Neatbo.

IP and CIDR guide: subnets, range aggregation and membership

Calculate IPv4 and IPv6 subnets, convert address ranges to CIDR, aggregate networks and check membership. Verify boundary addresses before updating allowlists.

Choose an operation for your task

Calculate IPv4 and IPv6 subnets, convert address ranges to CIDR, aggregate networks and check membership. Verify boundary addresses before updating allowlists.

Which operation fits?
Your taskWhere to start
Define a subnetCalculate prefix boundaries and compare the first and last address
Shorten access rulesAggregate exact coverage without filling address gaps
Check a boundary addressTest one included and one excluded neighboring address

Work in order and retain the original

Normalize addresses, validate masks and compare boundaries before consolidating rules. IPv4 and IPv6 have different sizes and notation; avoid converting them through floating-point numbers. An address being inside a network does not mean it is reachable, owned by a particular organization or appropriate to trust.

Representative workflow and expected result
192.0.2.0/25 and 192.0.2.128/25 cover the same range as 192.0.2.0/24; check both endpoints before replacing rules.

Separate processing success from acceptance

Test one included and one excluded address for every policy boundary. These tools do not scan networks, resolve DNS, locate IPs or apply firewall rules.

Before you finish

Expand a tool below for its steps, options and limits. Choose the tools needed for your task; you do not need to use every one.

  • Test one included and one excluded address for every policy boundary. These tools do not scan networks, resolve DNS, locate IPs or apply firewall rules.
  • Reopen the download and compare it with the example and the meaning of the input.
  • When an input exceeds the stated boundaries, retain it and split the task or use a suitable processor; renaming an extension does not make it compatible.

References

Tools in this category

Expand a tool to see its steps, options and supported formats, then open its workspace.

IPv4 subnet and netmask calculatorCalculate IPv4 subnet boundaries and usable endpoints, or convert a netmask and prefix.

Calculate the network, full address range, netmask, wildcard mask, and usable endpoints for one IPv4/CIDR. Switch to mask conversion for dotted masks and prefixes. Copy one field or download the complete JSON.

Steps

  1. Select Calculate subnet or Convert netmask / prefix above the input.
  2. Enter IPv4/CIDR such as 192.168.1.34/24, or a mask such as 255.255.255.0.
  3. Review the preview, calculate, then copy a field or download the JSON.

Available options

Task
Subnet · Netmask conversion

Capabilities and limits

  • One IPv4/CIDR or mask at a time. IPv6, batches, DNS, geolocation, and network scans are outside this calculator.
  • /31 has two point-to-point endpoints; /32 is one host route; /0 is a default route with no meaningful usable-host count.
  • Calculations run locally in your browser.
Open IPv4 subnet and netmask calculator →
IP range to CIDRTurn an inclusive IPv4 address range into the smallest exact list of CIDR blocks.

Enter the first and last IPv4 addresses to get the smallest exact CIDR list. Check each block and copy one or the complete newline-separated list for network configuration.

Steps

  1. Paste two IPv4 addresses separated by a hyphen, space, tab, or line break.
  2. Check the inclusive endpoints, address count and CIDR block count before converting.
  3. Inspect each block and its address range, then copy one block or download the complete list.

Capabilities and limits

  • One inclusive IPv4 range per run. The output may need several CIDR blocks; a single broader block would include extra addresses.
  • This tool does not look up address ownership or validate a firewall or cloud provider policy. Some destinations reject prefixes such as /0.
  • Calculations stay in this browser; no DNS, geolocation or network scan.
Open IP range to CIDR →
Aggregate CIDR blocksReduce an IPv4 CIDR list without changing its address coverage.

Combine duplicate, contained, overlapping, and adjacent IPv4 CIDR blocks into the shortest exact list. Preview address coverage and inspect each resulting range before copying it into an allowlist or rule set.

Steps

  1. Paste one IPv4 CIDR block per line, or choose a UTF-8 text list.
  2. Review input and output counts, unique address coverage, duplicate count, and any host-bit normalization.
  3. Aggregate, inspect each output range, then copy one block or download the complete newline-separated list.

Capabilities and limits

  • Up to 10,000 IPv4 CIDR entries, one per line. Blank lines and full-line # comments are ignored. UTF-8 text files are supported.
  • Host bits are normalized to the network boundary and shown before processing. The output never fills gaps between input blocks.
  • Aggregate only blocks that share the same intended policy. This tool does not validate destination rule syntax, performance, address ownership, or live network state.
Open Aggregate CIDR blocks →
IPv4 number converterConvert one IPv4 address between dotted decimal, unsigned integer and 32-bit binary.

Paste one IPv4 address, unsigned decimal integer, or 32-bit binary value. Inspect the equivalent forms side by side and copy the exact value needed for a database, log or network configuration.

Steps

  1. Paste one dotted IPv4 address, unsigned decimal integer, or supported binary form.
  2. Check the detected input type and address preview before converting.
  3. Compare the equivalent address, decimal and binary values. Copy a plain field or download the complete JSON.

Capabilities and limits

  • One IPv4 value per run. Decimal input uses the unsigned 32-bit range 0–4294967295 and network byte order; signed integers and little-endian host-order values are not reinterpreted.
  • Dotted input requires four 0–255 decimal octets without leading zeros. Binary input accepts 0b-prefixed bits, exactly 32 plain bits, or four 8-bit groups separated by periods or spaces.
  • This is representation conversion only; it does not resolve DNS, classify address ownership, or test network reachability.
Open IPv4 number converter →
IPv6 expand and compressConvert one IPv6 address to canonical, expanded and colon-free 32-digit forms.

Convert one IPv6 address or 32-digit hexadecimal value into RFC 5952 compressed notation, eight four-digit groups and a colon-free 32-digit value. Copy the exact form your destination requires.

Steps

  1. Paste one full or compressed IPv6 address, or exactly 32 hexadecimal digits.
  2. Check the detected input and canonical address preview.
  3. Copy the compressed, eight-group or 32-digit form needed by your destination, or download the complete JSON.

Capabilities and limits

  • One value per run. Full and compressed IPv6, an embedded IPv4 dotted tail and exactly 32 hexadecimal digits without colons are accepted. IPv4-mapped addresses use a dotted tail in the canonical result.
  • CIDR prefixes, zone IDs, brackets and ports are not accepted. This tool changes notation only; it does not perform DNS, ownership or reachability checks.
Open IPv6 expand and compress →
IPv6 subnet calculatorFind the exact start, end and size of one IPv6 prefix.

Enter one IPv6 address and /0–/128 prefix. See the normalized network, inclusive range and exact address count, then copy a field or download JSON. The mathematical range does not prove those addresses were assigned to you.

Steps

  1. Paste one IPv6 address and prefix, such as 2001:db8::1/64. Spaces around the slash are accepted.
  2. Check the normalized network preview and exact address count before calculating.
  3. Read the inclusive start and end, copy the field you need, or download the complete JSON. Confirm the provider allocation before configuring addresses.

Capabilities and limits

  • One IPv6 address and prefix per run. A zone ID, port, address list or file is not accepted.
  • This is exact local arithmetic, not a provider allocation, routing, DNS or reachability check. IPv6 has no broadcast address.
  • The count remains a decimal string in JSON so values beyond JavaScript safe integers are not rounded.
Open IPv6 subnet calculator →
MAC address normalizerConvert MAC addresses between colon, hyphen, Cisco dotted and plain formats, including short and Python hex octets.

Paste one 48-bit MAC address to convert four common notations and inspect the IEEE individual/group and universal/local bits. Short octets such as 0:b or Python 0x0L are padded on the left. This does not identify a device or vendor.

Steps

  1. Paste or type one address in colon, hyphen, Cisco dotted or 12-digit format, or paste six Python 2 hex() byte values with L suffixes.
  2. Check the normalized preview, especially if short octets were padded.
  3. Select “Normalize MAC address”. Copy the required address format or download the complete JSON.

Capabilities and limits

  • One 48-bit address per run. Mixed separators, OUI-only values and EUI-64 are not accepted.
  • Formatting and bit inspection run in your browser; no network or vendor lookup.
Open MAC address normalizer →
IP address validatorValidate one IPv4 or IPv6 address per line and export the valid entries.

Paste a list of IP addresses or open a UTF-8 text file. The tool checks each nonblank line as a complete address, keeps source line numbers for errors, and exports valid entries as plain text. It checks syntax, not reachability or ownership.

Steps

  1. Paste one address per line or choose a UTF-8 .txt file.
  2. Review the input count and invalid count before running; blank lines are ignored.
  3. Select “Validate IP addresses”. Check invalid line numbers, copy or download valid addresses, or download the complete JSON report.

Capabilities and limits

  • Up to 10,000 nonblank lines; one IPv4 or IPv6 address per line. Blank lines are ignored. CIDR prefixes, CSV rows and zone identifiers are not accepted.
  • Input and files stay in your browser. Validation does not query DNS, geolocation, assignment or network reachability.
Open IP address validator →
IP in CIDR checkerCheck a list of IP addresses against one IPv4 or IPv6 CIDR and export matching values.

Paste one address per line or choose a UTF-8 text file, then compare each address with one CIDR. The result identifies inside, outside, malformed and wrong-version rows, retaining source line numbers. Host bits in the CIDR are normalized before comparison.

Steps

  1. Enter the CIDR to check, such as 192.168.1.0/24 or 2001:db8::/32.
  2. Paste one IP address per line or choose a UTF-8 .txt file, then review the inside/outside preview.
  3. Select “Check CIDR membership”. Copy or download matching addresses, download outside addresses, or inspect the complete JSON report.

Available options

CIDR network
Enter as needed

Capabilities and limits

  • Up to 10,000 nonblank address lines and one IPv4 or IPv6 CIDR. Blank lines are ignored; mixed IP versions are reported as mismatches.
  • Files and text stay in your browser. Containment does not prove firewall behavior, route configuration, address ownership or reachability.
Open IP in CIDR checker →

Tools used in this article

IPv4 subnet and netmask calculator →Calculate IPv4 subnet boundaries and usable endpoints, or convert a netmask and prefix.IP range to CIDR →Turn an inclusive IPv4 address range into the smallest exact list of CIDR blocks.Aggregate CIDR blocks →Reduce an IPv4 CIDR list without changing its address coverage.IPv4 number converter →Convert one IPv4 address between dotted decimal, unsigned integer and 32-bit binary.IPv6 expand and compress →Convert one IPv6 address to canonical, expanded and colon-free 32-digit forms.IPv6 subnet calculator →Find the exact start, end and size of one IPv6 prefix.MAC address normalizer →Convert MAC addresses between colon, hyphen, Cisco dotted and plain formats, including short and Python hex octets.IP address validator →Validate one IPv4 or IPv6 address per line and export the valid entries.IP in CIDR checker →Check a list of IP addresses against one IPv4 or IPv6 CIDR and export matching values.