A CIDR block such as 192.168.10.0/22 is a short way to write a range of addresses: the first address, and how many of its leading bits stay fixed. The range itself, the netmask, the number of addresses, and the question of whether another address is inside are all worked out from those two facts. This page does that for IPv4 and IPv6, and it also goes the other way: a range that is not a block becomes the smallest list of blocks that covers it exactly.
It is built for the jobs that come up with firewall rules, allow lists, cloud security groups, and routing tables. Paste your list, and merge it into the shortest list that means the same thing, remove the addresses you do not want, split a block into smaller ones, or look up which block holds each address. Everything is worked out in your browser, and the code behind the page makes no network requests, so a list of internal networks stays on your device.
How to use the Convert CIDR to IP Range: Merge, Split, and Simplify
- Paste your blocksWrite one block, range, or address per line. A block can be 10.0.0.0/24, 10.0.0.0 255.255.255.0, or 10.0.0.0 0.0.0.255, and a range can be 10.0.0.5 - 10.0.0.90. IPv6 works the same way. Anything after a # on a line is ignored.
- Choose what to doExplain shows the details of each block. Range to CIDR gives the blocks for each range. Merge and simplify makes one short list. Leave out takes a second list away from the first. Split cuts a block into smaller ones. The last choice finds the block that holds each address.
- Read the resultLines that cannot be read are listed with the reason, so a typo is easy to find. The result shows the numbers that matter for the job, such as the count of addresses and what happened to each block of a merged list.
- Copy the listChoose how to write the list: as CIDR, as a range, or as an address with its netmask. Then copy it or download it as a text file.
What CIDR notation says
RFC 4632 describes Classless Inter-Domain Routing, which replaced the old system of address classes. An IPv4 address has 32 bits, and a block is written as an address, a slash, and the prefix length: the number of leading bits that are the same for every address in the block. In 192.168.10.0/22, 22 bits are fixed and 10 bits are free, so the block holds 2 to the power of 10, or 1,024 addresses, from 192.168.8.0 to 192.168.11.255. IPv6 works the same way with 128 bits, so a /32 holds 2 to the power of 96 addresses.
A block has to be aligned. Its first address must have zeros in all the free bits, which is why 192.168.10.0/22 is really the block that starts at 192.168.8.0. If you type an address with some of those bits set, this page uses the block that holds it and tells you that the host bits were set, because that is also what a router does with it.
Netmasks and wildcard masks
Older tools and many devices write the prefix as a netmask: 255.255.255.0 is /24, because it has 24 ones followed by zeros. Access lists on some routers use the wildcard mask instead, which is the same mask turned over: 0.0.0.255 means that the last 8 bits may be anything. This page reads both. A mask that is ones followed by zeros is a netmask. One that is zeros followed by ones is a wildcard mask, and the page says so. A mask with ones and zeros mixed, such as 255.0.255.0, is not a valid block, and the page says that instead of guessing.
From a range to blocks
A range such as 10.0.0.5 to 10.0.0.90 is not a block, because it does not start on a boundary. It can still be covered exactly by several blocks. The page starts at the first address and takes the biggest block that is aligned there and does not go past the end, then repeats from the next address. For the range above that gives 10.0.0.5/32, 10.0.0.6/31, 10.0.0.8/29, 10.0.0.16/28, 10.0.0.32/27, 10.0.0.64/28, 10.0.0.80/29, 10.0.0.88/31, and 10.0.0.90/32. That is the smallest list that covers exactly those addresses and no others, and it is the same list that Python's summarize_address_range makes.
Merging, simplifying, and leaving blocks out
A long allow list usually has blocks that sit inside others, blocks written twice, and neighbours that could be one. The page joins every overlapping or touching range and then writes the result as the smallest list of blocks. Two neighbouring /25 blocks become one /24, but a /25 next to a /26 stay two blocks, because the pair does not make a block. The table shows what happened to each line, so you can see which entries were redundant and which were joined.
Leaving blocks out works the other way. It takes the second list away from the first and writes what remains as blocks. Taking 10.0.0.64/26 out of 10.0.0.0/24 leaves 10.0.0.0/26 and 10.0.0.128/25. Because the work is done on exact ranges of numbers, there is no limit on how many blocks may overlap or how small the pieces become.
Hosts, the broadcast address, and IPv6
In IPv4 the first address of a block is the network address and the last is the broadcast address, so a /24 has 254 usable host addresses. RFC 3021 makes an exception for point-to-point links: a /31 has two addresses and both can be used, and a /32 is a single host. The page applies those rules. IPv6 has no broadcast address, so all addresses of a block are listed as usable. The Python library leaves out the first address of an IPv6 block, the subnet-router anycast address, from its list of hosts, and this page does not, so the counts differ by one for IPv6.
IPv6 addresses are written in the short form of RFC 5952: no leading zeros, lower case, and the longest run of zero groups, the first one if two runs tie, written as a double colon. A single zero group is not shortened. The full form with all eight groups is shown as well, because it is what you need for reverse DNS names, which are shown for blocks that fall on a boundary of a byte in IPv4 or a nibble in IPv6.
Special-purpose ranges
Some blocks are set aside for a purpose. RFC 1918 reserves 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 for private networks, and RFC 6598 reserves 100.64.0.0/10 for carrier-grade NAT. Loopback, link-local, multicast, and the documentation ranges have their own entries in the IANA registries. The page names a block when the whole block lies inside one of these ranges, and says nothing when the block is only partly inside, so that 10.0.0.0/7 is not called private. The table of ranges is a selection of the common ones, not the complete registry.
How the conversions were tested
The answers were checked against Python's ipaddress module, which is not part of this page. More than 2,600 cases were made from it: 500 addresses written in several ways, 600 blocks with their first and last address, count, netmask, wildcard mask, and usable hosts, 150 blocks written with a netmask or a wildcard mask, 300 ranges, 250 lists to merge, 250 lists to subtract from, 171 blocks to split, and 400 pairs of blocks with an address to look up. In every case the page gave the same answer, in IPv4 and IPv6, including the short form of IPv6 addresses.
Addresses that are not valid were checked as well: leading zeros, groups with too many digits, a double colon used twice, and an IPv4 tail with a missing number are all refused with a reason. Three thousand random strings were also read to check that none of them caused an error. The only intended difference from ipaddress is the one about IPv6 hosts described above.
Limits and accuracy
- The page works on the numbers in the blocks only. It does not look up who owns an address, which network it belongs to on the internet, or whether it answers. A browser page cannot do those lookups without sending the address to a server.
- Addresses with leading zeros, such as 010.0.0.1, are refused, because some programs read them as octal and others as decimal. Write them without the zeros.
- An IPv6 address with a zone ID, such as fe80::1%eth0, is refused. The zone belongs to the machine and is not part of the address.
- The table of special-purpose ranges is a selection of the common ones, so a block that is not named may still be special. The IANA registries list them all.
- For IPv6 every address of a block is listed as usable, including the first, which some programs keep for the subnet-router anycast address.
- A list can show at most 500 rows in the table, and a split lists at most 4,096 blocks, with the exact count shown above. Copy and download give the whole list that is shown.
- An IPv4-mapped IPv6 address such as ::ffff:10.0.0.1 is treated as an IPv6 address and is not matched against IPv4 blocks.
Frequently asked questions
How do I convert a CIDR block to an IP range?
Paste the block, such as 192.168.10.0/22, and choose Explain. The page shows the first and last address, here 192.168.8.0 and 192.168.11.255, the number of addresses, the netmask, and the usable hosts. A block with host bits set is moved to the start of its block, and the page says so.
How do I convert an IP range to CIDR?
Paste the range as two addresses with a dash between them, and choose Range to CIDR. The page gives the smallest list of blocks that covers exactly that range. A range that does not start on a boundary needs several blocks, and the list may be long.
What is the difference between a netmask and a wildcard mask?
A netmask has ones for the fixed network bits, such as 255.255.255.0. A wildcard mask is the same thing turned over, with ones for the bits that may change, such as 0.0.0.255. Routers use the netmask for subnets and often the wildcard mask in access lists. The page reads either one.
How many usable hosts does a /24 have?
254. A /24 has 256 addresses, and in IPv4 the first is the network address and the last is the broadcast address. A /31 has two usable addresses, as RFC 3021 allows for point-to-point links, and a /32 is a single host.
Can it merge a long list of subnets into a shorter one?
Yes. Choose Merge and simplify. Blocks inside other blocks are removed, duplicates are dropped, and neighbours that form a bigger block are joined. The table shows what happened to each line, and the result has the same addresses as the input.
Does it work with IPv6?
Yes. All the choices work with IPv6, with exact counts for the very large numbers of addresses. The addresses are written in the short form of RFC 5952, and the full form is shown as well. IPv4 and IPv6 can be mixed in one list, and they are kept apart in the result.
Is my list of networks uploaded anywhere?
No. Everything is worked out in your browser, and the code behind the page makes no network requests. The list is not saved, so copy the result before you close the page.
Research and references
This page was written and checked against the sources below.
- RFC 4632: Classless Inter-domain Routing (CIDR)
- RFC 5952: A Recommendation for IPv6 Address Text Representation
- RFC 1918: Address Allocation for Private Internets
- RFC 3021: Using 31-Bit Prefixes on IPv4 Point-to-Point Links
- IANA: IPv4 Special-Purpose Address Registry
- Python documentation: the ipaddress module, used to check the results

