CIDR subtraction and Nmap reports: local handoff steps
Subtract two CIDR lists or export saved Nmap XML to XLSX, CSV and JSON. Check inputs, empty results, completion status and supported limits.
Choose the deliverable before choosing the tool
CIDR subtraction consumes two coverage lists without contacting devices. The Nmap reader consumes an existing complete or partial XML report without running a scan. Neither input can replace the other.
| Material | Deliverable | First check |
|---|---|---|
| IPv4 include/exclude networks | Exact remaining CIDRs and address counts | Network alignment and exclusion intent |
| Nmap XML | Open-port XLSX/CSV/JSON | Scan scope, completion and timed-out hosts |
Subtract two coverage lists
Put 192.168.10.0/26 in A, then 192.168.10.24/29 and 192.168.10.48/28 on separate lines in B. The remainder contains 40 addresses expressed by three CIDRs. Removed gaps are not filled back in.
Duplicate and overlapping entries are combined before subtraction. An empty B only normalizes A; an exclusion covering all of A produces an empty TXT file and an explicit zero count in JSON.
192.168.10.0/28
192.168.10.16/29
192.168.10.32/28Read open ports from a saved scan
Paste Nmap XML output or select its local UTF-8 file. A selected file takes precedence, so clear it before switching back to text. Only TCP/UDP ports in the exact open state enter the table; closed, filtered and open|filtered are excluded.
Each open port becomes one row. The first IPv4 address is preferred, otherwise the first IPv6; the JSON preserves all reported addresses. Missing service versions stay blank. A missing or failed completion marker, or a timed-out host, means the saved observation may be incomplete.
XLSX stores text cells. CSV prefixes formula-like values with an apostrophe. All three downloads come from the same parsed records, while JSON retains original values for tracing spreadsheet-safety changes.
Arithmetic correctness and operational conclusions have different limits
An address outside the exclusion set is not necessarily unused, reachable or approved for allocation. Keep different firewall policies separate before manipulating their coverage; the tool cannot infer policy intent.
An open-port row is an observation from a saved scan, not a continuing fact. Counting open|filtered as open overstates certainty; treating an unscanned host as having no services misses inventory. Interpret the table with the original scan scope and time.
Check the handoff
- Use one network-aligned IPv4 CIDR /0–/32 per line; correct host bits first.
- Compare first/last addresses, remaining/removed counts and expected empty results with the source.
- Review scanStatus and timedOutHosts; zero open ports does not prove the network has no services.
- The on-page JSON previews 100 items. Use the full TXT/CSV/XLSX/JSON downloads for handoff.
- Keep the original lists or XML and open the exported file in the receiving software before using it.
References
- Python ipaddress
Independent reference for network arithmetic and exact range representation.
- Nmap XML output
Official Nmap XML host and port structure; not evidence of demand size.
Tools in this category
Expand a tool to see its steps, options and supported formats, then open its workspace.
IPv4 CIDR set subtractionSubtract excluded networks from an IPv4 allocation and save the exact remaining CIDR blocks.
Put the allowed or allocated networks in list A and networks to remove in list B. The result covers exactly the addresses in A that are absent from B, as the smallest ascending CIDR blocks.
Steps
- Paste the networks to keep in A and the exclusions in B, one CIDR per line. Leave B blank to normalize A.
- Subtract the two sets. Check remaining and removed address counts and the first/last addresses in the report.
- Copy the CIDR list or download remaining-cidrs.txt and the complete JSON report. Verify your allocation or policy before applying it elsewhere.
Capabilities and limits
- IPv4 only: one network-aligned CIDR per line, /0–/32. Host bits are rejected; use the IPv4 subnet calculator to find the network address first. IPv6 and address-range notation are unsupported.
- Each list accepts up to 10,000 entries and 1 MiB of UTF-8 text. Blank lines and whole-line # comments are ignored. Up to 50,000 output blocks; addresses are never individually enumerated.
- Overlapping, duplicate and adjacent inputs are combined. List B may be empty or contain networks outside A. Complete exclusion produces an empty TXT file and a JSON report with zero remaining addresses.
- The on-page JSON shows the first 100 blocks; the TXT and JSON downloads contain the full result. This is mathematical coverage, not free-address discovery, firewall policy validation or a network scan.
Nmap XML open-port reportTurn a saved Nmap XML scan into an Excel workbook and CSV of host addresses and open ports.
Paste a saved Nmap XML report or choose one UTF-8 XML file. Extract ports whose state is exactly open into an Excel-readable table. Download XLSX for spreadsheet use, CSV for interchange, and JSON for the complete parsed report.
Steps
- Paste XML from an authorized scan, or choose its saved XML file. Clear the selected file before switching back to pasted text.
- Build the report. Check open-port count, host count and scanStatus; absent or failed completion metadata means the report may be partial.
- Download open-ports.xlsx, open-ports.csv or the complete JSON. Review the table alongside the original scan before using it as an inventory.
Capabilities and limits
- One UTF-8 file up to 10 MiB, or pasted text up to 1 MiB; at most 20,000 open-port rows. A selected file takes precedence over the pasted text. The root must be nmaprun. Each cell is limited to 32,767 UTF-16 code units; repeated table values together must fit 2 MiB of UTF-8.
- Only explicit host/ports/port entries with state="open" and protocol tcp or udp are included. Closed, filtered, open|filtered, extraports and OS port probes are excluded. Missing service fields remain blank.
- For hosts with several addresses, the table uses the first IPv4 address, otherwise the first IPv6 address. The JSON download preserves every reported IP address. A report with no open ports exports headers and zero records.
- The standard bare <!DOCTYPE nmaprun> is accepted without loading a DTD. External/internal entity declarations are rejected; stylesheet instructions and referenced resources are never loaded.
- CSV prefixes formula-like cells with an apostrophe; XLSX stores every cell as text. The on-page JSON previews 100 records and truncates long preview values; downloads contain full values. If the scan has no successful finished marker or contains a timed-out host, a warning remains. This is a saved-report reader, not a scanner or proof of a complete inventory.