
Subnet Calculator: Compute a CIDR, Summarize Ranges and Check an IP
Compute network, mask, host range and broadcast of a CIDR, summarize ranges into minimal blocks and check an IP, all in your browser. Nothing is uploaded.
A CIDR block is a start and a size
Whenever you plan a VPC, write a firewall rule or build an allowlist, you handle blocks like 10.0.0.0/16. The CIDR notation hides some arithmetic: the start and end of the block, the host count, the overlap of two blocks, the reduction of ten entries to two. The Subnet Calculator takes an address and a prefix (or, in IPv4, a dotted mask). It shows the network, the mask, the wildcard and the broadcast. It also gives the first and last usable address, the host count and the address class, for IPv4 and IPv6 alike. The CIDR Summarize tool reads a list with one CIDR per line and reduces it to the fewest blocks that cover exactly the same addresses. The IP in Subnet tool tells you whether an IP belongs to a block, or whether two blocks overlap. All three tools compute in your browser and send no address to FastMinify. This guide recalls how a prefix sets the size of a block and how to read each field of the result. It shows how to summarize a list without inventing anything. It then covers the mistakes that cost the most, such as a subnet that is too small or two VPCs that overlap. Last, it repeats the same calculations in Python, in Node and with Terraform’s cidrsubnet function. The neighbouring tools live in the networking tools hub.
Which tool for which question
These tools do address arithmetic. Use them to check a plan before you write it into a cloud console or a rules file.
Each tool stops where another one starts, or where your own tooling starts.
Reading the results correctly
Enter an address and a prefix in the Subnet Calculator. Take 192.0.2.10 with /24, then 172.16.37.200 with /20.
Paste one CIDR per line into the CIDR Summarize tool. Take 10.0.0.0/25, 10.0.0.128/25, 10.0.1.0/24 and 10.0.2.0/24: the result is two lines, 10.0.0.0/23 and 10.0.2.0/24.
The IP in Subnet tool has two modes, chosen with the Mode selector. The verdict is written out, for example “10.1.2.3 is inside 10.1.0.0/16”.
Four mistakes that force a redeployment
The calculator has two fields, IP address and Prefix. If you type 192.0.2.10/24 in the first, it answers that the address must not contain “/” and that you should use the prefix field. This is on purpose: a field that accepted both forms would let ambiguous input through. In Mask mode, the second field expects a contiguous mask such as 255.255.240.0, and a mask such as 255.255.0.255 is rejected as invalid.
The calculator applies the general IPv4 rule, which is the total minus the network address and the broadcast. Cloud providers subtract more. Amazon VPC keeps the first four addresses and the last one of every subnet, which makes five. A /24 then offers 251 addresses, and a /28 offers 11 instead of 14. On AWS, the size of a VPC CIDR also runs from /16 to /28. Other providers have their own reservations, which only their documentation gives. The calculator does not know these reserved ranges.
The tool’s summary is exact. The result covers the same addresses as the input, nothing more, which makes it safe for an allowlist. Writing 10.0.0.0/22 by hand to replace 10.0.0.0/23 and 10.0.2.0/24 is something else: you also allow 10.0.3.0/24, which was not in the list. Another reading trap is that the Ascending sort is a text sort. For the list 10.0.0.0/8, 9.0.0.0/8, 172.16.0.0/12, the result comes out as 10.0.0.0/8, 172.16.0.0/12, 9.0.0.0/8.
Two overlapping networks cannot be joined by peering, a transit gateway or a VPN without address translation. On AWS, two VPCs whose CIDRs overlap cannot be linked by peering or by a transit gateway. The case is common. Everyone picks 10.0.0.0/16, keeps the default VPC at 172.31.0.0/16, or lets Docker take 172.17.0.0/16 while the office network sits on 192.168.0.0/24. Overlap mode answers in one sentence before you have created anything.
Prefixes, special ranges and IPv6 at a glance
An IPv4 block holds 2 to the power of (32 minus the prefix) addresses. Each extra prefix bit halves the block. Here are the usual sizes, with the usable host count in parentheses.
A few ranges have a meaning fixed by RFCs. The calculator recognizes them in the Address class field.
All three tools accept both families, with a few differences worth knowing.
The three tools, step by step
The Subnet Calculator recalculates as you type. There is no button to press.
Type the address
An IPv4 or IPv6 address, without a “/”. It does not have to be the network address: 192.0.2.10 works for the block 192.0.2.0/24.
Choose the prefix
CIDR mode expects a length, for example 24. Mask mode expects a dotted mask such as 255.255.255.0, for IPv4 only. For an IPv4 address, buttons for /32, /31, /30, /24, /16 and /8 fill the field.
Set the count and the binary view
Count switches between Usable and Total. The Binary option adds the address, the network and the mask in binary, useful to see where the prefix cuts an octet.
Copy a field or the whole result
Every field has its Copy button, and Copy all takes the lot. The address class is part of the result.
The CIDR Summarize tool reduces a list of blocks to its minimal form.
Paste the list
One CIDR per line, pasted or loaded from a file. Blank lines and comments that start with # are skipped, so you can paste an annotated export.
Choose Merge overlaps and the sort
The Merge overlaps switch, on by default, joins overlapping blocks and aligned adjacent blocks. Sort offers Ascending (a text sort) or None.
Read the result
It updates as you type and shows the family (IPv4 or IPv6) and the number of blocks. An invalid line is shown with its number, and the calculation stops there.
Copy the list
The resulting list pastes as it is into a security group, a firewall rule or a configuration file.
The IP in Subnet tool answers with a written verdict.
Choose the mode
contains checks that an IP belongs to a CIDR. overlap checks that two CIDRs share at least one address.
Fill both fields
An IP and a CIDR in contains mode, two CIDRs in overlap mode. The sample values (10.1.2.3 and 10.1.0.0/16) show the format.
Set the family if needed
With Auto, the family is detected from the input. Forcing IPv4 or IPv6 rejects input from the other family instead of converting it.
Copy the verdict
The sentence, for example “10.0.0.0/16 and 10.0.128.0/17 overlap”, pastes into a ticket or a configuration review.
A few limits to know before you rely on them.
cidrsubnetstart-end range goes through IP Range to CIDR firstThe same calculations in Python, Node and Terraform
The standard library does everything the three tools do. The classic trap is strict: by default, an address with host bits such as 192.0.2.10/24 raises a ValueError.
Basic example
This is the library the tools use. It computes the network and the broadcast of a CIDR, and match() answers the question “is this IP inside this block”.
Basic example
In a Terraform plan, cidrsubnet carves up a block instead of copying CIDRs by hand. The Terraform guide covers formatting and validating the files; check the result of each split here before you apply it.
Basic example
Nothing to install and nothing uploaded. The Subnet Calculator, the CIDR Summarize tool and the IP in Subnet tool cover computing, reducing and testing a list of blocks. Their limits come down to three points: no cloud-reserved ranges, no splitting into subnets, a text sort. To see an address in decimal, binary and hexadecimal, use the IP Address Converter. The networking tools hub brings them all together.
Conclusion
A CIDR is a start and a size, and almost everything else follows. The mask, the broadcast, the host count, the merging of two blocks and the overlap all derive from them. The Subnet Calculator gives these values for IPv4 and IPv6. The CIDR Summarize tool reduces a list without ever filling a hole. The IP in Subnet tool answers two questions, “is this address inside this block” and “do these two blocks touch”. The calculation ignores the addresses your cloud provider reserves. A block wider than the original list is also a choice, not a simplification. Check for overlaps before you connect two networks, not after. The networking tools hub brings the neighbouring tools together.
Compute a subnet in your browser
Related Articles

Format a Copy as cURL, parse a raw HTTP request or response and read a HAR export in your browser: nothing is sent, nothing is replayed.

Decode a JWT header and payload, or sign a test token, right in your browser: HS256, RS256, ES256, with no secret sent to a third-party server.

Length, entropy, symbols: generate a strong password in your browser with Web Crypto, no network transit, and know what the tool does not guarantee.