The VPN is connected, but the laptop thinks staging is at home.
The laptop has a local route for 192.168.1.0/24 through Wi-Fi. The VPN client also
installs a route for staging at 192.168.1.0/24. Those ranges cover the same addresses.
In this example, the active route lookup selects Wi-Fi, so a request for staging's 192.168.1.80 never enters the tunnel. The laptop treats that address as local and tries
to find it on the home link instead of sending it to the VPN gateway.
The exact tie-breaking rule depends on the operating system and VPN client. The important evidence is the route actually selected on the affected laptop. A VPN icon alone cannot tell you whether this destination is using the tunnel.
192.168.1.37/24 Wi-Fi subnet: 192.168.1.0/24dev wlan0 sample result: 192.168.1.80 dev wlan0192.168.1.80 company network, behind VPNThe VPN also claims 192.168.1.0/24. The destination is inside both ranges, so the
laptop's active route choice—not the VPN connection indicator—explains why this request misses the tunnel.
Move staging onto a range the home LAN does not use.
For a new staging environment, the team chooses 10.0.0.0/24 after checking that it
does not overlap the connected office, VPN, or cloud networks. IPv4 has 32 bits, so a /24 leaves 8 host bits: 2^8 = 256 total addresses. Under conventional
IPv4 subnet rules, the network and broadcast addresses are not assigned to hosts.
The service needs room for 100 API hosts, 50 workers, and 20 database hosts. Allocate the smallest power-of-two block that holds each group plus its two reserved addresses, then start each block on a boundary that matches its size.
| Workload | Hosts needed | Block | Usable capacity | Assigned host range |
|---|---|---|---|---|
| API | 100 | 10.0.0.0/25 | 126 | 10.0.0.1–10.0.0.126 |
| Workers | 50 | 10.0.0.128/26 | 62 | 10.0.0.129–10.0.0.190 |
| Database | 20 | 10.0.0.192/27 | 30 | 10.0.0.193–10.0.0.222 |
The slash counts fixed network bits—even when it cuts through an octet.
The dotted address is a readable form of 32 bits, grouped into four 8-bit octets. A /20 prefix fixes 16 bits in the first two octets and four more in the third. Its mask is 255.255.240.0: the third octet advances in blocks of 256 − 240 = 16.
Take 172.16.37.9/20. The third octet, 37, falls in the block from 32 through 47.
The network begins at 172.16.32.0; the broadcast address is 172.16.47.255. The prefix is still a bit count even when its boundary is not a
dot in the written address.
The same rule catches misleading string comparisons. 10.2.3.8 and 10.2.30.8 both start with the characters 10.2.3, but only the first
belongs to 10.2.3.0/24. Membership means comparing the address bits selected by the mask.
For 192.168.4.6/30, two host bits remain, so the aligned block has four addresses: 192.168.4.4–192.168.4.7. Under the conventional rule, .4 is the network, .7 is the broadcast, and .5 and .6 are host addresses.
After the fix, the staging destination should use the VPN.
After staging moves, the VPN needs a route for 10.0.0.0/24. From the developer's
laptop, traffic for 10.0.0.200 should select the VPN interface. Once the request reaches
staging, the API at 10.0.0.10/25 makes a separate decision when calling the database
at 10.0.0.200/27.
The API host sees that 10.0.0.200 is outside 10.0.0.0/25 and, with no
more-specific host route, sends it to gateway 10.0.0.1 using its default route. The
router then selects 10.0.0.192/27, the database subnet. Run ip route get 10.0.0.200 on both the laptop and API host: the laptop should select the VPN;
the API host should select its gateway. Those are two route decisions at different points in the same
conversation.
Connected networks need address ranges that route to one place.
The home and staging networks both claim 192.168.1.0/24. A route cannot distinguish
which copy of 192.168.1.80 the user intended from the destination address alone. The
laptop may select Wi-Fi or the tunnel according to route metrics and VPN policy; either way, the
address plan is ambiguous across the connection.
For inclusive ranges [aStart, aEnd] and [bStart, bEnd], they overlap
when aStart ≤ bEnd and bStart ≤ aEnd. Equality counts: ranges that share
an endpoint overlap. Check each pair of connected networks, and check every child range stays
inside its parent before installing routes or firewall rules.
Longest-prefix match chooses the most specific matching route. For nested ranges, that can direct
traffic to the wrong segment: 10.0.0.64/26 can capture 10.0.0.100 from the broader 10.0.0.0/25. For exact duplicate prefixes like
the home and staging ranges, the operating system and VPN policy choose between equally specific
routes; the destination address cannot identify which network the user intended.
A clean fix changes the plan and checks the route again.
For a new environment, allocate the non-overlapping parent range first, then divide it for the API, workers, and database. The example follows request order; each next block starts at the next boundary of its size. Stop at the parent network's end and report a request that cannot fit—never wrap into the next range.
First-fit in request order is easy to explain and preserves request order, but a different order can leave a different remainder. Sorting larger requests first can reduce fragmentation, while stable, reserved ranges may matter more for an established network. Pick and document the policy that fits the network’s ownership and growth plan.
Before rollout, check the new CIDRs against home, office, peer VPN, and cloud routes. Update the staging addresses, VPN's advertised routes, DNS records, firewall rules, and allowlists together. Then reconnect and repeat the route lookup from the affected laptop: the staging destination should select the VPN interface. If the route now uses the VPN and the service responds, that supports the overlap diagnosis. If the route changes but the service still times out, continue along the path and test the actual service port; the route alone does not prove the repair is complete.
This is easiest to fix before deployment. Renumbering a live network can require a migration plan; NAT can bridge some unavoidable overlaps, but it adds translation state and operational complexity.
Calculate, check, and allocate IPv4 blocks.
Start with a subnet summary, then check membership and plan child networks. The tasks use bounded IPv4 cases and run the same checks in TypeScript and Go.
Networking practice 10 min
Find the address range behind a prefix
This is an experiment with ticket-style exercises, giving beginners a feel for how tasks may be described in the workplace. Leave feedback
Checking your sign-in status. Your lesson remains available while we check.