In this topic, we will talk about network subnet in an Azure VNet. We try to understand what Class or Size of the network we need to select and how we configure it using the Azure Portal or PowerShell.

What is a Subnet?

A subnet is an IP network in which addresses point to on the same group, and it is a part of a larger network which is divided into smaller subnets.

Private Networks

Private is a Network that uses a private space of addresses. These addresses are used ONLY in
Local Area Networks (LAN).

Network Classes

There are three classes of networks that can we use to create private subnets, and these are A,B, and C.

At the table below we can see the defined RFC 1918 address spaces.

Range of IP addressesClass of NetworksNumber of Networks – – –

The next table shows the Networks, Hosts, and the default Network Masks for Private Networks (A,B, and C)

Class of AddressSize of Network Part(bits)Size of Host Part(bits)Default Network Mask For Each Class


It is very important to understand CIDR (Classless Inter-Domain Routing) notation. This is the number of the subnet mask bits. For example, means that the three first octets are part of the network and
the remaining are for the hosts.



is the procedure of dividing a network into smaller networks (subnets) or smaller groups of IP addresses.

To understand subnetting we must be familiar with binary math, and more specific with the procedure to convert binary to decimal and vice versa.

The table below is the AND logic table and it can help us with the subnetting process.

0 AND 0 = 0
0 AND 1 = 0
1 AND 0 = 0
1 AND 1 = 1


The following example refers to general guidelines for subnetting.

CIDR (Classless Inter-Domain Routing)

In this part of the post will try to discover the CIDR notation for a C Class IP Address.

For example

  • IP Address:
  • Subnet Mask:

Convert Decimal to Binary 

We can read how to convert Decimal to Binary in this

Subnet Mask 


The last octet is 00000000, that means that the Mask Bits are
24, which means that the CIDR is ( /24 )

In this example, the host address range will be –, with
broadcast IP address


Azure VNet Subnet Demo

Before we move on to the demo, it’s good to read the following MS
about Azure VNet’s.

For the demo purposes we suppose that we want to create 4 subnets, these are:

  • DMZ (Virtual Network Appliance)
  • Front End (Web Server)
  • Business (Application Server)
  • Back End (Database Server)

Deployment Steps

At the following steps, we will see how easily deploy the previous image architecture.

Create A Resource Group

From the Azure Portal left main pane select Resource Groups and click
+ Add

In the new pane fill in the necessary fields and click the button Review + Create

Resource groupType a valid name for the Resource group
RegionSelect a region to create the Resource group

Review the Resource group settings and click Create, as the image below shows.

Create a Virtual Network

Step 1: Create a Virtual Network

In the first step in the Create virtual network deployment blade, we must fill up the required fields.

NameType a name for the VNet
Address spaceType a valid address range in CIDR notation
SubscriptionSelect a valid subscription
Resource groupSelect Create new, or an existing Resource Group
LocationSelect the location where the VNet will be created
NameType a subnet name
Address rangeType a valid address range for the subnet*
DDos protectionAzure DDoS basic protection is integrated into the Azure platform by default and at no additional cost.
Service endpointsEnable one or more service endpoints for this subnet
FirewallAzure Firewall is a managed cloud-based network security service that protects your Azure Virtual Network resources


*The subnet’s address range in CIDR notation (e.g. It must be contained by the address space of the virtual network. The address range of a subnet which is in use can’t be edited.

Step 2: Create Virtual Network Subnets

At the second step, we will create the other 3 subnets, Front-End, Business, and Back-End subnets.

The next step should be repeated for each subnet

From the Virtual Network left main blade, select Settings
, and click + Subnet.

Type a valid subnet Name, a valid Address range and click

At the end of Step 2, we are able to see 4 subnets into the VNet (See the image below).

Network Diagram

We can also see the Network Diagram.

From the left Virtual Network main blade, select Monitoring
Diagram, and then we are able to see the Network Diagram of the virtual network, as the image below shows.


In this post, we talk about Subnets, Subnetting, Azure Virtual Network, VNet Subnet and we deploy to Azure a common scenario for an On-Premise infrastructure.

See Also


Share This