URL & Network Tools

IP Range to CIDR

Most IP ranges do not line up with a single CIDR block. Enter a start and end address, for example 10.0.0.5 - 10.0.0.130, and get the exact, minimal set of CIDR blocks that covers that range and nothing more. Works for IPv4 and IPv6 and for many ranges at once.

  • Runs in your browser
  • No sign-up
  • Free to use

One range per line: start and end address separated by “-”, “–”, “to”, a comma or spaces.

How to use IP Range to CIDR

  1. Enter ranges as start - end, one per line.
  2. Read the CIDR blocks for each range.
  3. Copy them into your firewall, router or allow-list.
  4. Check the block count if your system limits entries.

IP Range to CIDR features

Exact coverage

Blocks cover the range precisely, never more.

Minimal list

The fewest aligned blocks possible.

IPv4 and IPv6

Both families supported.

Flexible input

Separators -, –, to, comma or spaces.

Bulk

Many ranges, each labelled in the output.

Private

Runs in your browser.

When to use IP Range to CIDR

  • Converting a vendor’s IP range into firewall rules.
  • Turning DHCP pools into CIDR notation for documentation.
  • Building allow-lists from start and end addresses.
  • Studying how CIDR alignment works.

IP Range to CIDR FAQ

Why does one range become several blocks?

A CIDR block must be a power of two in size and start on a matching boundary. A range that does not start and end on such boundaries can only be covered exactly by several blocks.

Is the result always minimal?

Yes. The algorithm takes the largest aligned block that fits at each step, which yields the fewest blocks.

Can the result include addresses outside my range?

No. Every address in the output lies within the range you entered.

What if start is after end?

The tool reports an error; swap the two addresses.

How do I go the other way?

Use CIDR to IP Range.

Is anything sent?

No.

Fitting blocks into a range

A CIDR block is like a tile that must be a power of two in size and placed on a grid line of its own size. A range such as 10.0.0.5 to 10.0.0.130 starts and ends off the grid, so it cannot be one tile; it has to be tiled with several of different sizes.

The algorithm is greedy and provably minimal. Starting at the first address, it takes the largest block that is aligned at that address and does not run past the end, then continues after it. Sizes rise towards the middle of the range and fall again near the end, producing the familiar staircase of prefixes.

Exactness matters for security. Rounding a range out to the nearest single block would include addresses you did not intend to allow. The output here covers precisely the range and can be pasted into access control lists with confidence.

If your system limits the number of entries, consider whether a slightly larger aligned block is acceptable, or use the CIDR Calculator to merge neighbouring ranges first. Keep the original range in your documentation alongside the blocks.

Other useful tools