CIDR allowlist checks: include the right IPs without widening a range
Review subnet boundaries and CIDR aggregation before copying an allowlist. Use a range that needs two blocks and test addresses just outside it.
An address is not the whole network
Writing 192.168.1.34/24 describes the network containing that address, not just one host. Review the address and prefix together when copying configuration.
For one host, check whether the target system expects /32. For a range, write both endpoints first and convert them to CIDR rather than guessing a mask.
Review the boundaries
Inspect the first and last addresses in the calculated network. Test one address that should belong and one that should not.
This does not replace your firewall platform’s rule preview, but it catches common prefix errors. A continuous range crossing a boundary may require multiple CIDR entries.
Simplify without expanding access
Aggregation should preserve the covered address set. Two complete neighboring /25 blocks can form a /24; incomplete coverage must not be widened merely to shorten a list.
Neatbo performs local address arithmetic. It does not probe hosts or apply results to devices. Keep both the original list and the converted output for review.
A range that cannot be represented by one exact block
Suppose the intended range is 192.168.1.0 through 192.168.1.191. A /24 would also include .192 through .255. Exact coverage uses 192.168.1.0/25 plus 192.168.1.128/26. The additional line is necessary to avoid widening the range.
Test the endpoints .0 and .191, plus the excluded address .192. Membership tests should agree with the intended set. Then inspect the target system’s rule ordering, default action and address-family handling; arithmetic alone cannot tell you what the final policy permits.
Keep the original list together with the proposed normalized version so a reviewer can compare them. This tool does not connect to addresses or apply configuration, and a matching membership result is not authorization to change a network policy.
| Block | Covered range | Addresses |
|---|---|---|
| 192.168.1.0/25 | .0–.127 | 128 |
| 192.168.1.128/26 | .128–.191 | 64 |
| Combined | .0–.191 | 192 |
| 192.168.1.0/24 | .0–.255 | 256: wider than intended |
192.168.1.0/25
192.168.1.128/26Before you finish
- Write down the intended start and end before converting.
- Test excluded neighbors, not only included examples.
- Do not treat IPv4 host-count conventions as IPv6 rules.
- Review and apply any configuration through your normal change process.
References
- RFC 4632: CIDR
Background on address blocks and aggregation; applying a rule requires the target system’s own policy review.