Practical guide and verification
Wildcard masks invert subnet-mask bits
A wildcard mask uses 0 where a bit must match and 1 where it may vary. For a conventional subnet mask, each octet pair should sum to 255, such as 255.255.255.0 paired with 0.0.0.255.
Contiguous subnet assumptions do not cover every ACL wildcard
Prefix-length conversion assumes a normal contiguous subnet mask. Some access-control systems permit noncontiguous wildcard patterns; those patterns cannot always be summarized by one CIDR prefix and should be reviewed as bit masks instead.
Check the address range the rule actually matches
After converting a prefix, verify the first and last address implied by the network and wildcard. This is more informative than copying the wildcard alone because an ACL mistake can unintentionally include many more hosts.
Host and network semantics depend on the device syntax
A wildcard of 0.0.0.0 means every bit of the supplied address must match, while 255.255.255.255 allows every bit to vary. Vendor command syntax may provide shortcuts such as host or any, so confirm the platform documentation before deploying a rule.
Use binary evidence when an octet looks suspicious
Convert the subnet and wildcard octets to eight-bit binary and compare them bit by bit. A valid inverse pair should complement each other, which quickly exposes decimal typos such as 254 where 255 was intended.