Fix an inter-VDOM policy-routing RPF drop when a suitable kernel return route cannot be used, with an exception on the receiving VDOM link.
Troubleshoot cross-model FortiGate imports with config-error-log, interface dependency mapping and a comparison of the loaded configuration.
Troubleshoot FortiGate proposal errors by tunnel selection, IKE/ESP transforms, PRF, DH, PFS and the failed negotiation stage.
Fix the PSK/local-user migration settings: enable EAP, restore policy groups and remove the conflicting tunnel-level group binding.
Compare endpoint-address and current-endpoint-address, NAT keepalive and responder roles after an LTE/5G or roaming endpoint changes.
Diagnose resolving error, SSL errors and connection reset by peer using DoH bootstrap DNS, endpoint compatibility and certificate validation.
Find the device-mode setting for the refused RouterOS tool, then enable the sniffer with physical confirmation. Handle flagged configuration separately.
Map overlapping VPN networks to distinct translated prefixes and align FortiGate selectors, routes, IP pools, VIPs and reverse traffic.
Diagnose intermittent IPsec data loss using Child SA rekey, tunnel counters, routing and narrowly scoped hardware-offload issues.
Diagnose FE instead of GbE on an AP, switch or gateway: verify negotiated speed, isolate cable and port faults, and separate link rate from Wi-Fi throughput.
Fix a RouterOS WireGuard import rejected because the configuration file begins with a comment.
Remove an automatically created interface-subnet object or an obsolete packet-capture reference using the documented correction.
Traffic works until FortiGate offloads it? Find scoped NPU/ASIC fixes for IPsec, QinQ, NP6 failback and SoC5 shaping, with CLI commands and fixed releases.
Check which FortiGate models still support FortiClient SSL VPN, the last working FortiOS version, upgrade cutoffs, and where Agentless VPN remains.
Mac Wi-Fi connected but websites won't load? Check DHCP, router, DNS and VPN separately before resetting network settings.
Troubleshoot Mac VPN connections that break internet access, internal DNS or local network resources. Understand split tunneling and routing.
Fix a MacBook external display that stays black or runs at the wrong resolution. Check USB-C video support, docks, detection and Mac limits.
Can't find or join an iPhone hotspot? Check cellular data, Allow Others to Join, compatibility, Wi-Fi passwords and USB connection.
Understand iPhone Private Wi-Fi Address settings and why MAC-based access lists, reservations or guest networks may behave differently.
Troubleshoot AirDrop when a nearby iPhone or Mac doesn't appear, requests fail or receiving settings prevent transfers.
Find MacBook battery cycle count, interpret battery health and charging limits, and troubleshoot slow or interrupted charging.
Capture one FortiGate traffic flow with bounded sniffer commands. Find ingress, egress and replies, account for NAT, and stop captures safely.
Run a bounded FortiGate debug flow for one connection. Understand policy, route and session messages, then stop debugging and clear filters.
Filter FortiGate sessions by client, destination and port. Read policy IDs, NAT actions and reply counters without clearing live connections.
Check the route to a destination and match a complete flow against FortiGate policy routing. Separate route availability from forwarding decisions.
Check FortiGate BGP state, accepted and advertised routes, and routing-table installation. Diagnose one peer without resetting the BGP session.
Inspect FortiGate link state, interface counters and ARP resolution. Compare counter changes and separate physical faults from Layer 3 problems.
Inspect FortiGate FGCP members, roles and configuration checksums. Localize a synchronization mismatch without forcing failover or resynchronization.
Check FortiGate SD-WAN health, members and rule selection. Use the right service command for your FortiOS version and verify the actual flow.
Inspect FortiGate FQDN resolution and NTP synchronization. Distinguish cached addresses, DNS reachability, clock offset and time-zone display.
Correlate FortiGate IKE and RADIUS authentication with FAC push approval. Capture one login, identify timeout boundaries and stop debugging cleanly.
Read RouterOS Ethernet link speed, errors, traffic counters and SFP diagnostics with a focused command reference and an evidence-first workflow.
Find a MAC address on a RouterOS bridge and inspect VLAN membership, PVID and hardware-offload state without changing the bridge configuration.
Inspect RouterOS v7 routes, next hops, custom tables and policy rules. Separate a missing route from selection of the wrong routing table.
Inspect RouterOS firewall counters, NAT rules and connection tracking to follow one connection without flushing sessions or adding broad allow rules.
Choose Torch or the RouterOS packet sniffer, filter one host or service, and understand NAT, hardware-offload and FastTrack visibility limits.
Find RouterOS DHCP leases, check pool use and inspect delivered network settings. Separate server, client and relay questions before changing leases.
Inspect RouterOS v7 BGP session state and one received prefix. Separate session establishment, route acceptance and next-hop selection.
Read RouterOS v7 OSPF neighbour states, interface templates and LSAs. Check adjacency and route installation as separate troubleshooting stages.
Choose RouterOS binary backup or readable export, protect sensitive files and use Safe Mode for small remote changes without confusing it with a backup.
Inspect RouterOS IPsec IKE peers, matching policies and selected SA counters while avoiding session resets and accidental exposure of encryption keys.
Check Juniper link state, interface errors, flaps and optical receive power. A practical read-only workflow for MX, with EX and SRX differences.
Find IPv4 and IPv6 routes in Junos inet.0 and VRF tables. Compare a destination lookup, an exact prefix and the Routing Engine forwarding table.
Troubleshoot Juniper BGP state, received routes and advertised prefixes. Understand what each command proves before resetting a session.
Check Junos OSPF neighbors, interface timers, MTU and learned routes. Distinguish normal 2-Way behavior from a failed adjacency.
Inspect IS-IS neighbors, Level 1 and Level 2 operation, interface metrics and the database on Juniper MX without resetting the protocol.
Trace an endpoint from IP to MAC to switch port. Separate Juniper EX ELS switching commands from MX bridge-domain commands.
Inspect Junos stateless firewall filters, counters and policers. Verify attachment and compare counter changes without clearing production evidence.
Review a Junos candidate, validate syntax and use commit confirmed deliberately. Understand rollback 0 versus rollback 1 before changing a device.
Check Juniper LACP actor and partner state, packet counters and aggregate members. Diagnose a missing link without bouncing the whole bundle.
Collect Juniper logs, current time, NTP peer state and alarms before troubleshooting. Build a reliable incident timeline with read-only commands.
Check Cisco IOS XE interface status, CRC errors, drops and err-disabled ports. Read-only Catalyst commands with a practical troubleshooting workflow.
Troubleshoot Cisco Catalyst VLANs and 802.1Q trunks with read-only IOS XE commands. Compare allowed, active and forwarding VLANs at both ends.
Find the STP root, inspect blocked ports and investigate inconsistent states on Cisco IOS XE. Includes separate PVST and MST read-only workflows.
Check Cisco IOS XE port-channel status, LACP neighbors and member flags. Understand suspended links and uneven traffic without resetting the bundle.
Trace an IP address to a Cisco switch port using ARP, MAC tables, CDP and LLDP. Learn which table to check and where the method stops working.
Look up an IPv4 route in Cisco IOS XE, select the correct VRF and inspect CEF forwarding. Separate routing-table evidence from end-to-end reachability.
Check IOS XE BGP sessions, accepted prefixes, advertised routes and route installation. Read-only commands with practical interpretation and scope limits.
Troubleshoot OSPFv2 on IOS XE using neighbor, interface and database commands. Understand 2-Way, ExStart and Full without resetting the process.
Check IOS XE IPv4 ACL attachment and rule matches. Learn why zero software counters on Catalyst 9000 do not prove that hardware traffic missed an ACL.
Inspect IOS XE IPv4 NAT translations and statistics without clearing sessions. Follow a single flow and distinguish NAT state from successful connectivity.
Find the right UniFi SSH credentials and collect read-only device logs. Separate console, AP and switch access from legacy USG and EdgeOS commands.
Choose a useful UniFi capture point for DHCP, DNS and TCP failures. Run short tcpdump captures and distinguish missing packets from a wrong interface.
Understand key UniFi management ports by endpoint and purpose. Separate device communication, browser access and discovery before changing firewall rules.
Save the right UniFi backup and collect console or device support files. Build a useful incident bundle without confusing recovery data with logs.
Understand EdgeOS operational and configuration modes. Preview changes and use commit-confirm correctly, including its reboot and saved-config behavior.
Check EdgeOS routes, BGP sessions and advertised prefixes. Separate the BGP table, active routing table and policy-routing path before changing peers.
Inspect EdgeOS interfaces and interface MAC addresses, then capture ARP on the correct LAN. Separate a physical port from its VLAN or switch interface.
Read EdgeOS firewall and NAT counters without clearing sessions. Check interface attachment, WAN_IN versus WAN_LOCAL, rule order and a fresh test connection.
Copy focused tcpdump filters for hosts, networks, DNS and TCP. Learn where to capture, how to save a PCAP and what missing packets really mean.
Find practical Wireshark display filters and matching capture filters for hosts, ports, DNS and TCP. Avoid common mistakes when investigating packet loss.
Diagnose DNS with dig: choose a resolver, compare A and AAAA answers, test TCP, inspect response codes and distinguish NXDOMAIN from an empty answer.
Use Test-NetConnection, Resolve-DnsName and Get-NetTCPConnection to separate DNS, route, TCP and local-listener problems on Windows.
Inspect Linux addresses, route selection, neighbors and sockets with read-only ip and ss commands. Find the right interface and local listener before changing configuration.
Check a server certificate with OpenSSL while preserving SNI and hostname verification. Inspect expiry, SAN names and the difference between a supplied and trusted chain.
Separate DNS, TCP, TLS and HTTP failures with curl. Test one backend with --resolve, preserve hostname verification and read timing results correctly.
Run repeatable iperf3 tests and interpret single-stream, reverse and UDP results. Separate path capacity from endpoint limits without hiding weak performance.
Interpret all six BGP neighbor states, common reset reasons and an Established session with zero routes. Start with targeted read-only checks.
Interpret SFP receive power, alarms and growing CRC counters. Compare both ends, use the actual optic limits and avoid replacing parts without evidence.
Understand tagged and untagged VLAN traffic across vendors. Compare ingress classification, allowed membership and egress tagging before changing a port.
Locate a DHCPv4 failure by following Discover, Offer, Request and ACK. Use packet evidence to distinguish VLAN, relay, scope and client problems.
Find interface, IPv4 route and BGP inspection commands across FortiGate, MikroTik, Junos and Cisco, with context and links to detailed references.
Use the most-specific observed route to find an IP address’s BGP origin, then compare that evidence with registry information.
Inspect originated IPv4 and IPv6 routes without confusing them with allocations or networks reached through transit.
Read an observed AS path without treating it as a map of commercial contracts or the packet path your application used.
Registry records describe resource registration; BGP observations describe routing. A difference between them needs context, not an automatic error verdict.
Compare destination behavior with intermediate replies before deciding where a connection fails.
Validate a prefix–origin pair, including its prefix length, and keep validator availability separate from the routing result.
Compare the exact DNS question and its cached answer before treating a recent change as complete or broken.