IPv4 and IPv6: prefixes, subnets and the default gateway
How an address splits into a prefix and a host part, why a prefix boundary can fall inside an octet, and what the default gateway actually does in IPv4 and IPv6.

An IP address carries two meanings at once: a prefix that names the network, and a host part that numbers a system on it. The prefix length, written /n, marks the boundary between the two — a bit position, not an octet. If the destination sits inside the host’s own prefix the packet stays on the link; if it does not, the host hands it to the default gateway, a router on the same link. IPv6 keeps that split and that default-gateway role with a 128-bit address, a /64 LAN convention and no broadcast.
The model: an address is a prefix plus a host part
RFC 791 describes an IPv4 address as a network number followed by a “local address” — its “rest” field: one number with two roles (RFC 791, §3.1). CIDR makes that division explicit and adjustable (RFC 4632, §3.1): the prefix length gives the number of leftmost bits that identify the network, and the remaining bits number the systems on it. A /16 leaves 16 host bits; a /24 leaves 8. The subnet mask is the same boundary written as bits — the first n bits ones, the rest zeros. The host part differs per device; the prefix is what other networks route towards.
Terms
- Prefix and prefix length — the network bits, written
/nin CIDR notation. - Host part — the remaining bits; one value per interface.
- Subnet mask — the same boundary expressed as a dotted mask instead of a slash.
- On-link — reachable without a router.
- Default gateway — the next-hop router used for every off-link destination.
Local or gateway: the one decision a host makes
A host compares the destination address with its own prefix. Inside the prefix, it resolves the link-layer address of the destination and sends the frame directly. Outside, it sends the frame to the default gateway — a router on the same link whose job is to forward datagrams between networks (RFC 791, §2.4). Only the gateway’s own address has to be reachable locally; the rest of the path is decided hop by hop, by each router in turn. The destination address never changes in transit; only the link-layer header is rewritten per hop. Two consequences follow: the gateway must sit on a network the host can already reach, and changing a host’s address without updating its gateway breaks every off-link destination.
Why the prefix boundary is a bit, not a dot
Dotted decimal groups an address into four eight-bit octets, which tempts the reader to assume the prefix always ends on a dot. It does not. A /26 boundary falls two bits inside the fourth octet, so it splits a single decimal group between network and host. That is the point of classless addressing: a prefix can describe any power-of-two block, not only the old fixed class sizes.
The prefix boundary is a bit position, not a dot — one address, two prefixes:
└────────────────────────────┘└─────────┘ /24 network ends at the 3rd dot
└───────────────────────────────┘└──────┘ /26 network extends 2 bits into the 4th octet
▲
the 4th octet splits: 2 network bits, 6 host bits
Splitting the documentation block 198.51.100.0/24 with a /26 gives four blocks:
| Prefix | Range |
|---|---|
| 198.51.100.0/26 | 198.51.100.0 – 198.51.100.63 |
| 198.51.100.64/26 | 198.51.100.64 – 198.51.100.127 |
| 198.51.100.128/26 | 198.51.100.128 – 198.51.100.191 |
| 198.51.100.192/26 | 198.51.100.192 – 198.51.100.255 |
IPv6: the same split, a wider address
IPv6 keeps the prefix-plus-host model and changes the size and the machinery:
- 128 bits instead of 32, to support far more nodes and deeper hierarchy (RFC 8200, §1).
- A
/64convention. Typical unicast interface identifiers are 64 bits, so a normal subnet uses a/64prefix (RFC 4291, §2.5.1). - No broadcast. Its function is taken over by multicast (RFC 4291, §2).
- Neighbor Discovery instead of ARP. Address resolution, router discovery and redirects are combined into ICMPv6 Neighbor Discovery (RFC 4861, §3.1), so there is no ARP table and no separate netmask mechanism.
What does not change: an IPv6 address is still a prefix plus an interface identifier, which plays the role of the host part; off-link traffic still goes to a default gateway on the local link; forwarding is still hop by hop. Address autoconfiguration (SLAAC) and duplicate-address detection build on Neighbor Discovery — related subjects, not developed here.
Common misconceptions and limits
- The gateway is not a “tunnel to the internet”. It is one router on the local link; a packet may cross many unrelated routers after it. That framing hides the hop-by-hop reality.
- An IP address does not identify a device. Addresses are assigned to interfaces, not devices (RFC 4291, §2.1); one machine can hold several, they can be reassigned over time, and NAT lets many hosts share one public address. An address says where to deliver a packet now, not who owns the hardware.
- Non-routable is not secure. Private ranges exist to conserve global space (RFC 1918), not as a security control: RFC 1918 itself notes that private hosts can still reach external services through mediating gateways, and non-routability says nothing about traffic already inside the network.
- Newer is not automatically safer. IPv6 changes address size, discovery and header handling; it does not remove the need to filter traffic, control the default gateway and monitor the network.
Level and prerequisites. L1 — fundamentals. No configuration experience required; knowing that a device has an IP address is enough.
Where to go next
- Networking — the area this sheet belongs to.
References
- RFC 791 — Internet Protocol (network number and “rest” field, §3.1; gateways, §2.4).
- RFC 4632 — CIDR: prefix notation and masks (§3.1).
- RFC 8200 — IPv6 specification (128-bit addressing, §1).
- RFC 4291 — IPv6 Addressing Architecture (interface identifiers, §2.5.1; no broadcast, §2; addresses on interfaces, §2.1).
- RFC 4861 — Neighbor Discovery for IPv6 (comparison with IPv4, §3.1).
- RFC 5737 — IPv4 address blocks reserved for documentation.
- RFC 1918 — Address allocation for private internets.