Practice Questions - Subnetting -1

 

Subnetting is one of the most important concepts in computer networking and a must-have skill for network engineers, cybersecurity professionals, and IT students. It helps in dividing a large IP network into smaller, manageable sub-networks, improving performance, security, and efficient IP address utilization.
In this blog series, you will learn subnetting step-by-step with simple explanations, real examples, and hands-on practice questions.


Question #1

What is the range of assignable IP addresses for a subnet containing an IP address of 172.16.1.10 /19?

a. 172.16.0.1 – 172.16.31.254

b. 172.16.0.1 – 172.16.63.254

c. 172.16.0.0 – 172.16.31.255

d. 172.16.0.1 – 172.16.31.255

e. 172.16.0.0 – 172.16.63.254

Question #2

You are assigning IP addresses to hosts in the 192.168.4.0 /26 subnet. Which two of the following IP addresses are assignable IP addresses that reside in that subnet?

a. 192.168.4.0

b. 192.168.4.63

c. 192.168.4.62

d. 192.168.4.32

e. 192.168.4.64

Question #3

A host in your network has been assigned an IP address of 192.168.181.182 /25. What is the subnet to which the host belongs?

a. 192.168.181.128 /25

b. 192.168.181.0 /25

c. 192.168.181.176 /25

d. 192.168.181.192 /25

e. 192.168.181.160 /25

Question #4

You are working with a Class B network with the private IP address of 172.16.0.0 /16. You need to maximize the number of broadcast domains, where each broadcast domain can accommodate 1000 hosts. What subnet mask should you use?

a. /22

b. /23

c. /24

d. /25

e. /26

Question #5

What is the directed broadcast address of a subnet containing an IP address of 172.16.1.10 /19?

a. 172.16.15.255

b. 172.16.31.255

c. 172.16.255.255

d. 172.16.95.255

e. 172.16.0.255

Question #6

A customer is using a Class C network of 192.168.10.0 subnetted with a 28-bit subnet mask. How many subnets can be created by using this subnet mask?

a. 32

b. 16

c. 30

d. 8

e. 14

Question #7

Given a subnet of 172.16.56.0 /21, identify which of the following IP addresses belong to this subnet. (Select 2.)

a. 172.16.54.129

b. 172.16.62.255

c. 172.16.61.0

d. 172.16.65.255

e. 172.16.64.1

Question #8

What is the subnet address of the IP address 192.168.5.55 with a subnet mask of 255.255.255.224?

a. 192.168.5.0 /27

b. 192.168.5.16 /27

c. 192.168.5.32 /27

d. 192.168.5.48 /27

e. 192.168.5.64 /27



Question #9

You are working for a company that will be using the 192.168.1.0 /24 private IP address space for IP addressing inside their organization.

They have multiple geographical locations and want to carve up the 192.168.1.0 /24 address space into subnets. Their largest subnet will need 13 hosts.

What subnet mask should you use to accommodate at least 13 hosts per subnet, while maximizing the number of subnets that can be created?

a. 255.255.255.248

b. 255.255.255.224

c. 255.255.255.252

d. 255.255.255.192

e. 255.255.255.240

Question #10

A customer is using a Class C network of 192.168.10.0 subnetted with a 28-bit subnet mask. How many assignable addresses are available in each of the subnets?

a. 32

b. 16

c. 30

d. 8

e. 14

Question #11

An IP address of 192.168.0.100 /27 belongs to which of the following subnets?

a. 192.168.0.92

b. 192.168.0.128

c. 192.168.0.64

d. 192.168.0.96

e. 192.168.0.32

Question #12

What subnet mask should be used to subnet the 192.168.10.0 network to support the number of subnets and IP addresses per subnet shown in the following topology?



a. 255.255.255.0

b. 255.255.255.128

c. 255.255.255.192

d. 255.255.255.224

e. 255.255.255.240





Solutions

Question #1

What is the range of assignable IP addresses for a subnet containing an IP address of 172.16.1.10 /19?

a. 172.16.0.1 – 172.16.31.254

b. 172.16.0.1 – 172.16.63.254

c. 172.16.0.0 – 172.16.31.255

d. 172.16.0.1 – 172.16.31.255

e. 172.16.0.0 – 172.16.63.254

Answer: a

To determine the subnets, assignable IP address ranges, and directed broadcast addresses created by the 19-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 19-bit subnet mask, which is written in binary as:

11111111 11111111 11100000 00000000

The interesting octet is the third octet, because the third octet (i.e. 11100000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 19-bit subnet mask can be written in dotted decimal notation as: 255.255.224.0

Since the third octet is the interesting octet, the decimal value in the interesting octet is 224.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 224 = 32

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

172.16.0.0/19

We then count by the block size (of 32) in the interesting octet (the third octet in this question) to determine the remaining subnets:

172.16.32.0 /19

172.16.64.0 /19

172.16.96.0 /19

172.16.128.0 /19

172.16.160.0 /19

172.16.192.0 /19

172.16.224.0 /19

Step #5: Identify the subnet address, the directed broadcast address, and the usable range of addresses.

Looking through the subnets created by the 19-bit subnet mask reveals that the IP address of 172.16.1.10 resides in the 172.16.0.0 /19 subnet.

The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet address.

The next subnet address is 172.16.32.0. So, the directed broadcast address for the 172.16.0.0 /19 subnet is 1 less than 172.16.32.0, which is:

172.16.31.255

The usable IP addresses are all the IP addresses between the subnet address and the directed broadcast address. Therefore, in this example, the assignable IP address range for the 172.16.0.0 /19 network is:

172.16.0.1 – 172.16.31.254

Question #2

You are assigning IP addresses to hosts in the 192.168.4.0 /26 subnet. Which two of the following IP addresses are assignable IP addresses that reside in that subnet?

a. 192.168.4.0

b. 192.168.4.63

c. 192.168.4.62

d. 192.168.4.32

e. 192.168.4.64

Answer: c and d

To determine subnets and usable address ranges created by the 26-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 26-bit subnet mask, which is written in binary as:

11111111 11111111 11111111 11000000

The interesting octet is the forth octet, because the forth octet (i.e. 11000000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 26-bit subnet mask can be written in dotted decimal notation as: 255.255.255.192

Since the forth octet is the interesting octet, the decimal value in the interesting octet is 192.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 192 = 64

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

192.168.4.0 /26

We then count by the block size (of 64) in the interesting octet (the forth octet in this question) to determine the remaining subnets:

192.168.4.64 /26

192.168.4.128 /26

192.168.4.192 /26

Step #5:

This question is asking about the 192.168.4.0 /26 subnet. From the above list of subnets, we can determine that the assignable range of IP addresses for this subnet is 192.168.4.1 – 192.168.4.62. We can also determine that 192.168.4.0 is the network address, and 192.168.4.63 is the directed broadcast address.

From the assignable range of IP addresses we have calculated, we can determine that the two assignable IP addresses given as options in this question are: 192.168.4.62 and 192.168.4.32.

Question #3

A host in your network has been assigned an IP address of 192.168.181.182 /25. What is the subnet to which the host belongs?

a. 192.168.181.128 /25

b. 192.168.181.0 /25

c. 192.168.181.176 /25

d. 192.168.181.192 /25

e. 192.168.181.160 /25

Answer: a

To determine subnets and usable address ranges created by the 25-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 25-bit subnet mask, which is written in binary as:

11111111 11111111 11111111 10000000

The interesting octet is the forth octet, because the forth octet (i.e. 10000000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 25-bit subnet mask can be written in dotted decimal notation as: 255.255.255.128

Since the forth octet is the interesting octet, the decimal value in the interesting octet is 128.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 128 = 128

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

192.168.181.0 /25

We then count by the block size (of 128) in the interesting octet (the forth octet in this question) to determine the remaining subnets, or in this case just a single additional subnet


192.168.181.128 /25

Now that we have our two subnets identified, we can determine the subnet in which the IP address of 192.168.181.182 resides.

Since the usable range of IP addresses for the 192.168.181.128 /25 network is 192.168.181.129 – 192.168.181.254 (because 192.168.181.128 is the network address, and 192.168.181.255 is the directed broadcast address), and since 192.168.181.182 is in that range, the subnet to which 192.168.181.182 /25 belongs is:

192.168.181.128 /25

Question #4

You are working with a Class B network with the private IP address of 172.16.0.0 /16. You need to maximize the number of broadcast domains, where each broadcast domain can accommodate 1000 hosts. What subnet mask should you use?

a. /22

b. /23

c. /24

d. /25

e. /26

Answer: a

In addition to testing your knowledge of subnetting, this question is also making sure you understand that a subnet is a broadcast domain. This should not be confused with a collision domain (i.e. each port on a switch is in its own collision domain).

To determine how many host bits are required to support 1000 hosts, we can create a table from the following formula:

Number of Hosts = 2h – 2, where h is the number of host bits

From this formula, we can create the following table:

1 Host Bit => 0 Hosts

2 Host Bits => 2 Hosts

3 Host Bits => 6 Hosts

4 Host Bits => 14 Hosts

5 Host Bits => 30 Hosts

6 Host Bits => 62 Hosts


7 Host Bits => 126 Hosts

8 Host Bits => 254 Hosts

9 Host Bits => 510 Hosts

10 Host Bits => 1022 Hosts

This table tells us that a subnet with 10 host bits will accommodate the requirement of 1000 hosts. If we have 10 host bits, then we have a 22-bit subnet mask (i.e. 32 – 10 = 22). Also, by not using more host bits than we need, we are maximizing the number of subnets that can be created.

Question #5

What is the directed broadcast address of a subnet containing an IP address of 172.16.1.10 /19?

a. 172.16.15.255

b. 172.16.31.255

c. 172.16.255.255

d. 172.16.95.255

e. 172.16.0.255

Answer: b

To determine the subnets, assignable IP address ranges, and directed broadcast addresses created by the 19-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 19-bit subnet mask, which is written in binary as:

11111111 11111111 11100000 00000000

The interesting octet is the third octet, because the third octet (i.e. 11100000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 19-bit subnet mask can be written in dotted decimal notation as: 255.255.224.0

Since the third octet is the interesting octet, the decimal value in the interesting octet is 224.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.


Block Size = 256 – 224 = 32

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

172.16.0.0 /19

We then count by the block size (of 32) in the interesting octet (the third octet in this question) to determine the remaining subnets:

172.16.32.0 /19

172.16.64.0 /19

172.16.96.0 /19

172.16.128.0 /19

172.16.160.0 /19

172.16.192.0 /19

172.16.224.0 /19

Step #5: Identify the subnet address, the directed broadcast address, and the usable range of addresses.

Looking through the subnets created by the 19-bit subnet mask reveals that the IP address of 172.16.1.10 resides in the 172.16.0.0 /19 subnet.

The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet address.

The next subnet address is 172.16.32.0. So, the directed broadcast address for the 172.16.0.0 /19 subnet is 1 less than 172.16.32.0, which is:

172.16.31.255

The usable IP addresses are all the IP addresses between the subnet address and the directed broadcast address. Therefore, in this example, the assignable IP address range for the 172.16.0.0 /19 network is:

172.16.0.1 – 172.16.31.254

Question #6

A customer is using a Class C network of 192.168.10.0 subnetted with a 28-bit subnet mask. How many subnets can be created by using this subnet mask?

a. 32

b. 16

c. 30

d. 8


e. 14

Answer: b

The subnet in this question is a Class C network, because there is a 192 in the first octet. A class C network has a natural mask of 24 bits. However, this network has a 28-bit subnet mask. Therefore, we have 4 borrowed bits, which are network bits added to a network’s natural mask (i.e. 28 – 24 = 4). The number of subnets can be calculated as follows:

Number of Subnets = 2s, where s is the number of borrowed bits.

Therefore, in this question, the number of created subnets is 16:

Number of Subnets = 24 = 16

Question #7

Given a subnet of 172.16.56.0 /21, identify which of the following IP addresses belong to this subnet. (Select 2.)

a. 172.16.54.129

b. 172.16.62.255

c. 172.16.61.0

d. 172.16.65.255

e. 172.16.64.1

Answer: b, c

To determine subnets and usable address ranges created by the 21-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 21-bit subnet mask, which is written in binary as:

11111111 11111111 11111000 00000000

The interesting octet is the third octet, because the third octet (i.e. 11111000) is the first octet to contain a 0 in the binary subnet mask.

Step #2: Identify the decimal value in the interesting octet of the subnet mask. A 21-bit subnet mask can be written in dotted decimal notation as: 255.255.248.0


Since the third octet is the interesting octet, the decimal value in the interesting octet is 248.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 248 = 8

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

172.16.0.0 /21

We then count by the block size (of 8) in the interesting octet (the third octet in this question) to determine the remaining subnets:

172.16.8.0 /21 172.16.16.0 /21 172.16.24.0 /21 172.16.32.0 /21 172.16.40.0 /21 172.16.48.0 /21 172.16.56.0 /21 172.16.64.0 /21 ... SUBNETS OMITTED ...

We can stop counting after we pass the subnet we are being asked about. Specifically, in this question, we’re being asked about 172.16.56.0 /21.

Step #5: Identify the subnet address, the directed broadcast address, and the usable range of addresses.

The subnet address, where all host bits are set to a 0, is given:

172.16.56.0 /24

The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet address.

The next subnet address is 172.16.64.0. So, the directed broadcast address for the 172.16.54.0 /21 subnet is 1 less than 172.16.64.0, which is: 172.16.63.255

The usable IP addresses are all the IP addresses between the subnet address and the directed broadcast address. Therefore, in this example, the usable IP address range for the 172.16.56.0 /21 network is:

172.16.56.1 – 172.16.63.254

The only IP addresses in this question that reside in this range are:

172.16.62.255 172.16.61.0

WARNING: Many CCNA R&S candidates look at IP addresses like these and immediately assume they are not usable IP addresses, because they have a 0 or a 255 in the forth octet. They argue that 172.16.61.0 is a subnet address and that 172.16.62.255 is a directed broadcast address.

While that would only be true of the subnet mask were 24-bits, remember that, by definition, a subnet address has all of its host bits set to a 0, and a directed broadcast address has all of its host bits set to a 1. In this question, we have 11 host bits (i.e. 32 – 21 = 11), not 8 host bits. So, 172.16.62.255 and 172.16.61.0 are actually usable IP addresses.

Question #8

What is the subnet address of the IP address 192.168.5.55 with a subnet mask of 255.255.255.224?

a. 192.168.5.0 /27

b. 192.168.5.16 /27

c. 192.168.5.32 /27

d. 192.168.5.48 /27

e. 192.168.5.64 /27

Answer: c

To determine subnets and usable address ranges created by the 27-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 27-bit subnet mask, which is written in binary as:

11111111 11111111 11111111 11100000

The interesting octet is the forth octet, because the forth octet (i.e. 11100000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 27-bit subnet mask can be written in dotted decimal notation as: 255.255.255.224


Since the forth octet is the interesting octet, the decimal value in the interesting octet is 224.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 224 = 32

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

192.168.5.0 /27

We then count by the block size (of 32) in the interesting octet (the forth octet in this question) to determine the remaining subnets:

192.168.5.32 /27

192.168.5.64 /27

192.168.5.96 /27

192.168.5.128 /27

192.168.5.160 /27

192.168.5.192 /27

192.168.5.224 /27

Now that we have all of our subnets identified, we can determine the subnet in which the IP address of 192.168.5.55 resides.

Since the usable range of IP addresses for the 192.168.5.32 /27 network is 192.168.5.33 – 192.168.5.62 (because 192.168.5.32 is the network address, and 192.168.5.63 is the directed broadcast address), and since 192.168.5.55 is in that range, the subnet to which 192.168.5.55 /27 belongs is:

192.168.5.32 /27

Question #9

You are working for a company that will be using the 192.168.1.0 /24 private IP address space for IP addressing inside their organization.

They have multiple geographical locations and want to carve up the 192.168.1.0 /24 address space into subnets. Their largest subnet will need 13 hosts.

What subnet mask should you use to accommodate at least 13 hosts per subnet, while maximizing the number of subnets that can be created?

a. 255.255.255.248


b. 255.255.255.224

c. 255.255.255.252

d. 255.255.255.192

e. 255.255.255.240

Answer: e

We can determine the maximum number of hosts allowed in a subnet by raising the number 2 to the power of the number of host bits and then subtracting 2. So, the formula looks like this:

Maximum Number of Hosts per Subnet = 2h – 2, where h is the number of host bits.

Why are we subtracting two? Well, there are two IP addresses in the subnet that cannot be assigned. These addresses are: (1) the network address, where all of the host bits are set to a 0 and (2) the directed broadcast address, where all of the host bits are set to a 1.

In the actual exam, if you are given scratch paper or access to a note taking application, you might want to write out a table such as the following for your reference:

1 Host Bit: 21 – 2 = 0

2 Host Bits: 22 – 2 = 2

3 Host Bits: 23 – 2 = 6

4 Host Bits: 24 – 2 = 14

5 Host Bits: 25 – 2 = 30

6 Host Bits: 26 – 2 = 62

7 Host Bits: 27 – 2 = 126

8 Host Bits: 28 – 2 = 254

In this question, we’re asked to determine a subnet mask that accommodates at least 13 hosts per subnet. By looking at the reference table we created, we can see that 4 host bits (which support 14 hosts) would work, while 3 host bits (which supports only 6 hosts) would not be enough.

So, we need a subnet with 4 host bits, which are enough host bits to meet the design goal, but not more than we need. Using more host bits than we need would violate the requirement to maximize the number of subnets.

A subnet mask with 4 host bits has 28 network bits (i.e. 32 – 4 = 28), and therefore a 28-bit subnet mask. A 28-bit subnet mask can be written as:

255.255.255.240


Question #10

A customer is using a Class C network of 192.168.10.0 subnetted with a 28-bit subnet mask. How many assignable addresses are available in each of the subnets?

a. 32

b. 16

c. 30

d. 8

e. 14

Answer: e

An IPv4 address contains a total of 32 bits. Since, in this question, we have 28 subnet bits, the number of host bits is 4 (i.e. 32 – 28 = 4). The number of assignable IP addresses in a subnet can be calculated as follows:

Number of Assignable IP Addresses = 2h – 2, where h is the number of host bits.

Therefore, in this question, each subnet has 14 assignable IP addresses:

Number of Assignable IP Addresses = 24 – 2 = 16 – 2 = 14

Question #11

An IP address of 192.168.0.100 /27 belongs to which of the following subnets?

a. 192.168.0.92

b. 192.168.0.128

c. 192.168.0.64

d. 192.168.0.96

e. 192.168.0.32

Answer: d

To determine the subnets created by the 27-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 19-bit subnet mask, which is written in binary as:

11111111 11111111 11111111 11100000

The interesting octet is the forth octet, because the forth octet (i.e. 11100000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 27-bit subnet mask can be written in dotted decimal notation as: 255.255.255.224

Since the forth octet is the interesting octet, the decimal value in the interesting octet is 224.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 224 = 32

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

192.168.0.0 /27

We then count by the block size (of 32) in the interesting octet (the forth octet in this question) to determine the remaining subnets:

192.168.0.32 /27

192.168.0.64 /27

192.168.0.96 /27

192.168.0.128 /27

192.168.0.160 /27

192.168.0.192 /27

192.168.0.224 /27

Step #5: Identify the subnet address of the IP address 192.168.0.100 /27.

Looking through the subnets created by the 27-bit subnet mask reveals that the IP address of 192.168.0.100 resides in the 192.168.0.96 subnet.

Question #12

What subnet mask should be used to subnet the 192.168.10.0 network to support the number of subnets and IP addresses per subnet shown in the following topology?




a. 255.255.255.0

b. 255.255.255.128

c. 255.255.255.192

d. 255.255.255.224

e. 255.255.255.240

Answer: c

To meet the design requirements, four subnets must be created, and each subnet must accommodate a maximum of 50 IP addresses.

We can begin by creating a listing of how many subnets are created from different numbers of borrowed bits, using the formula:

Number of Subnets Created = 2n, where n is the number of borrowed bits

1 borrowed bits => 2 subnets

2 borrowed bits => 4 subnets

3 borrowed bits => 8 subnets

4 borrowed bits => 16 subnets

5 borrowed bits => 32 subnets

6 borrowed bits => 64 subnets

7 borrowed bits => 128 subnets

From this, we can see we need at least 2 borrowed bits to accommodate 4 subnets. However, we need to make sure the subnet will accommodate 50 IP addresses. To determine this, we can use the formula:

Number of IP Addresses = 2h – 2, where h is the number of host bits


If we have 2 borrowed bits (i.e. the minimum number of borrowed bits required for 4 subnets), we have 6 host bits (i.e. 8 – 2 = 6). From the above formula, we can determine the number of IP addresses supported by 6 host bits.

Number of IP Addresses = 26 – 2 = 62

Since 6 host bits meet our requirement of at least 50 IP addresses per subnet, we can use a 26-bit subnet mask (i.e. 2 bits added to the Class C default mask (also known as the natural mask) of 24 bits). A 26-bit subnet mask can be written as:

255.255.255.192




Best No-Code Website Builders for Small Business (2026)

 Best for design & custom control: Webflow (great if you want near-code control and a powerful CMS)

Best for easiest setup & AI help: Wix (AI site builder, lots of templates and marketing tools).

Best for polished templates & creators: Squarespace (beautiful templates, solid e-commerce and content tools).



Introduction

In 2026, small businesses no longer need to hire expensive developers to launch a high-quality website. No-code website builders empower entrepreneurs, consultants, and creators to go from idea to launch — fast, affordable, and with professional results. In this guide, we compare the top three platforms — Webflow, Wix, and Squarespace — so you can choose the right one for your business goals.

Whether you want a portfolio site, ecommerce store, or blog, this guide will help you understand which builder fits your needs and budget in 2026.

What “No-Code Website Builder” Means

A no-code website builder lets you design, build, and launch a website without writing traditional code like HTML, CSS, or JavaScript. Instead, you work with visual editors, drag-and-drop tools, and templates designed to make the process intuitive.

Benefits include:

  • Lower cost versus hiring developers

  • Faster launch — often within hours

  • Built-in hosting, security, and updates

  • Easy content updates without tech skills

Now let’s jump into the top options available in 2026.


Webflow no-code website builder example
Webflow no-code website builder example


Overview

no-code website builders for professionals

Webflow is a powerful visual builder that sits between basic drag-and-drop editors and custom code. It’s ideal for brands that want total design control, a robust CMS, and scalability.

Pros

  • Pixel-perfect visual editor

  • Powerful CMS and content modeling

  • Exportable HTML/CSS/JS (good for developers)

  • Strong SEO controls (meta tags, clean output)

Webflow no-code website builder example
Webflow no-code website builder example


Cons

  • Slightly steeper learning curve

  • Can be more expensive for advanced features

  • Templates require some design sense

Best For

  • Agencies, designers, and brands wanting professional quality

  • Businesses with complex content structures


Overview

Wix is one of the most beginner-friendly platforms available. With its AI Website Builder, you can generate a full site from answers to simple questions — ideal for entrepreneurs who want to launch fast.


 

Wix AI website builder dashboard
Wix AI website builder dashboard


Pros

  • AI builder that does heavy lifting

  • Huge template library

  • Excellent marketing tools and apps

  • Affordable entry-level plans

Cons

  • Less advanced design control vs Webflow

  • Can feel less “custom” if templates are used as-is

Best For

  • Solopreneurs, coaches, and small ecommerce shops

  • People who want fast setup without design headaches



🥉 Squarespace — Best for Polished Templates & Creators


Squarespace template for small busines
Squarespace template for small business

Squarespace template for small business
Squarespace template for small business


Feature Comparison Table

Feature Comparison Table

Feature Comparison Table


How to Choose the Right One (Step-by-Step)

Here’s a decision framework to help you pick:

❓ Step 1: What’s your priority?

  • Design control & scalability: Webflow

  • Fast and easy setup: Wix

  • Beautiful templates & simplicity: Squarespace

💰 Step 2: Budget

Most builders offer tiered pricing. Plan for:

  • Hosting included in monthly plan

  • Custom domain

  • Premium apps (forms, booking, ecommerce)

🚀 Step 3: Future plans

Think about:

  • ecommerce next year?

  • blog or membership content?

  • email marketing or SEO growth?



Choosing the right no-code website builder can transform your small business launch.

  • Webflow — best for custom design and professional control

  • Wix — fastest setup and AI help

  • Squarespace — polished templates and easy publishing

Pick one based on your goals and get your business online in less than a day.




Intrusion Prevention System - Course-Era Answers

 Intrusion Prevention System - Course-Era Fortinet Fortimanager answers

 

 

Which two types of traffic can be offloaded for acceleration to content processors (CP)? (Choose two.)

IPv6 traffic

SSL VPN traffic

Intrusion prevention system (IPS)-inspected traffic

Session helper traffic

 

 

 

Which custom intrusion prevention system (IPS) signature blocks only FTP passive mode requests?

F-SBID (--attack_id 1002; --name "Block.FTP; --protocol ftp; --flow from_client; -pattern “PASV”; --no_case;)

F-SBID (--attack_id 1002; --name "Block.FTP "; --protocol tcp; --service ftp; --flow from_client; --pattern "PASV"; --no_case;)

F-SBID (--attack_id 1002; --name "Block.PASV.FTP "; --protocol tcp; --dst_port 20; --flow from_client; --pattern "PASV"; --no_case;)

F-SBID (--attack_id 1002; --name "Block.PASV.FTP "; --protocol tcp; --flow from_client; --pattern "PASV"; --no_case;)

 

 

config ips global

set nps-accel-mod basic

end

Which two types of traffic will be offloaded to the network processor (NP)? (Choose two.)

 

IPsec phase 2 and hashing

Pre-intrusion prevention system (IPS) anomaly filtering

SSL encryption and decryption

Antivirus

 

 

When creating custom intrusion prevention system (IPS) signatures, which two options are required? (Choose two.)

 

 

--name

--protocol

--severity

–service

 

 

Which two scenarios can you block using FortiGuard intrusion prevention system (IPS) signatures? (Choose two.)

 

 

Traffic with protocol anomalies

Propagation of zero-day malware

Traffic exploiting known vulnerabilities

Traffic from invalid URLs

 


How to Deploy an Intrusion Prevention System (IPS): A Practical Guide

 How to Deploy an Intrusion Prevention System (IPS): A Practical Guide




Deploying an Intrusion Prevention System (IPS) isn’t just a technical requirement—it’s a strategic step toward strengthening your organization’s overall security posture. An IPS can proactively detect and block threats before they impact business operations.
But to make an IPS effective, you need a structured approach.


🔍 1. Analysis Phase – Laying the Foundation

Before touching any tools or configurations, it’s important to understand your environment.

✔️ Define what to protect

Identify critical assets such as servers, applications, sensitive data, and network segments.

✔️ Define and classify threats

Map potential attacks that could target your environment—malware, brute-force attacks, DDoS, insider threats, etc.

✔️ Define where IPS should be deployed

Decide optimal placement—at the perimeter, data center core, internal segments, or cloud environments.

This phase ensures clarity, helping you deploy an IPS with precision instead of guesswork.



🧪 2. Evaluation Phase – Monitor, Learn, Adjust

Once planning is complete, the next step is controlled deployment.

✔️ Configure the IPS in monitoring mode

Start by letting the IPS observe traffic without actively blocking. This prevents disruption while you learn the baseline behavior.

✔️ Monitor logs continuously

Review alerts, understand traffic patterns, and identify unusual events.

✔️ Detect false positives and false negatives

This is where the real tuning happens.

  • False positives? The IPS flags legitimate traffic as malicious.

  • False negatives? The IPS misses real threats.

✔️ Tune the IPS

Refine signatures, adjust policies, update rules, and whitelist legitimate activities.

This loop may run several times until the IPS accurately distinguishes between normal and malicious traffic.



🔧 3. Maintenance Phase – Ongoing Optimization

Deploying an IPS is not a “set it and forget it” activity.

✔️ Configure IPS for full protection

Once monitoring results are stable, enable prevention mode to actively block threats.

✔️ Periodically monitor logs

Threat landscapes evolve, and so must your policies.

✔️ Re-evaluate false positives/negatives

Tune the IPS regularly to maintain accuracy and reduce noise.

✔️ Continuous improvement

Regular updates, patch management, policy reviews, and threat intelligence integration keep your IPS relevant and effective.



💡 Final Thoughts

An IPS is powerful, but only when deployed strategically.
Following a structured lifecycle—Analyze → Evaluate → Maintain—helps ensure:

✔️ Accurate threat detection
✔️ Minimal false alarms
✔️ No impact on business operations
✔️ Long-term security resilience

Implementing an IPS isn’t just about installing a device; it’s about building a living security mechanism that adapts to your environment.

If you’re planning to deploy or optimize your IPS setup, this framework is a great place to start!


BGP Routing Protocol Practice Lab 01

 

BGP Routing Protocol Practice Lab 01



Lab 1: MED and AS-Path Prepend


Basic configuration

R1:

interface Loopback0

ip address 1.1.1.1 255.255.255.255

!

interface FastEthernet0/0 
ip address 150.1.1.1 255.255.255.0
 no shut

!

interface Serial0/0

ip address 10.0.0.1 255.255.255.252

no shut

R2:

interface Loopback0

ip address 2.2.2.2 255.255.255.255

!

interface Loopback192

ip address 192.1.1.1 255.255.255.0

!

interface Loopback193

ip address 193.1.1.1 255.255.255.0

!

interface Loopback194

ip address 194.1.1.1 255.255.255.0

!

interface Loopback195

ip address 195.1.1.1 255.255.255.0

!

interface Serial0/0

ip address 10.0.0.2 255.255.255.252

no shut !

interface Serial0/1

ip address 10.0.0.9 255.255.255.252

no shut



R3:

interface Loopback0

ip address 3.3.3.3 255.255.255.255

!

interface FastEthernet0/0 ip address 150.3.3.3 255.255.255.0 no shut

!

interface Serial0/1

ip address 10.0.0.10 255.255.255.252

no shut !

interface Serial0/2

ip address 10.0.0.13 255.255.255.252

no shut !

interface Serial0/3

ip address 10.0.0.17 255.255.255.252

no shut




R4:


interface Loopback0

ip address 4.4.4.4 255.255.255.255

!

interface FastEthernet0/0 ip address 150.1.1.4 255.255.255.0 no shut

!

interface Serial0/0

ip address 10.0.0.14 255.255.255.252

no shut !

interface Serial0/1

ip address 10.0.0.18 255.255.255.252

no shut




Configure BGP as illustrated in the topology. Use the Loopback 0 addresses for peering. Do NOT configure any IGPs. Instead, use static routes only. R1 should peer with R2 and R4. R2 should peer with R1 and R3. R3 should peer with R2 and R4. R4 should peer with R1 and R3.



R1(config)#ip route 2.2.2.2 255.255.255.255 serial 0/0

R1(config)#ip route 4.4.4.4 255.255.255.255 fastethernet 0/0 150.1.1.4

R1(config)#router bgp 1

R1(config-router)#neighbor 2.2.2.2 remote-as 2

R1(config-router)#neighbor 2.2.2.2 update-source loopback 0

R1(config-router)#neighbor 2.2.2.2 ebgp-multihop 3

R1(config-router)#neighbor 4.4.4.4 remote-as 4

R1(config-router)#neighbor 4.4.4.4 update-source loopback 0

R1(config-router)#neighbor 4.4.4.4 ebgp-multihop 3



R2(config)#ip route 1.1.1.1 255.255.255.255 serial 0/0

R2(config)#ip route 3.3.3.3 255.255.255.255 serial 0/1

R2(config)#router bgp 2

R2(config-router)#neighbor 1.1.1.1 remote-as 1

R2(config-router)#neighbor 1.1.1.1 update-source loopback 0

R2(config-router)#neighbor 1.1.1.1 ebgp-multihop 3

R2(config-router)#neighbor 3.3.3.3 remote-as 3

R2(config-router)#neighbor 3.3.3.3 update-source loopback 0

R2(config-router)#neighbor 3.3.3.3 ebgp-multihop 3




R3(config)#ip route 2.2.2.2 255.255.255.255 serial 1/1

R3(config)#ip route 4.4.4.4 255.255.255.255 serial 1/2

R3(config)#ip route 4.4.4.4 255.255.255.255 serial 1/3

R3(config)#router bgp 3

R3(config-router)#neighbor 2.2.2.2 remote-as 2

R3(config-router)#neighbor 2.2.2.2 update-source loopback 0

R3(config-router)#neighbor 2.2.2.2 ebgp-multihop 3

R3(config-router)#neighbor 4.4.4.4 remote-as 4

R3(config-router)#neighbor 4.4.4.4 update-source loopback 0

R3(config-router)#neighbor 4.4.4.4 ebgp-multihop 3




R4(config)#ip route 1.1.1.1 255.255.255.255 fastethernet 0/0 150.1.1.1

R4(config)#ip route 3.3.3.3 255.255.255.255 serial 0/0

R4(config)#ip route 3.3.3.3 255.255.255.255 serial 0/1

R4(config)#router bgp 4

R4(config-router)#neighbor 1.1.1.1 remote-as 1

R4(config-router)#neighbor 1.1.1.1 update-source loopback 0

R4(config-router)#neighbor 1.1.1.1 ebgp-multihop 3

R4(config-router)#neighbor 3.3.3.3 remote-as 3

R4(config-router)#neighbor 3.3.3.3 update-source loopback 0

R4(config-router)#neighbor 3.3.3.3 ebgp-multihop 3




In order to ensure that the ORIGIN code is INCOMPLETE, you need to redistribute the LAN subnets into BGP. However, you can also use the network statement in conjunction with a route map and set the ORIGIN code within the route map.



R1(config)#route-map CONNECTED permit 10

R1(config-route-map)#match interface fastethernet 0/0

R1(config-route-map)#exit

R1(config)#route-map CONNECTED deny 20

R1(config-route-map)#exit

R1(config)#router bgp 1

R1(config-router)#redistribute connected route-map CONNECTED R1(config-router)#exit





You can verify the ORIGIN code by looking at the prefix entry in the BGP Tables. The ORIGIN code of INCOMPLETE is denoted by a question mark (?) in the output of the show ip bgp command. You can view additional detail on a per-prefix basis also when using this command



show ip bgp


show ip bgp


show ip bgp

show ip bgp




Configure BGP, so that R4 prefers the path via R3 to reach any subnet

In the output of the show ip bgp command on R4 we can see that the preferred route to reach 150.3.3.0 is via R3, however the preferred route to reach 150.2.2.0 is via R1 (the lowest routerid), also, to ensure that the subnet 150.1.1.0 will be reached via R3, configure BGP on R1 to advertise all prefixes with a longer AS-PATH to influence the path selection as follow:




R1(config)#route-map PREP permit 10

R1(config-route-map)#set as-path prepend 1 1 1 1 R1(config-route-map)#exit

R1(config)#router bgp 1

R1(config-router)#neighbor 4.4.4.4 route-map PREP out R1(config-router)#exit



Notice now the preferred path to reach both prefixes 150.3.3.0 and 150.2.2.0 is via R3 with the next-hop 3.3.3.3 because the shortest AS-PATH length:



do show ip bgp



Configure R4 so that it sends all updates to R3 with a MED of 4. Configure R2 so that it sends all updates to R3 with a MED of 2. Ensure that R3 prefers all routes with the better (lower) MED value.

Before configuring the MED let's verify the BGP RIBs on R3:

The preferred path to reach the prefix 150.1.1.0 is via R4, we should see all routes with the next-hop R2:





Let's configure MED




Let's configure MED on R3:

R4(config)#route-map MED permit 10

R4(config-route-map)#set metric 4

R4(config-route-map)#exit

R4(config)#router bgp 4

R4(config-router)#neighbor 3.3.3.3 route-map MED out

R4(config-router)#exit



R2(config)#route-map MED permit 10

R2(config-route-map)#set metric 2

R2(config-route-map)#exit

R2(config)#router bgp 2


R2(config-router)#neighbor 3.3.3.3 route-map MED out

R2(config-router)#exit





Let's verify the BGP RIBs of R3:

We have still the best path to reach 150.1.1.0 via R4 as shown by the show ip bgp command on R3 below, so the problem is not resolved even if R2 advertises the lowest MED comparing with R4.

The reason is: we met two issues in this case:

-the first issue is: by default, the MED is only compared for path received from the same AS ,in this case R3 receives two values of MED from two routers (R2 and R4) configured in different AS.

-The second issue: the MED is compared after the AS-PATH in the BGP decision process. In this case R3 will select the path via R4 as the best path to the 150.1.1.0/24 prefix because of the shorter AS-PATH length.



BGP MED




To override the two issues, configure the bgp always-compare-med command to avoid the first issue so always compare the MED even if MED is received from Different AS. And bgp bestpath as-path ignore command to avoid the second issue so that R3 override the BGP decision process by ignoring the step of the AS-PATH in the BGP Decision Process:

Let's configure these two commands:



R3(config)#router bgp 3

R3(config-router)#bgp bestpath as-path ignore R3(config-router)#bgp always-compare-med



We can see for the prefix 150.1.1.0 that the path with the longer AS-PATH length is preferred because the lowest MED even if the AS-PATH takes precedence over the MED in the order of the path selection in BGP:


BGP



Another way to verify all BGP RIBs with do show ip bgp, R3 prefers all routes from R2 because the lowest MED:





#BGP #LAB #CCNA #CCNP #CCIE #cisco #gns3 #solution

















Featured Post

Day 41 — BGP Confederations: Sub-AS Design, External View and Migration

1. Opening Confederations are another way to scale BGP inside a large administrative domain. They divide the domain into member autonomous systems while presenting a single confederation identifier to external peers. They are powerful, but their operational model is more complex than simply 'using private ASNs inside.' The engineering goal is not to memorize another BGP command. It is to understand what information each speaker is allowed to propagate, what path information can be hidden, and what failure domain is created by the chosen control-plane architecture . 2. Concept and standards behavior RFC 5065 defines AS_CONFED_SEQUENCE and AS_CONFED_SET and how member-AS relationships are represented. Confederation external sessions have eBGP-like properties inside the confederation, while the confederation is presented externally as one AS. Modern guidance must also account for the fact that RFC 9774 prohibits new origination of AS_SET/AS_CONFED_SET in ordinary aggregation c...