Aggregate CIDR blocks
Reduce an IPv4 CIDR list without changing its address coverage.
- 1Add input
- 2Review and run
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Combine duplicate, contained, overlapping, and adjacent IPv4 CIDR blocks into the shortest exact list. Preview address coverage and inspect each resulting range before copying it into an allowlist or rule set.
How to use this tool
- Paste one IPv4 CIDR block per line, or choose a UTF-8 text list.
- Review input and output counts, unique address coverage, duplicate count, and any host-bit normalization.
- Aggregate, inspect each output range, then copy one block or download the complete newline-separated list.
Supported inputs and limits
Up to 10,000 IPv4 CIDR entries, one per line. Blank lines and full-line # comments are ignored. UTF-8 text files are supported.
Host bits are normalized to the network boundary and shown before processing. The output never fills gaps between input blocks.
Aggregate only blocks that share the same intended policy. This tool does not validate destination rule syntax, performance, address ownership, or live network state.
Worked example
Example input
192.0.2.0/25 192.0.2.128/25 198.51.100.0/25
Example options
{}Example output
192.0.2.0/24 198.51.100.0/25
When something does not work
Enter one valid IPv4 CIDR per line. Fix the line number shown in the preview; only blank lines and full-line # comments are ignored.
Frequently asked questions
Will aggregation add addresses that were not in my input?
No. It returns the smallest CIDR list for the same union of addresses. A gap stays excluded even if including it would shorten the list.
What happens to duplicate or contained CIDR blocks?
They are removed from the output. Adjacent blocks combine when their union can be represented by a broader CIDR; every output block shows its exact address range.
What if a CIDR address has host bits set?
For example, 192.0.2.5/24 is treated as 192.0.2.0/24. The preview reports how many entries were normalized so you can review them.
Can I combine rules with different allow or deny actions?
Keep different policies separate. This tool only aggregates addresses; it does not know the action or priority of each original rule.
Is my list sent to a server?
No. The list is processed in your browser and no network scan or lookup is performed.
Documentation & further reading
Related tools
IPv4 subnet and netmask calculator
Calculate IPv4 subnet boundaries and usable endpoints, or convert a netmask and prefix.
IP range to CIDR
Turn an inclusive IPv4 address range into the smallest exact list of CIDR blocks.
IPv4 number converter
Convert one IPv4 address between dotted decimal, unsigned integer and 32-bit binary.
IPv6 expand and compress
Convert one IPv6 address to canonical, expanded and colon-free 32-digit forms.