OT security

IPv4 subnet planning for OT networks: CIDR, VLANs and address plans

A practical method for sizing OT subnets: how CIDR maps to host counts, how to leave room to grow, how to align subnets with cells and zones and how to document the plan.

CIDR in one table

A CIDR prefix such as /24 says how many leading bits of an IPv4 address identify the network. The remaining bits count the addresses inside it. Subtract the network address and the broadcast address to get the hosts you can actually assign.

PrefixSubnet maskTotal addressesUsable hosts
/24255.255.255.0256254
/25255.255.255.128128126
/26255.255.255.1926462
/27255.255.255.2243230
/28255.255.255.2401614
/29255.255.255.24886
/30255.255.255.25242
/31255.255.255.25422 (point-to-point links, RFC 3021)

The OT network calculator shows the same breakdown for any address, including the binary view that makes the boundaries obvious.

Start from zones, not from addresses

The most common planning mistake is to pick addresses first and invent a structure later. Reverse it. Begin with the zones and conduits in your network design (see the Purdue model and the IEC 62443 introduction) and give each zone its own subnet. A subnet per production cell or function means a firewall rule can say “line 1 controllers may talk to the line 1 supervisory server on this port” instead of listing individual hosts.

Size for growth, not for today

Renumbering a running plant needs a maintenance window and careful coordination, so it is cheaper to leave room than to resize later. List today’s devices per zone (controllers, I/O blocks, drives, HMIs, switches, cameras, gateways), add spares, and add a growth margin your team agrees on. A simple working rule is to plan for at least double today’s device count whenever renumbering would require a shutdown. Round up to the next prefix, remembering that two addresses in each subnet are never assignable.

Choose private ranges deliberately

RFC 1918 reserves three private ranges: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Pick ranges that do not overlap with the corporate IT network, with the networks of machine builders and integrators, or with the VPNs used for remote support. Overlaps look harmless until two networks have to be connected, and then they force NAT or renumbering. Avoid leaving devices on their factory default network such as 192.168.0.x; it invites collisions as the first spare unit arrives.

A worked address plan (example)

This is an illustration of the method for a site given the block 10.20.0.0/16. The numbers are not a recommendation for your plant.

SubnetPurposeHosts needed todayChosen size
10.20.10.0/24Line 1 controllers and I/O≈ 60/24 (room to grow)
10.20.11.0/25Line 1 HMIs and operator panels≈ 12/25
10.20.20.0/24Line 2 controllers and I/O≈ 55/24
10.20.100.0/24SCADA, historian and edge servers≈ 20/24
10.20.200.0/28Firewall, switch and gateway management≈ 8/28
10.20.250.0/30Point-to-point link to the DMZ firewall2/30

VLANs and subnets belong together

Map one VLAN to one subnet and keep the mapping in the same table. A broadcast domain that is too large slows discovery-heavy protocols and makes faults harder to isolate, and some industrial protocols rely on multicast or broadcast discovery, so check the requirements of your devices before merging cells into one large VLAN. Managed switches are needed to enforce the separation: see managed versus unmanaged industrial switches.

Document it where people will find it

  • Keep one table with subnet, VLAN, purpose, gateway, owner and the firewall rule set that applies.
  • Store it under version control or in the asset inventory, and update it in the same change that adds a device.
  • Reserve a block for management interfaces, and reserve addresses for spares and for commissioning laptops.
  • Check each subnet with the calculator before it goes into a firewall rule.

An address plan is one of the first deliverables in the first 30 days of an IT/OT project, because every later step, from the gateway pilot to remote access, depends on it.

THE NEXT STEP

From calculation to implementation.

Let’s look at your machine, your data flow or your production goal together. Describe your situation in a few sentences and the ASP Dijital team will reply by email.

Talk to ASP Dijital