Why a range is rarely one prefix
A CIDR block must start at a multiple of its own size. An arbitrary range such as 192.168.1.10 – 192.168.1.100 does not start or end on such boundaries, so it has to be expressed as several blocks. Firewalls, ACLs, prefix lists and cloud security groups only accept prefixes, which is why this conversion comes up constantly.
The greedy algorithm
Starting from the first address, the tool repeatedly picks the largest block that:
- is aligned (the current address is a multiple of the block size), and
- does not run past the end address.
It emits that block, moves to the address right after it and repeats. This produces the minimal list of blocks for any range.
Worked example: 192.168.1.10 – 192.168.1.100
| Block | Range | Addresses |
|---|---|---|
| 192.168.1.10/31 | .10 – .11 | 2 |
| 192.168.1.12/30 | .12 – .15 | 4 |
| 192.168.1.16/28 | .16 – .31 | 16 |
| 192.168.1.32/27 | .32 – .63 | 32 |
| 192.168.1.64/27 | .64 – .95 | 32 |
| 192.168.1.96/30 | .96 – .99 | 4 |
| 192.168.1.100/32 | .100 | 1 |
Seven blocks, 91 addresses in total, exactly 100 − 10 + 1. Note that .32/27 and .64/27 cannot merge into a /26: a /26 must start at .0, .64, .128 or .192.
Using the output
! Cisco IOS prefix list
ip prefix-list RANGE seq 5 permit 192.168.1.10/31
ip prefix-list RANGE seq 10 permit 192.168.1.12/30
...
# Linux nftables set
nft add element inet filter allowed { 192.168.1.10/31, 192.168.1.12/30, 192.168.1.16/28 }
# MikroTik address list
/ip firewall address-list add list=range address=192.168.1.16/28
Many platforms (MikroTik address lists, nftables, iptables with -m iprange) also accept a native range. Prefix form is still preferable when the rule must be portable or synced across devices.
Tips
- If you control the range, move its boundaries to aligned values. 192.168.1.0 – 192.168.1.127 is one /25 instead of seven entries.
- Large irregular ranges (for example from a geo-IP or WHOIS export) can expand to dozens of prefixes; TCAM space on switches is finite, so check the hardware entry budget.
- The order of start and end does not matter; the tool swaps them if needed.
- When importing ranges from DHCP scopes or vendor documentation, double-check whether the end address is inclusive. An off-by-one at the end can add a whole extra /32 entry, or leave the last host uncovered.
For the reverse direction, turning a CIDR block into its first and last address, use the IPv4 subnet calculator: the network and broadcast addresses are exactly the start and end of the block.