Home / Network Tools / IP Range to CIDR Converter
Network Tools

IP Range to CIDR Converter

Convert an IPv4 or IPv6 start/end interval into the fewest exact CIDR blocks, prove why each block fits, quantify one-prefix spillover, normalize mixed allowlists, and export repeatable browser-local evidence.

Exact CIDR Deployment & Aggregation Studio

Turn an arbitrary IPv4 or IPv6 interval into the fewest exact prefixes, inspect every boundary, compare the one-block shortcut, normalize a messy allowlist, and export the result without sending addresses to a backend.

IPv4 + IPv6 · BigInt · browser-local

1. Enter one inclusive range

Ready.
—address family
—inclusive addresses
—exact CIDR blocks
—range shape
—one-block cover
—one-block spillover
—one-block utilization

2. Exact set vs. one broader prefix

A shorter one-prefix answer can be operationally tempting, but it may include addresses outside the approved interval. The comparison below quantifies that expansion instead of hiding it.

Select an exact block below

3. Minimal exact blocks

#CIDRStartEndAddressesIPv4 maskIPv4 wildcard

The greedy step always takes the largest power-of-two block aligned at the current start that still fits inside the remaining interval. Click a row to inspect that step.

4. CIDR → range reverse verifier

—Reverse verification is local.
—first address
—last address
—addresses
—entered host bits

—

5. Generic allowlist / configuration handoff

Run a range first.

Operational boundary: These are generic source-address snippets, not a complete firewall policy. Ports, protocols, destination, rule ordering, cloud quotas, provider syntax versions and security approval remain separate decisions.

6. Normalize a mixed list — ranges, CIDRs and single IPs

Overlapping and touching intervals are merged within each IP family, then decomposed into the smallest exact CIDR set. IPv4 and IPv6 may coexist in the same input; they are never merged across families.

Ready.
#FamilyCIDRStartEndAddresses

7. Explicit local projects

LabelRangeFamilyAction

Nothing is auto-saved. Up to 12 explicitly saved projects stay in this browser only.

8. Audit & handoff

Truth boundary: This Studio proves inclusive address arithmetic, exact minimal CIDR coverage, containing-prefix spillover, CIDR normalization and same-family range union. It does not decide whether an IPv4 address is a usable host in a particular subnet, apply DHCP/cloud reservations, validate live routing, choose a security policy, or guarantee that a vendor accepts a generated snippet. IPv6 has no broadcast-address concept.

How to turn an arbitrary IP range into CIDR blocks without widening access by accident

Exact cover and one-prefix cover answer different questions

The minimal exact set contains every requested address and no others. A single containing prefix is shorter to write but can spill below the start or above the end. The Studio shows both and counts the extra addresses explicitly.

Why a ragged range needs several blocks

A CIDR prefix always has a power-of-two size and must begin on a matching binary boundary. The exact algorithm repeatedly selects the largest aligned block that still fits inside the remaining interval.

IPv4 masks are evidence, not extra ranges

For IPv4 each exact prefix includes its dotted subnet mask and wildcard mask. Those are alternative representations of the same prefix; they do not change which addresses are covered.

IPv6 uses the same interval logic at 128 bits

IPv6 ranges are calculated with exact BigInt arithmetic. There is no IPv6 broadcast address, and very large address counts are kept as integers rather than rounded floating-point values.

Merging a list must not silently widen it

Mixed-list normalization first converts each supplied range, prefix or single address to an interval, merges only overlapping or touching intervals of the same family, then decomposes that exact union back into CIDRs.

Deployment snippets need operational review

Copied nginx, UFW, iptables or Terraform fragments only carry source CIDRs. A real policy also depends on ports, protocols, rule order, destinations, provider limits and the intended allow/deny model.

Verification checklist for firewall, ACL and route handoff

Confirm that the first and last input addresses are inclusive and use the same family. Sum the address counts of the exact CIDR rows and compare them with the requested interval size. If considering one broader prefix, review the before/after spillover count rather than assuming a shorter rule is equivalent. For an existing prefix, use the reverse verifier to normalize host bits and check the actual first/last address it covers.

/31, /32 and IPv6 host semantics

The converter reports full address-block coverage, not a universal “usable host” count. IPv4 /31 can be used on point-to-point links under RFC 3021, /32 identifies one address, and IPv6 has no broadcast address. Device, DHCP and cloud-provider policies can impose additional reservations outside this arithmetic.

Privacy and repeat work

Range conversion, mixed-list aggregation and saved projects run in the browser. Nothing is auto-saved. Settings-only share links deliberately omit IP addresses, mixed-list contents and local project data.

Search by task, tool name, or category. Press Esc to close.
Start typing to find a tool.