Neatbo.

IPv4 CIDR set subtraction

Subtract excluded networks from an IPv4 allocation and save the exact remaining CIDR blocks.

Browser-local processingInputTwo IPv4 CIDR text listsOutputCIDR TXT + JSON report
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run
0 characters · 0 bytes
Preparing the tool…

Before you start

Put the allowed or allocated networks in list A and networks to remove in list B. The result covers exactly the addresses in A that are absent from B, as the smallest ascending CIDR blocks.

How to use this tool

  1. Paste the networks to keep in A and the exclusions in B, one CIDR per line. Leave B blank to normalize A.
  2. Subtract the two sets. Check remaining and removed address counts and the first/last addresses in the report.
  3. Copy the CIDR list or download remaining-cidrs.txt and the complete JSON report. Verify your allocation or policy before applying it elsewhere.

Supported inputs and limits

IPv4 only: one network-aligned CIDR per line, /0–/32. Host bits are rejected; use the IPv4 subnet calculator to find the network address first. IPv6 and address-range notation are unsupported.

Each list accepts up to 10,000 entries and 1 MiB of UTF-8 text. Blank lines and whole-line # comments are ignored. Up to 50,000 output blocks; addresses are never individually enumerated.

Overlapping, duplicate and adjacent inputs are combined. List B may be empty or contain networks outside A. Complete exclusion produces an empty TXT file and a JSON report with zero remaining addresses.

The on-page JSON shows the first 100 blocks; the TXT and JSON downloads contain the full result. This is mathematical coverage, not free-address discovery, firewall policy validation or a network scan.

Worked example

Example input

192.168.10.0/26

List B — networks to remove:
192.168.10.24/29
192.168.10.48/28
Example options
{}

Example output

192.168.10.0/28
192.168.10.16/29
192.168.10.32/28

When something does not work

Correct the first malformed or non-network-aligned CIDR and run again. Check /0 exclusions carefully: a full-space exclusion leaves no remaining addresses.

Frequently asked questions

Does a larger exclusion cover smaller networks?

Yes. A CIDR in B removes every covered address from A, including complete smaller networks. Exclusions outside A do not add or remove unrelated addresses.

How is this different from CIDR aggregation?

Aggregation combines one list without removing any covered address. This workspace compares two lists and removes B from A; aggregation is used only to express the remainder compactly.

Will it contact the addresses?

No. Both lists stay in this browser. The result cannot tell whether an address is assigned, reachable or available to use.

Documentation & further reading

Related tools