Skip to main content
QUIETLYTIC
Networking

CIDR Range Calculator

Convert between a start-end IP range and the CIDR blocks covering it.

Local · nothing leaves this browser Waiting for a range
Esc Clear
The blocks that cover it

Enter a range on the left.

How it works

Firewalls, allowlists and routing tables speak CIDR. People speak ranges — "everything from .10 to .60". The two do not map one to one, and the gap between them is where a rule ends up wider than anyone intended.

Why one range becomes several blocks

A CIDR block always begins on a boundary that is a multiple of its own size. A range starting one address past a boundary, or ending one short of the next, cannot be written as a single block at any prefix length. 192.0.2.1 to 192.0.2.6 takes four: a /32, two /31s and a final /32. There is no prefix that covers those six addresses and no others.

Minimal, and never wider than you asked

At each step the largest block is taken that both aligns on the current address and does not extend past the end of the range. That is provably the smallest set, and it guarantees the property that actually matters: no block here reaches an address outside your range. A tool that rounded up to a tidier prefix would hand you a rule that silently admits hosts you never listed.

Both directions

Give it a block instead and it reports the first and last address and the count — the same question asked from the other side.

Example

192.0.2.1 - 192.0.2.6 returns 192.0.2.1/32, 192.0.2.2/31, 192.0.2.4/31, 192.0.2.6/32. Four rules where one would be wrong: the tempting 192.0.2.0/29 covers the range but also admits .0 and .7.

Frequently asked questions

Why does one range produce several CIDR blocks?

Because a CIDR block always starts on a boundary that is a multiple of its own size. A range that begins one address past a boundary, or ends one short of the next, cannot be described by a single block at any prefix length. 192.0.2.1 to 192.0.2.6 needs four: a /32, two /31s and another /32.

Is the output the smallest possible set?

Yes. At each step it takes the largest block that both aligns on the current address and does not extend past the end of the range, which is provably minimal. No block ever overruns the range you asked for — that is the property that makes the result safe to paste into a firewall rule without widening it.

Does it work for IPv6?

Yes, and the arithmetic is exact. Address maths here runs on arbitrary-precision integers rather than JavaScript numbers, which stop being exact above 2^53 — a limit an IPv6 range passes immediately.

Related tools

From the intelligence desk