CIDR Overlap Checker
Find which blocks in a list overlap, contain or duplicate each other.
Paste a list on the left.
How it works
An allowlist accumulates. Someone adds a /32 for a contractor, someone else later adds the
/24 it sits inside, and now there are two rules for one host — which one applies depends on
evaluation order rather than on anyone's intent.
Two blocks cannot partially overlap
This is the useful structural fact, and it is worth knowing before you read any result. Because every CIDR block is aligned to its own size, two blocks are either completely separate or one wholly contains the other. There is no half-in, half-out case. So every overlap found here resolves by deleting the narrower rule — a far simpler fix than a genuine partial overlap would require.
Adjacent is not overlapping
10.0.0.0/25 ends at 10.0.0.127 and 10.0.0.128/25 begins at the next
address. They touch without overlapping, and are reported as disjoint. Two adjacent blocks of the same size that
align can often be merged into one — but that is a tidiness question, not a correctness one, so it is not flagged.
Why containment matters more than duplication
An exact duplicate is usually harmless noise. Containment is where intent gets lost: a narrow deny sitting under a broader allow is a rule somebody believes is in force that is not, and nothing in the config says so.
Example
A list of 10.0.0.0/8, 10.1.0.0/16, 192.168.0.0/16 and a second
10.0.0.0/8 returns three findings: the /8 contains the /16, the two
/8s are identical, and the duplicate /8 contains the /16 as well.
192.168.0.0/16 is disjoint from all of them and is not reported.
Frequently asked questions
Can two CIDR blocks partially overlap?
No, and that is the useful part. Because every block is aligned to its own size, two blocks are either completely separate or one wholly contains the other — a half-in, half-out overlap is impossible. So every overlap this finds can be resolved by deleting the narrower rule, which is a much simpler fix than a partial overlap would need.
Why does an overlap matter in a firewall ruleset?
Because two rules covering the same addresses usually disagree about what to do with them, and which one wins depends on evaluation order rather than on intent. A narrower deny sitting under a broader allow is a rule someone believes is in force that is not.
Are adjacent blocks reported as overlapping?
No. 10.0.0.0/25 ends at 10.0.0.127 and 10.0.0.128/25 begins at the next address, so they touch without overlapping and are reported as disjoint.
Related tools
CIDR Calculator
Network, broadcast, mask and usable range for any block — and split it into subnets.
LocalCIDR Range Calculator
Convert between a start-end IP range and the CIDR blocks covering it.
LocalPrivate & Public IP Classifier
Tell whether an address is routable, private, loopback or otherwise reserved.
LocalIPv6 Calculator
Expand, compress and inspect an IPv6 address or prefix.
LocalIP Address Converter
Every representation of an address at once — dotted, binary, integer and hex.
LocalCommon Ports Lookup
Look up what normally listens on a TCP or UDP port, and why it matters if it is exposed.
Local