taap.digitalnetwork engineering toolkit

IP range to CIDR converter

Give the first and last address of a range. The tool returns the smallest set of aligned CIDR blocks that covers it with no extra addresses.

range2cidr

Why a range is rarely one prefix

A CIDR block must start at a multiple of its own size. An arbitrary range such as 192.168.1.10 – 192.168.1.100 does not start or end on such boundaries, so it has to be expressed as several blocks. Firewalls, ACLs, prefix lists and cloud security groups only accept prefixes, which is why this conversion comes up constantly.

The greedy algorithm

Starting from the first address, the tool repeatedly picks the largest block that:

  1. is aligned (the current address is a multiple of the block size), and
  2. does not run past the end address.

It emits that block, moves to the address right after it and repeats. This produces the minimal list of blocks for any range.

Worked example: 192.168.1.10 – 192.168.1.100

BlockRangeAddresses
192.168.1.10/31.10 – .112
192.168.1.12/30.12 – .154
192.168.1.16/28.16 – .3116
192.168.1.32/27.32 – .6332
192.168.1.64/27.64 – .9532
192.168.1.96/30.96 – .994
192.168.1.100/32.1001

Seven blocks, 91 addresses in total, exactly 100 − 10 + 1. Note that .32/27 and .64/27 cannot merge into a /26: a /26 must start at .0, .64, .128 or .192.

Using the output

! Cisco IOS prefix list
ip prefix-list RANGE seq 5 permit 192.168.1.10/31
ip prefix-list RANGE seq 10 permit 192.168.1.12/30
...

# Linux nftables set
nft add element inet filter allowed { 192.168.1.10/31, 192.168.1.12/30, 192.168.1.16/28 }

# MikroTik address list
/ip firewall address-list add list=range address=192.168.1.16/28

Many platforms (MikroTik address lists, nftables, iptables with -m iprange) also accept a native range. Prefix form is still preferable when the rule must be portable or synced across devices.

Tips

  • If you control the range, move its boundaries to aligned values. 192.168.1.0 – 192.168.1.127 is one /25 instead of seven entries.
  • Large irregular ranges (for example from a geo-IP or WHOIS export) can expand to dozens of prefixes; TCAM space on switches is finite, so check the hardware entry budget.
  • The order of start and end does not matter; the tool swaps them if needed.
  • When importing ranges from DHCP scopes or vendor documentation, double-check whether the end address is inclusive. An off-by-one at the end can add a whole extra /32 entry, or leave the last host uncovered.

For the reverse direction, turning a CIDR block into its first and last address, use the IPv4 subnet calculator: the network and broadcast addresses are exactly the start and end of the block.

Frequently asked questions

Is the result always minimal?

Yes. The greedy largest-aligned-block approach yields the minimum number of CIDR blocks for a contiguous range.

Can a range ever be a single block?

Only when the start is a multiple of the range size and the size is a power of two, for example 10.0.0.0 – 10.0.0.255 (/24) or 172.16.4.0 – 172.16.7.255 (/22).

Does it handle IPv6 ranges?

No, this tool is IPv4 only. For IPv6, use the IPv6 subnet calculator to plan aligned prefixes instead of ranges.

Study and design tool. Validate any configuration in a lab and against vendor documentation before applying it in production.