IP Range to CIDR Converter
Ranges to CIDR, CIDR to ranges, merged lists and exclusions — ready for your firewall.
What do you want to do?
Turns ranges into CIDR blocks and CIDRs into ranges, and merges a mixed list into the fewest prefixes.
Accepts 192.0.2.1, 192.0.2.0/24, 192.0.2.0/255.255.255.0, 192.0.2.10-192.0.2.20, 192.0.2.10-20, 192.0.2.* and IPv6 such as 2001:db8::/48, separated by new lines, commas or spaces. # starts a comment.
Entries that could not be read
Result
Overlaps
Each entry converted
| Line | Entry | First – last | Addresses | CIDR |
|---|
Plan subnets inside a block with the VLSM calculator · Convert one address to binary, hex or integer
About the IP Range to CIDR Converter
Firewalls, cloud security groups and allow-lists want CIDR blocks, but address lists arrive as ranges, single addresses, netmasks and duplicates. Paste any mix of them — IPv4 and IPv6 — and this converter returns the fewest CIDR prefixes that cover exactly the same addresses, along with the merged ranges, address counts and every entry converted on its own.
It can also subtract one list from another (for example “the whole internet except private networks” for a VPN) and compare two lists to show what they share and which entries overlap. Results can be copied as a plain list or as ready-to-paste rules for nginx, Apache, iptables, nftables, ipset, pf, Windows Firewall, Cisco IOS and MikroTik. Nothing you paste leaves your browser.
How to use it
- Choose what to do: Convert & merge one list, Subtract a second list from the first, or Compare two lists.
- Paste addresses, ranges (
10.0.0.1-10.0.0.50or10.0.0.1-50), CIDRs (10.0.0.0/24), netmasks (10.0.0.0 255.255.255.0) or wildcards (10.0.0.*) — one per line or separated by commas. - Fix any entries listed under “could not be read”; everything else is already in the result.
- Pick an output format — a plain CIDR list, ranges, comma-separated, or firewall rules — and set the rule action and list name if the format uses them.
- Copy the result or download it as a file.
Examples
192.168.1.10-192.168.1.20
192.168.1.10/31 192.168.1.12/30 192.168.1.16/30 192.168.1.20/32
A CIDR block must start on a multiple of its size, so 11 addresses from .10 need four blocks: 2 + 4 + 4 + 1.
192.168.0.0/24, 192.168.1.0/24, 192.168.2.0 - 192.168.3.255, 2001:db8::/48, 2001:db8:1::/48
192.168.0.0/22 2001:db8::/47
Start with: 0.0.0.0/0 Remove: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
0.0.0.0/5, 8.0.0.0/7, 11.0.0.0/8, 12.0.0.0/6, 16.0.0.0/4, 32.0.0.0/3, 64.0.0.0/2, 128.0.0.0/3, 160.0.0.0/5, 168.0.0.0/6, 172.0.0.0/12, 172.32.0.0/11, … (31 prefixes)
Routing these through a WireGuard tunnel instead of 0.0.0.0/0 keeps devices on your local network reachable.
Common uses
- Turning a vendor’s published IP ranges into CIDR blocks for a firewall or cloud security group.
- Cleaning up an allow-list: removing duplicates and entries already covered by larger blocks.
- Building WireGuard or other VPN AllowedIPs that route everything except local or private networks.
- Checking whether two address plans, ACLs or blocklists overlap before merging networks.
- Summarising routes (supernetting) before announcing or filtering them.
How a range becomes CIDR blocks
A CIDR block of length /n holds 2^(32 − n) IPv4 addresses (2^(128 − n) for IPv6) and must start at a multiple of that size. The converter walks from the first address of a range and each time takes the largest block that both starts there and ends inside the range, until the range is covered — the standard aggregation method behind RFC 4632. The result is the smallest possible number of prefixes, covering exactly the addresses of the range and no others.
When merging a list, overlapping and adjacent entries are combined first, so 192.168.0.0/24 and 192.168.1.0/24 become 192.168.0.0/23. IPv6 results are written in the standard compressed form of RFC 5952 (lower case, longest run of zeros as ::).
Notation it understands
- Single addresses:
192.0.2.7,2001:db8::7, also in[brackets]. - CIDR:
192.0.2.0/24; if host bits are set (192.0.2.77/24) the whole network is used and the page says so. - Netmask or wildcard:
192.0.2.0/255.255.255.0,192.0.2.0 255.255.255.0or the Cisco wildcard192.0.2.0 0.0.0.255. The extremes0.0.0.0and255.255.255.255are refused after a space, because as a mask and as a wildcard they mean opposite things. - Ranges:
a-b,a – b,a to b, or the short form192.0.2.10-20for the last number. - Wildcards:
192.0.2.*,10.*. - Separate entries with new lines, commas, semicolons or spaces;
#starts a comment. Leading zeros (010.0.0.1) are rejected, because some systems read them as octal.
About the firewall formats
- nginx / Apache:
allow/denylines, orRequire ip(Apache 2.4). In allow mode nginx ends withdeny all;. - iptables, nftables, ipset, pf: append rules to INPUT, define named interval sets, hash:net sets (a /0 is written as two /1 halves, which ipset needs) or a pf table.
- Windows Firewall: a
New-NetFirewallRulecommand; IPv4 and IPv6 can share one rule. - Cisco IOS: a standard named access list with each prefix’s wildcard mask (
hostfor single addresses), or a prefix list for route filtering. In block mode, a final permit lets everything else through. - MikroTik:
/ip firewall address-listentries.
Review generated rules before applying them to production equipment — rule order, chains and existing policies differ from network to network.
Limitations
- Up to 50,000 entries per list and 200,000 prefixes in a result.
- Hostnames are not looked up — enter IP addresses only.
- IPv6 zone indexes (
fe80::1%eth0) and IPv6 short ranges such as2001:db8::1-ffare not accepted; write both full addresses. - The generated rules are a starting point: check them against your device’s documentation and existing rule order.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Why does one IP range turn into several CIDR blocks?
A CIDR block always contains a power of two addresses and must start on a multiple of its size. Most ranges do not line up with those boundaries, so they are split into several blocks — the converter finds the fewest. A range like 10.0.0.0–10.0.0.255 lines up perfectly and becomes one /24.
How do I convert a CIDR to an IP range?
Paste the CIDR and choose the “Ranges” output format, or open “Each entry converted” to see the first and last address and the number of addresses of every entry. 10.0.0.0/22, for example, is 10.0.0.0–10.0.3.255 (1,024 addresses).
How do I route everything through a VPN except my local network?
Choose Subtract, put 0.0.0.0/0 (and ::/0 for IPv6) in the first list and your private ranges in the second, then copy the comma-separated result into WireGuard’s AllowedIPs. The Example button fills in exactly this.
What does “host bits set” mean?
The address before the slash is not the first address of its network — 192.168.1.77/24 belongs to 192.168.1.0/24. Firewalls usually treat it as the whole network, and so does this converter; it tells you so in “Each entry converted”.
Does it work with IPv6?
Yes. IPv4 and IPv6 can be mixed in one list; they are merged separately and listed IPv4 first. Address counts for IPv6 are shown as powers of two (a /64 is 2^64 addresses).
Is my list uploaded anywhere?
No. Parsing, merging and formatting all run in your browser, so internal address plans and blocklists stay on your device.