Glossary

Networking

Subnet

A contiguous block of IP addresses managed as a unit, often shared reputation and all.

A subnet is a contiguous block of IP addresses carved out of a larger allocation and administered as one unit. It is written in CIDR notation, where the number after the slash says how much of the address is fixed: a /24 fixes the first 24 bits and leaves 256 addresses, a /16 leaves 65,536, and a /32 is one single address. Smaller number, bigger block.

That notation is worth being able to read, because it is the vocabulary in which blocking decisions are expressed. When a site bans a /24 it has removed 256 addresses in one rule, and it did not have to know or care which of them was the problem.

Addresses in one subnet generally share an owner, a physical location and, decisively, a reputation. Reputation systems frequently score at block level precisely because it is cheap and usually right: whoever controls a range controls everything in it, so behaviour within a block is genuinely correlated. That is a reasonable inference, and it is also why an address can be penalised for what its neighbours did.

The consequence for anyone buying proxies is that address-level thinking misleads you. A fresh address inside an abused range arrives already suspect. A newly announced clean range gives every address in it a clean start. Neither outcome had anything to do with the individual IP you were sold.

So subnet diversity is a quality signal that sits underneath pool size and rarely gets advertised. A thousand addresses spread across many blocks survive a block-level ban that would remove a thousand addresses crammed into one. The block is the unit that gets blocked, so the block is the unit worth counting.

It nests with the ASN too, and the two answer different questions. The autonomous system tells you which ORGANISATION owns the space, which drives the residential-or-hosted classification. The subnet tells you which specific slice of that organisation's space you are in, which drives how far the consequences of one address's behaviour spread. A pool can look diverse by ASN and still be concentrated into a few blocks inside each one.

Frequently asked questions

What does /24 mean in an IP range?

It is CIDR notation stating how many leading bits are fixed. A /24 fixes 24 of the 32 bits, leaving 8 bits and therefore 256 addresses. A /16 leaves 65,536, and a /32 is a single address. The smaller the number after the slash, the larger the block, which is why a /16 ban is far more sweeping than a /24 ban.

Can a whole subnet be blocked at once?

Routinely, and that is exactly why it matters. Blocking a range is one rule instead of hundreds, so a site facing abuse from several addresses in a block will often just remove the block. Anyone else in it loses access without having done anything, which is the mechanism behind a clean new address arriving already blocked.

Does subnet diversity matter more than pool size?

For resilience, yes. Ten thousand addresses inside a handful of blocks can be removed by a handful of rules, while the same count spread widely has no single point of failure. Pool size tells you how much supply exists; subnet spread tells you how much of it can disappear at once.

How is a subnet different from an ASN?

They answer different questions and nest inside each other. The ASN identifies the organisation that owns and routes the address space, which is what drives the residential-versus-hosted classification. The subnet is a specific block inside that space, which is what drives how widely one address's reputation spreads. A pool can be diverse by ASN and still concentrated by subnet.

Back to the full glossary.

HProxy.

Ready when you are.Your dashboard is ten seconds away.

Get Startedor talk to us at support@hproxy.com
HProxy