Neatbo.

Interpret CIDR remainders and saved port observations

Distinguish mathematical coverage from real allocations, and understand ambiguous states, timed-out hosts and blank service fields in an open-port inventory.

A computed set and a saved observation

CIDR subtraction starts from two sets you provide, so the remainder can be checked precisely by address. A Nmap table starts from observations saved during a scan; coverage also depends on scope, permissions, time and timeouts. Preserve that context so the receiver can interpret the handoff.

What each result establishes
ResultCheckable conclusionExternal confirmation still needed
CIDR remainderAddresses in A that B does not coverWhether the allocation is permitted
Nmap open-port rowAn explicit open observation in the reportWhether it remains open and whether the scan was complete

Keep excluded gaps excluded

With A = 10.0.0.0/24 and B = 10.0.0.0/25, the remainder is 10.0.0.128/25 with 128 addresses. Writing it back as 10.0.0.0/24 for convenience would reintroduce the excluded half.

Duplicate networks do not add addresses, and exclusions outside A cannot enlarge A. Minimal CIDR representation compresses the same address set; it does not fill nearby space that was never allowed.

A half-network cross-check
A: 10.0.0.0/24
B: 10.0.0.0/25
A − B: 10.0.0.128/25
addresses: 128

Interpret the blanks behind a port row

The open|filtered state preserves uncertainty and therefore does not enter the confirmed-open table. A blank service or version means the report did not contain that value; inserting a familiar default would invent an observation.

An overall successful finish can still include timed-out hosts. Read scanStatus and timedOutHosts, and keep the original scan time, target scope and options in the handoff notes. A format converter cannot reconstruct that context by guessing.

Choose how the receiver will read the data

XLSX text cells make the table readable in spreadsheet software without treating a hostname as a formula. CSV is simpler for interchange, but spreadsheet applications interpret some leading characters, so formula-like CSV values receive an apostrophe.

Use JSON to compare original values when a later program needs them. The first 100 on-page records are a preview, not a basis for extrapolating totals. Open the downloaded file and compare record counts and quoted values to verify the handoff.

Make the handoff reproducible

  • Attach A/B provenance, policy meaning and address-count checks to the CIDR output.
  • Attach scan time, target scope and finish/timeout status to the port table.
  • Compare JSON original values with CSV safety prefixes before consuming them as identifiers.
  • Open XLSX in the receiving software and sample a record containing commas, quotes or non-ASCII text.

References

  • Python ipaddress

    Independent reference for network arithmetic and exact range representation.

  • Nmap XML output

    Official Nmap XML host and port structure; not evidence of demand size.

Tools used in this article

IPv4 CIDR set subtraction →Subtract excluded networks from an IPv4 allocation and save the exact remaining CIDR blocks.Nmap XML open-port report →Turn a saved Nmap XML scan into an Excel workbook and CSV of host addresses and open ports.