Skip to main content
QUIETLYTIC
Networking

CIDR Overlap Checker

Find which blocks in a list overlap, contain or duplicate each other.

Local · nothing leaves this browser Waiting for a list
Esc Clear
Overlaps, containment and duplicates

Paste a list on the left.

How it works

An allowlist accumulates. Someone adds a /32 for a contractor, someone else later adds the /24 it sits inside, and now there are two rules for one host — which one applies depends on evaluation order rather than on anyone's intent.

Two blocks cannot partially overlap

This is the useful structural fact, and it is worth knowing before you read any result. Because every CIDR block is aligned to its own size, two blocks are either completely separate or one wholly contains the other. There is no half-in, half-out case. So every overlap found here resolves by deleting the narrower rule — a far simpler fix than a genuine partial overlap would require.

Adjacent is not overlapping

10.0.0.0/25 ends at 10.0.0.127 and 10.0.0.128/25 begins at the next address. They touch without overlapping, and are reported as disjoint. Two adjacent blocks of the same size that align can often be merged into one — but that is a tidiness question, not a correctness one, so it is not flagged.

Why containment matters more than duplication

An exact duplicate is usually harmless noise. Containment is where intent gets lost: a narrow deny sitting under a broader allow is a rule somebody believes is in force that is not, and nothing in the config says so.

Example

A list of 10.0.0.0/8, 10.1.0.0/16, 192.168.0.0/16 and a second 10.0.0.0/8 returns three findings: the /8 contains the /16, the two /8s are identical, and the duplicate /8 contains the /16 as well. 192.168.0.0/16 is disjoint from all of them and is not reported.

Frequently asked questions

Can two CIDR blocks partially overlap?

No, and that is the useful part. Because every block is aligned to its own size, two blocks are either completely separate or one wholly contains the other — a half-in, half-out overlap is impossible. So every overlap this finds can be resolved by deleting the narrower rule, which is a much simpler fix than a partial overlap would need.

Why does an overlap matter in a firewall ruleset?

Because two rules covering the same addresses usually disagree about what to do with them, and which one wins depends on evaluation order rather than on intent. A narrower deny sitting under a broader allow is a rule someone believes is in force that is not.

Are adjacent blocks reported as overlapping?

No. 10.0.0.0/25 ends at 10.0.0.127 and 10.0.0.128/25 begins at the next address, so they touch without overlapping and are reported as disjoint.

Related tools

From the intelligence desk