Scope of Subnetting in Penetration Testing
During an authorized penetration test of network infrastructure, precise determination of test segment boundaries is essential. Correct subnet calculation enables identification of all active nodes within a target range, facilitates scanning phase planning, and prevents unauthorized access to adjacent network segments. The tester must establish clear network boundaries to ensure work remains within authorized scope.
Understanding subnet structure is critical for traffic routing analysis, entry and exit point identification, and firewall/IDS log examination. This enables the security professional to work methodically, document scope accurately, and provide clear evidence of authorized testing boundaries to stakeholders and auditors.
- Identify segment boundaries and VLAN assignments
- Plan routing paths for internal testing campaigns
- Determine host IP ranges for systematic analysis
CIDR Notation and Mask Calculation
CIDR (Classless Inter-Domain Routing) notation expresses a subnet as an IP address, forward slash, and prefix length. For example, 192.168.1.0/24 represents a network with mask 255.255.255.0, where the first 24 bits define the network address. Host availability is calculated using 2^(32-prefix): a /24 network contains 256 total addresses, minus two reserved addresses (network and broadcast), yielding 254 usable hosts.
Each prefix bit doubles available subnets. A /25 divides a /24 into two networks of 128 addresses each; /26 creates four networks of 64 addresses. Rapid conversion between CIDR notation and decimal mask representation is essential for efficient scope planning. The pentester should be able to quickly identify network and broadcast addresses for any given range.
- /24 = 256 addresses (254 usable hosts): 255.255.255.0
- /25 = 128 addresses (126 usable hosts): 255.255.255.128
- /26 = 64 addresses (62 usable hosts): 255.255.255.192
- /30 = 4 addresses (2 usable hosts): 255.255.255.252
Determining Subnet Boundaries and Host Ranges
For any subnet, calculate: network address (first address), broadcast address (last address), and usable host range. Method: convert IP and mask to binary, apply bitwise AND between IP and mask to obtain network address. Add one to network address for the first usable host; subtract one from broadcast address for the last usable host. This provides the complete inventory of addresses within scope.
Practical example: subnet 10.0.50.0/24 yields network address 10.0.50.0, first host 10.0.50.1, last host 10.0.50.254, broadcast 10.0.50.255. During testing, this defines which addresses require scanning and identifies router interfaces at segment boundaries. Accurate boundary calculation prevents scan overlap with out-of-scope networks and provides proof of controlled testing.
Supernets and Route Aggregation
A supernet combines multiple adjacent subnets into a single larger network with shorter prefix length. Two subnets 192.168.0.0/25 and 192.168.0.128/25 aggregate to 192.168.0.0/24. This occurs frequently in firewall rules where aggregated notation controls access to address blocks. The tester must decompose aggregated rules to understand actual scope and restrictions.
Supernet identification requires finding the shortest common prefix of adjacent subnets. Practical application: inter-segment routing rules often use aggregated notation. During firewall policy review, the tester must expand aggregations to identify specific ranges that fall within and outside authorized scope, ensuring accurate coverage assessment and compliance with engagement terms.
Practical Calculation Examples
Problem 1: divide subnet 172.16.0.0/22 into four equal subnets for departmental testing. Prefix /22 = 1024 addresses. Division into four yields /24 each (256 addresses per subnet). Result: 172.16.0.0/24, 172.16.1.0/24, 172.16.2.0/24, 172.16.3.0/24. During testing, each subnet is scanned separately with documented function, access control, and discovered vulnerabilities.
Problem 2: determine if hosts 10.20.30.50 and 10.20.31.100 reside in the same /23 subnet. Mask /23 = 255.255.254.0. Applying bitwise AND: both resolve to 10.20.30.0 network. Answer: yes, same subnet. This knowledge aids connectivity analysis, identifies potential direct communication paths, and determines whether traffic traverses routers or operates on shared layer-2 segments.
Tools and Calculation Automation
Calculation speed increases with tools: ipcalc (Linux), sipcalc, online subnet calculators, Python ipaddress module. Bash offers grep, awk, sed for IP manipulation. Automation through Python scripts generates host lists for scanning, validates address membership, aggregates results by segment, and identifies overlaps or gaps in coverage. CIDR notation simplifies batch operations on IP ranges.
Metasploit and Nmap accept CIDR notation for automatic range scanning. Python's ipaddress module provides: network host enumeration, subnet intersection testing, supernet calculation, and address validation. These capabilities streamline scanning plan generation, result analysis, and scope documentation. Automated validation catches configuration errors before scanning begins, ensuring scope accuracy.
Documentation and Reporting
Penetration test reports must clearly document tested subnets with CIDR notation, address counts, usable ranges, and discovered services. This demonstrates scope to stakeholders and provides justification for effort allocation. Explicit listing of exclusions (addresses not scanned per agreement) prevents disputes and clarifies test boundaries.
Report tables should include: subnet (CIDR), total addresses, active hosts, segment function, vulnerabilities discovered. This structure enables management to assess risk per segment and prioritize remediation. Accurate subnet calculation and documentation enhance test credibility, facilitate client communication, and reduce post-test disputes regarding coverage and scope compliance.