IP Range ⇔ CIDR Converter
Enter a start and end IP to split that range into the smallest possible set of CIDR blocks, or enter CIDR notation (e.g. 192.168.1.0/24) to get the block's first/last IP and total address count. Useful for firewall and ACL rule authoring.
To check a single IP with a subnet mask, see the subnet calculator , or for a reference table by prefix length, see the CIDR reference table .
Converting between an address range and CIDR notation
Enter a starting and an ending address and this tool divides the range into the fewest CIDR blocks that cover it exactly. It works the other way too, taking notation such as `192.168.1.0/24` and giving you the first and last addresses along with the total count. It earns its keep when writing firewall rules and access control lists.
**What often comes as a surprise is that an arbitrary range cannot necessarily be written as a single CIDR.** A CIDR block is bound by two constraints: **its size must be a power of two, and its first address must fall on a boundary of that size.** The six addresses from `192.168.1.5` to `192.168.1.10`, for instance, satisfy neither, so they cannot form one block and **must be divided into several, such as a `/32`, a `/31` and a `/30`.** This tool performs that division in the fewest blocks possible. Where you would rather not multiply the number of rules, **redesigning the range so its edges fall on boundaries generally proves the tidier course.**
How to use it
- Enter the starting and ending addresses You are given the list of CIDR blocks the range divides into.
- Look at how many blocks there are **A range that divides into many blocks is one whose edges do not fall on boundaries.**
- Or work back from a CIDR Enter notation such as `/24` and you are given the first and last addresses and the total count.
- Transcribe it into your rules It can go straight into a firewall or access control list.
Tips for getting more out of it
- Handy for turning a firewall or ACL range like "192.168.1.1 to 192.168.1.254" into CIDR notation your router configuration actually accepts.
- Unless the range boundaries happen to align to a clean power of two, the IP range → CIDR conversion will produce several blocks. If you get too many blocks, reconsider where the range starts and ends to keep your ACL simpler.
- For CIDR → IP range, even if the IP you enter isn't the exact start of a block, the tool rounds it to the network and broadcast address of the block it belongs to.
- If you only need to check a single IP and mask, try the subnet calculator; for a full lookup table by prefix length, the CIDR reference table is a good companion to this tool.
Where it comes in useful
Writing firewall rules
**It turns "permit only this range" into a sequence of CIDR blocks.**
Tidying an access control list
You can consider, with the boundaries in view, whether several rules might be consolidated.
Confirming an allocation
You can count how many addresses a CIDR handed to you by a provider contains.
Reconsidering a subnet design
**Merely aligning the edges to boundaries can cut the number of rules needed dramatically.**
IP addressing terms
- CIDR
- The notation expressing a block by an address and a prefix length, as in `192.168.1.0/24`.
- Prefix length
- The number after the slash. **Each increase of one halves the number of addresses the block contains.**
- Network address
- The first address of a block. **Unless it falls on a boundary, the block does not hold together.**
- Broadcast address
- The last address of a block. In an IPv4 subnet it is ordinarily not assigned to a host.
- Subnet mask
- A notation such as `255.255.255.0`, expressing the same thing as a CIDR prefix length.
- The power-of-two constraint
- **The size of a CIDR block is confined to a power of two.** This is why an arbitrary range cannot be written as one.
Frequently Asked Questions
Side Note — The algorithm behind IP range to CIDR conversion
The algorithm for splitting an IP range into CIDR blocks is a classic, approachable example of a "greedy algorithm" in computer science. The procedure is simple: at each position, pick the largest block that satisfies both how many bits of power-of-two alignment the current address has and how much of the remaining range is left, advance past that block, and repeat until you reach the end. This greedy approach is provably optimal — it always produces the theoretical minimum number of blocks.
In practice, engineers run into systems — cloud security groups, on-premises router ACLs, and more — that only accept CIDR notation rather than an arbitrary IP range. Converting an allocation handed down by a cloud provider, or a range that's been tracked internally as "10.1.0.10 to 10.1.0.50" in a spreadsheet, into router-ready CIDR blocks is an unavoidable step. Doing the bit arithmetic by hand is tedious and error-prone, which is exactly where a conversion tool like this one earns its keep.
The reverse direction — deriving an IP range from CIDR notation — comes up whenever you need a human-friendly "start to end" view of an allocated block. If a provider hands you "203.0.113.0/28", being able to instantly confirm the usable range is 203.0.113.0 through 203.0.113.15 lets you set up firewall allow-lists or DHCP scopes correctly the first time.