Neatbo.

CIDR allowlist checks: include the right IPs without widening a range

Review subnet boundaries and CIDR aggregation before copying an allowlist. Use a range that needs two blocks and test addresses just outside it.

An address is not the whole network

Writing 192.168.1.34/24 describes the network containing that address, not just one host. Review the address and prefix together when copying configuration.

For one host, check whether the target system expects /32. For a range, write both endpoints first and convert them to CIDR rather than guessing a mask.

Review the boundaries

Inspect the first and last addresses in the calculated network. Test one address that should belong and one that should not.

This does not replace your firewall platform’s rule preview, but it catches common prefix errors. A continuous range crossing a boundary may require multiple CIDR entries.

Simplify without expanding access

Aggregation should preserve the covered address set. Two complete neighboring /25 blocks can form a /24; incomplete coverage must not be widened merely to shorten a list.

Neatbo performs local address arithmetic. It does not probe hosts or apply results to devices. Keep both the original list and the converted output for review.

A range that cannot be represented by one exact block

Suppose the intended range is 192.168.1.0 through 192.168.1.191. A /24 would also include .192 through .255. Exact coverage uses 192.168.1.0/25 plus 192.168.1.128/26. The additional line is necessary to avoid widening the range.

Test the endpoints .0 and .191, plus the excluded address .192. Membership tests should agree with the intended set. Then inspect the target system’s rule ordering, default action and address-family handling; arithmetic alone cannot tell you what the final policy permits.

Keep the original list together with the proposed normalized version so a reviewer can compare them. This tool does not connect to addresses or apply configuration, and a matching membership result is not authorization to change a network policy.

A range that cannot be represented by one exact block
BlockCovered rangeAddresses
192.168.1.0/25.0–.127128
192.168.1.128/26.128–.19164
Combined.0–.191192
192.168.1.0/24.0–.255256: wider than intended
A fictional example to try
192.168.1.0/25
192.168.1.128/26

Before you finish

  • Write down the intended start and end before converting.
  • Test excluded neighbors, not only included examples.
  • Do not treat IPv4 host-count conventions as IPv6 rules.
  • Review and apply any configuration through your normal change process.

References

  • RFC 4632: CIDR

    Background on address blocks and aggregation; applying a rule requires the target system’s own policy review.

Tools used in this article

IPv4 subnet and netmask calculator →Calculate IPv4 subnet boundaries and usable endpoints, or convert a netmask and prefix.IP range to CIDR →Turn an inclusive IPv4 address range into the smallest exact list of CIDR blocks.IP in CIDR checker →Check a list of IP addresses against one IPv4 or IPv6 CIDR and export matching values.