CompTIA Network+ (N10-009)Networking ConceptsMedium

A network administrator is setting up a new firewall and needs to block all traffic originating from a specific range of internal IP addresses (10.0.0.10 to 10.0.0.15) while allowing all other internal traffic. Which of the following wildcard masks would correctly identify this range for a firewall rule?

  1. A0.0.0.15
  2. B0.0.0.7
  3. C255.255.255.240
  4. D0.0.0.0
Show answer & explanation

Correct answer: B. 0.0.0.7

A wildcard mask uses binary zeros to match a corresponding bit and binary ones to ignore it. To match the range 10.0.0.10 to 10.0.0.15, which are 00001010 to 00001111 in binary for the last octet, the first five bits (00001) must match, and the last three bits (010 to 111) can vary. Therefore, the wildcard mask needs to have 0s for the first five bits and 1s for the last three bits, which is 00000111 in binary, or 7 in decimal.

Why the other options are wrong

  • A. This wildcard mask would allow for a larger range (up to 16 addresses) than specified, not precisely 10.0.0.10 to 10.0.0.15.
  • C. This is a subnet mask, not a wildcard mask, and its inverse (0.0.0.15) would identify a different range or purpose.
  • D. This wildcard mask would only match a single host address, not a range.

Wildcard Mask

A 32-bit number used in Access Control Lists (ACLs) to specify which bits of an IP address should be matched (0) and which bits should be ignored (1).

  • Used to match a range of IP addresses or specific hosts.
  • Inverse of a subnet mask; 0 means 'match this bit', 1 means 'ignore this bit'.
  • Commonly seen in Cisco router ACLs and OSPF area configurations.

Memory trick: Wild cards IGNORE the ones, MATCH the zeros.

More Networking Concepts questions