IPv4 CIDR set subtraction
Subtract excluded networks from an IPv4 allocation and save the exact remaining CIDR blocks.
- 1Add input
- 2Adjust settings
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Put the allowed or allocated networks in list A and networks to remove in list B. The result covers exactly the addresses in A that are absent from B, as the smallest ascending CIDR blocks.
How to use this tool
- Paste the networks to keep in A and the exclusions in B, one CIDR per line. Leave B blank to normalize A.
- Subtract the two sets. Check remaining and removed address counts and the first/last addresses in the report.
- Copy the CIDR list or download remaining-cidrs.txt and the complete JSON report. Verify your allocation or policy before applying it elsewhere.
Supported inputs and limits
IPv4 only: one network-aligned CIDR per line, /0–/32. Host bits are rejected; use the IPv4 subnet calculator to find the network address first. IPv6 and address-range notation are unsupported.
Each list accepts up to 10,000 entries and 1 MiB of UTF-8 text. Blank lines and whole-line # comments are ignored. Up to 50,000 output blocks; addresses are never individually enumerated.
Overlapping, duplicate and adjacent inputs are combined. List B may be empty or contain networks outside A. Complete exclusion produces an empty TXT file and a JSON report with zero remaining addresses.
The on-page JSON shows the first 100 blocks; the TXT and JSON downloads contain the full result. This is mathematical coverage, not free-address discovery, firewall policy validation or a network scan.
Worked example
Example input
192.168.10.0/26 List B — networks to remove: 192.168.10.24/29 192.168.10.48/28
Example options
{}Example output
192.168.10.0/28 192.168.10.16/29 192.168.10.32/28
When something does not work
Correct the first malformed or non-network-aligned CIDR and run again. Check /0 exclusions carefully: a full-space exclusion leaves no remaining addresses.
Frequently asked questions
Does a larger exclusion cover smaller networks?
Yes. A CIDR in B removes every covered address from A, including complete smaller networks. Exclusions outside A do not add or remove unrelated addresses.
How is this different from CIDR aggregation?
Aggregation combines one list without removing any covered address. This workspace compares two lists and removes B from A; aggregation is used only to express the remainder compactly.
Will it contact the addresses?
No. Both lists stay in this browser. The result cannot tell whether an address is assigned, reachable or available to use.
Documentation & further reading
Related tools
IPv4 subnet and netmask calculator
Calculate IPv4 subnet boundaries and usable endpoints, or convert a netmask and prefix.
IP range to CIDR
Turn an inclusive IPv4 address range into the smallest exact list of CIDR blocks.
Aggregate CIDR blocks
Reduce an IPv4 CIDR list without changing its address coverage.
IPv4 number converter
Convert one IPv4 address between dotted decimal, unsigned integer and 32-bit binary.