Subnet Calculator: Compute a CIDR, Summarize Ranges and Check an IP

Subnet Calculator: Compute a CIDR, Summarize Ranges and Check an IP

Compute network, mask, host range and broadcast of a CIDR, summarize ranges into minimal blocks and check an IP, all in your browser. Nothing is uploaded.

11.10.2026
17 min read
Share this article:
NetworkingSubnetCIDRIPSysadmin

A CIDR block is a start and a size

Whenever you plan a VPC, write a firewall rule or build an allowlist, you handle blocks like 10.0.0.0/16. The CIDR notation hides some arithmetic: the start and end of the block, the host count, the overlap of two blocks, the reduction of ten entries to two. The Subnet Calculator takes an address and a prefix (or, in IPv4, a dotted mask). It shows the network, the mask, the wildcard and the broadcast. It also gives the first and last usable address, the host count and the address class, for IPv4 and IPv6 alike. The CIDR Summarize tool reads a list with one CIDR per line and reduces it to the fewest blocks that cover exactly the same addresses. The IP in Subnet tool tells you whether an IP belongs to a block, or whether two blocks overlap. All three tools compute in your browser and send no address to FastMinify. This guide recalls how a prefix sets the size of a block and how to read each field of the result. It shows how to summarize a list without inventing anything. It then covers the mistakes that cost the most, such as a subnet that is too small or two VPCs that overlap. Last, it repeats the same calculations in Python, in Node and with Terraform’s cidrsubnet function. The neighbouring tools live in the networking tools hub.

Subnet Calculator: IPv4 and IPv6, CIDR prefix or dotted mask (IPv4 only). It shows Network, Subnet mask, Wildcard, Broadcast, First usable, Last usable, Host count and Address class, with an optional binary view
Two ways to count hosts, Usable or Total. In IPv4 a /31 counts 2 hosts (RFC 3021) and a /32 counts 1. In IPv6 there is no broadcast and the usable count equals the total
CIDR Summarize: merges overlapping blocks and aligned adjacent blocks. It never fills a hole, skips blank lines and lines that start with #, and stops at the first invalid line with its number
IP in Subnet: contains mode tells whether an IP belongs to a CIDR, overlap mode whether two CIDRs share an address. The family is detected, or forced to IPv4 or IPv6
No network access: the tools ping nothing, resolve no name and query no registry. They do arithmetic on the addresses you type
A 64 KiB input limit per tool, and a calculation that stays in the tab

Which tool for which question

Good uses

These tools do address arithmetic. Use them to check a plan before you write it into a cloud console or a rules file.

Check an addressing plan before creating subnets: the network, broadcast and host count of every block, in the <a href="/en/subnet-calculator" class="text-primary hover:underline">Subnet Calculator</a>
Translate a mask read on a router or in a Windows dialog (<code>255.255.240.0</code>) into a prefix (<code>/20</code>) and a wildcard (<code>0.0.15.255</code>), which is what Cisco-style ACLs expect
Shrink a list of several dozen allowed addresses before you paste it into a security group, a WAF or a firewall that caps the number of rules, with the <a href="/en/cidr-summarize" class="text-primary hover:underline">CIDR Summarize tool</a>
Test a rule: does <code>10.1.2.3</code> belong to <code>10.1.0.0/16</code>? The <a href="/en/ip-in-subnet" class="text-primary hover:underline">IP in Subnet tool</a> answers in one sentence
Check that two ranges do not overlap before you peer networks or set up a VPN
Compare the subnet of a Docker Compose network (the <code>ipam</code> key) with the ranges of your company VPN. The <a href="/en/blog/validate-docker-compose-env-online" class="text-primary hover:underline">Docker Compose guide</a> covers validating the rest of the file
What belongs elsewhere

Each tool stops where another one starts, or where your own tooling starts.

Show an address in decimal, binary or hexadecimal: the <a href="/en/ip-address-converter" class="text-primary hover:underline">IP Address Converter</a>
Split a range such as <code>10.0.0.1-10.0.0.3</code> into CIDR blocks: the <a href="/en/ip-range-to-cidr" class="text-primary hover:underline">IP Range to CIDR converter</a>
Change the base of any number: the <a href="/en/number-base-converter" class="text-primary hover:underline">Number Base Converter</a>
Find out whether a machine answers, which path a packet takes or what DNS resolves: none of these tools sends a packet
Subtract the addresses your cloud provider keeps for itself: the provider’s documentation is the reference (see below)
Write the blocks in your infrastructure: the <a href="/en/blog/terraform-hcl-format-validate-online" class="text-primary hover:underline">Terraform guide</a> and the <a href="/en/blog/kubernetes-validate-yaml-manifests-online" class="text-primary hover:underline">Kubernetes guide</a> validate the files themselves, and <code>cidrsubnet</code> is shown below

Reading the results correctly

The calculator result, field by field

Enter an address and a prefix in the Subnet Calculator. Take 192.0.2.10 with /24, then 172.16.37.200 with /20.

Network is the address with its host bits set to zero: <code>192.0.2.10/24</code> gives <code>192.0.2.0</code>. You do not need to know the network address to type it in
Broadcast is the last address of the block. The first usable address is the network plus one, and the last is the broadcast minus one. For this /24, that means <code>192.0.2.1</code> to <code>192.0.2.254</code>, or 254 hosts
Wildcard is the mask inverted bit by bit: <code>0.0.0.255</code> for a /24, <code>0.0.15.255</code> for a /20. Cisco-style ACLs and OSPF <code>network</code> statements are written with it
The /20 in the example gives the network <code>172.16.32.0</code>, the broadcast <code>172.16.47.255</code>, the mask <code>255.255.240.0</code> and 4,094 usable hosts
A /31 holds two addresses, both usable on a point-to-point link (RFC 3021), and a /32 names a single address. The calculator applies both cases instead of subtracting two
Address class names the range. Private covers 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 (RFC 1918). Carrier-grade NAT covers 100.64.0.0/10 (RFC 6598). Reserved covers documentation ranges, including 192.0.2.0/24 (RFC 5737)
Summarizing a list of blocks

Paste one CIDR per line into the CIDR Summarize tool. Take 10.0.0.0/25, 10.0.0.128/25, 10.0.1.0/24 and 10.0.2.0/24: the result is two lines, 10.0.0.0/23 and 10.0.2.0/24.

Blank lines and lines that start with <code>#</code> are skipped. The first invalid line stops the calculation and the error gives its number
A CIDR without a prefix (<code>10.0.1.0</code>) is rejected. For a single address, write <code>/32</code>
Host bits are reduced to the network: <code>10.0.0.5/24</code> and <code>10.0.0.77/24</code> together give <code>10.0.0.0/24</code>
Two neighbouring blocks merge only if they align. <code>10.0.0.0/25</code> and <code>10.0.0.128/25</code> form a /24, but <code>10.0.1.0/24</code> and <code>10.0.2.0/24</code> stay two lines, because a /23 has to start at an even value of the third octet
A hole is never filled. <code>10.0.0.0/24</code> and <code>10.0.2.0/24</code> stay apart: the result covers exactly the same addresses as the input, no more and no less
An IPv4 and an IPv6 entry in the same list are rejected (“Mixed family on line 2”). Summarize each family separately
With the Merge overlaps option off, the tool only removes exact duplicates and merges nothing
Checking an IP or two ranges

The IP in Subnet tool has two modes, chosen with the Mode selector. The verdict is written out, for example “10.1.2.3 is inside 10.1.0.0/16”.

In contains mode, the first field takes an IP and the second a CIDR. In overlap mode, both fields take a CIDR
Two CIDR blocks are either nested or disjoint: they never overlap halfway. <code>10.0.0.0/16</code> and <code>10.0.128.0/17</code> overlap because the second sits inside the first, while <code>10.0.0.0/16</code> and <code>10.1.0.0/16</code> do not
The host bits of the CIDR are ignored: <code>10.1.2.3</code> is inside <code>10.1.5.9/16</code>, which is treated as <code>10.1.0.0/16</code>
Both fields must be of the same family. A mapped IPv6 address such as <code>::ffff:10.1.2.3</code> is not an IPv4 address. Against an IPv4 CIDR, the tool answers that the IP families do not match
Family offers auto, IPv4 or IPv6. Forcing a family rejects the other one instead of guessing
A CIDR without a prefix (<code>10.1.0.0</code>) is rejected as an invalid CIDR

Four mistakes that force a redeployment

Typing the prefix in the address field

The calculator has two fields, IP address and Prefix. If you type 192.0.2.10/24 in the first, it answers that the address must not contain “/” and that you should use the prefix field. This is on purpose: a field that accepted both forms would let ambiguous input through. In Mask mode, the second field expects a contiguous mask such as 255.255.240.0, and a mask such as 255.255.0.255 is rejected as invalid.

Pasting a full CIDR into the address field
Typing a wildcard (<code>0.0.15.255</code>) where a mask is expected
Choosing Mask mode for an IPv6 address, which has no dotted mask
Typing <code>24</code> in Mask mode, or <code>255.255.255.0</code> in CIDR mode
Put the bare address in the first field and the prefix, or the mask, in the second. For a CIDR you already have, split it at the “/”.
Sizing a cloud subnet from the host count

The calculator applies the general IPv4 rule, which is the total minus the network address and the broadcast. Cloud providers subtract more. Amazon VPC keeps the first four addresses and the last one of every subnet, which makes five. A /24 then offers 251 addresses, and a /28 offers 11 instead of 14. On AWS, the size of a VPC CIDR also runs from /16 to /28. Other providers have their own reservations, which only their documentation gives. The calculator does not know these reserved ranges.

Planning a /28 for 14 instances when only 11 addresses are free
Forgetting that managed services (load balancer, NAT gateway, network interfaces) use addresses from the same subnet
Sizing a subnet with no margin for an autoscaling group at peak load
Carrying the 254 hosts of a /24 into a cloud addressing plan without subtracting the reserved addresses
The subnet is full at the worst moment, and an AWS subnet cannot be resized: you create another one and move the resources.
Thinking that summarizing means widening

The tool’s summary is exact. The result covers the same addresses as the input, nothing more, which makes it safe for an allowlist. Writing 10.0.0.0/22 by hand to replace 10.0.0.0/23 and 10.0.2.0/24 is something else: you also allow 10.0.3.0/24, which was not in the list. Another reading trap is that the Ascending sort is a text sort. For the list 10.0.0.0/8, 9.0.0.0/8, 172.16.0.0/12, the result comes out as 10.0.0.0/8, 172.16.0.0/12, 9.0.0.0/8.

Replacing two separate blocks with a wider one “to keep it simple”, and opening addresses nobody asked for
Taking the Ascending sort for a numeric sort of the addresses
Comparing two summarized lists that were not sorted the same way
Summarizing IPv4 and IPv6 together and being surprised by the rejection
Let the tool produce the exact list, and treat any wider block as a security decision, made and reviewed as such.
Finding an overlap after the networks are connected

Two overlapping networks cannot be joined by peering, a transit gateway or a VPN without address translation. On AWS, two VPCs whose CIDRs overlap cannot be linked by peering or by a transit gateway. The case is common. Everyone picks 10.0.0.0/16, keeps the default VPC at 172.31.0.0/16, or lets Docker take 172.17.0.0/16 while the office network sits on 192.168.0.0/24. Overlap mode answers in one sentence before you have created anything.

Reusing the CIDR of a test VPC for production
Giving 10.0.0.0/16 to every project of the same organization
Testing only the cloud ranges and forgetting the office and VPN ones
Putting a Docker Compose subnet in a range the company network already uses
You have to renumber a network that is already running, which means recreating its subnets and its resources.

Prefixes, special ranges and IPv6 at a glance

Prefix, mask and block size

An IPv4 block holds 2 to the power of (32 minus the prefix) addresses. Each extra prefix bit halves the block. Here are the usual sizes, with the usable host count in parentheses.

<code>/16</code> has the mask <code>255.255.0.0</code> and holds 65,536 addresses (65,534 usable)
<code>/20</code> has the mask <code>255.255.240.0</code> and holds 4,096 addresses (4,094)
<code>/24</code> has the mask <code>255.255.255.0</code> and holds 256 addresses (254)
<code>/25</code> has the mask <code>255.255.255.128</code> and holds 128 addresses (126)
<code>/26</code> has the mask <code>255.255.255.192</code> and holds 64 addresses (62)
<code>/27</code> has the mask <code>255.255.255.224</code> and holds 32 addresses (30)
<code>/28</code> has the mask <code>255.255.255.240</code> and holds 16 addresses (14)
<code>/29</code> has the mask <code>255.255.255.248</code> and holds 8 addresses (6)
<code>/30</code> has the mask <code>255.255.255.252</code> and holds 4 addresses (2)
<code>/31</code> has the mask <code>255.255.255.254</code> and holds 2 addresses, both usable (RFC 3021)
<code>/32</code> has the mask <code>255.255.255.255</code> and names one address
The special blocks you meet most often

A few ranges have a meaning fixed by RFCs. The calculator recognizes them in the Address class field.

<code>10.0.0.0/8</code>, <code>172.16.0.0/12</code> (172.16.0.0 to 172.31.255.255) and <code>192.168.0.0/16</code> are the private ranges of RFC 1918, classed Private
<code>100.64.0.0/10</code> is the shared address space for carrier-grade NAT (RFC 6598), classed Carrier-grade NAT. Some mesh VPN services use it too, so do not take it for ordinary private space
<code>127.0.0.0/8</code> is loopback, and <code>169.254.0.0/16</code> is the link-local space of self-assigned addresses. Neither is routed
<code>192.0.2.0/24</code>, <code>198.51.100.0/24</code> and <code>203.0.113.0/24</code> are set aside for documentation (RFC 5737). So is <code>2001:db8::/32</code> in IPv6 (RFC 3849). The calculator classes <code>192.0.2.10</code> and <code>2001:db8::1</code> as Reserved, which is why its sample values show that
<code>0.0.0.0/0</code> covers the whole IPv4 space. It is the default route, and the “open to the world” rule of a security group
IPv4 and IPv6 side by side

All three tools accept both families, with a few differences worth knowing.

IPv4 has 32 bits, IPv6 has 128. An IPv6 address is written in hexadecimal groups of 16 bits. The sign <code>::</code> replaces a run of zero groups, once per address
The calculator prints IPv6 addresses in compressed form (RFC 5952), which may differ from what you typed
A <code>/64</code> is the usual size of a local segment, because stateless autoconfiguration (SLAAC) assumes a 64-bit interface identifier. It holds 18,446,744,073,709,551,616 addresses, which the tool prints in full
There is no broadcast in IPv6: the Broadcast field disappears from the result, and Usable equals Total
Mask mode (<code>255.255.255.0</code>) exists for IPv4 only. CIDR mode works for both families
Summarizing and the membership check also work in IPv6, as long as a single list does not mix the two families

The three tools, step by step

Compute a subnet

The Subnet Calculator recalculates as you type. There is no button to press.

1

Type the address

An IPv4 or IPv6 address, without a “/”. It does not have to be the network address: 192.0.2.10 works for the block 192.0.2.0/24.

2

Choose the prefix

CIDR mode expects a length, for example 24. Mask mode expects a dotted mask such as 255.255.255.0, for IPv4 only. For an IPv4 address, buttons for /32, /31, /30, /24, /16 and /8 fill the field.

3

Set the count and the binary view

Count switches between Usable and Total. The Binary option adds the address, the network and the mask in binary, useful to see where the prefix cuts an octet.

4

Copy a field or the whole result

Every field has its Copy button, and Copy all takes the lot. The address class is part of the result.

Summarize a list with CIDR Summarize

The CIDR Summarize tool reduces a list of blocks to its minimal form.

1

Paste the list

One CIDR per line, pasted or loaded from a file. Blank lines and comments that start with # are skipped, so you can paste an annotated export.

2

Choose Merge overlaps and the sort

The Merge overlaps switch, on by default, joins overlapping blocks and aligned adjacent blocks. Sort offers Ascending (a text sort) or None.

3

Read the result

It updates as you type and shows the family (IPv4 or IPv6) and the number of blocks. An invalid line is shown with its number, and the calculation stops there.

4

Copy the list

The resulting list pastes as it is into a security group, a firewall rule or a configuration file.

Check with IP in Subnet

The IP in Subnet tool answers with a written verdict.

1

Choose the mode

contains checks that an IP belongs to a CIDR. overlap checks that two CIDRs share at least one address.

2

Fill both fields

An IP and a CIDR in contains mode, two CIDRs in overlap mode. The sample values (10.1.2.3 and 10.1.0.0/16) show the format.

3

Set the family if needed

With Auto, the family is detected from the input. Forcing IPv4 or IPv6 rejects input from the other family instead of converting it.

4

Copy the verdict

The sentence, for example “10.0.0.0/16 and 10.0.128.0/17 overlap”, pastes into a ticket or a configuration review.

What the tools do not do

A few limits to know before you rely on them.

No packet is sent: no ping, no DNS resolution, no address registry lookup
No range reserved by a cloud provider is subtracted from the host count
A block is not split into smaller subnets: a /16 holds 256 /24 blocks, to be listed by hand or with cidrsubnet
Summarizing reads only CIDRs with a prefix. A start-end range goes through IP Range to CIDR first
The Ascending sort is a text sort, not a numeric sort of the addresses
Input is limited to 64 KiB per tool

The same calculations in Python, Node and Terraform

The ipaddress module in Python

The standard library does everything the three tools do. The classic trap is strict: by default, an address with host bits such as 192.0.2.10/24 raises a ValueError.

Basic example

import ipaddress # strict=False accepts host bits (192.0.2.10/24); the default strict=True raises ValueError net = ipaddress.ip_network('192.0.2.10/24', strict=False) print(net.network_address, net.broadcast_address) # 192.0.2.0 192.0.2.255 print(net.netmask, net.hostmask) # 255.255.255.0 0.0.0.255 (hostmask = wildcard) print(net.num_addresses) # 256 in total, 254 usable # Summarize: adjacent and overlapping blocks collapse, holes stay blocks = ['10.0.0.0/25', '10.0.0.128/25', '10.0.1.0/24', '10.0.2.0/24'] print(list(ipaddress.collapse_addresses(ipaddress.ip_network(b) for b in blocks))) # [IPv4Network('10.0.0.0/23'), IPv4Network('10.0.2.0/24')] # Contains and overlap print(ipaddress.ip_address('10.1.2.3') in ipaddress.ip_network('10.1.0.0/16')) # True print(ipaddress.ip_network('10.0.0.0/16').overlaps(ipaddress.ip_network('10.0.128.0/17'))) # True
The ipaddr.js library in Node

This is the library the tools use. It computes the network and the broadcast of a CIDR, and match() answers the question “is this IP inside this block”.

Basic example

import ipaddr from 'ipaddr.js' const cidr = '172.16.37.200/20' console.log(ipaddr.IPv4.networkAddressFromCIDR(cidr).toString()) // 172.16.32.0 console.log(ipaddr.IPv4.broadcastAddressFromCIDR(cidr).toString()) // 172.16.47.255 console.log(ipaddr.IPv4.subnetMaskFromPrefixLength(20).toString()) // 255.255.240.0 // match() is the "contains" check const ip = ipaddr.parse('10.1.2.3') console.log(ip.match(ipaddr.parseCIDR('10.1.0.0/16'))) // true console.log(ip.match(ipaddr.parseCIDR('10.2.0.0/16'))) // false
The cidrsubnet function in Terraform

In a Terraform plan, cidrsubnet carves up a block instead of copying CIDRs by hand. The Terraform guide covers formatting and validating the files; check the result of each split here before you apply it.

Basic example

locals { vpc_cidr = "10.0.0.0/16" # cidrsubnet(prefix, newbits, netnum): 16 + 8 new bits = a /24, and netnum 2 is the third one app_subnet = cidrsubnet(local.vpc_cidr, 8, 2) # "10.0.2.0/24" db_subnet = cidrsubnet(local.vpc_cidr, 8, 3) # "10.0.3.0/24" }
The FastMinify networking tools

Nothing to install and nothing uploaded. The Subnet Calculator, the CIDR Summarize tool and the IP in Subnet tool cover computing, reducing and testing a list of blocks. Their limits come down to three points: no cloud-reserved ranges, no splitting into subnets, a text sort. To see an address in decimal, binary and hexadecimal, use the IP Address Converter. The networking tools hub brings them all together.

Conclusion

A CIDR is a start and a size, and almost everything else follows. The mask, the broadcast, the host count, the merging of two blocks and the overlap all derive from them. The Subnet Calculator gives these values for IPv4 and IPv6. The CIDR Summarize tool reduces a list without ever filling a hole. The IP in Subnet tool answers two questions, “is this address inside this block” and “do these two blocks touch”. The calculation ignores the addresses your cloud provider reserves. A block wider than the original list is also a choice, not a simplification. Check for overlaps before you connect two networks, not after. The networking tools hub brings the neighbouring tools together.

Type the address and the prefix in two fields, and read the network, the broadcast and the host count before you create a subnet
Subtract the addresses your cloud provider reserves from the host count: five per subnet on AWS
Summarize an allowlist with the tool, which stays exact, and treat any wider block as a security decision
Test two ranges for overlap before a peering or a VPN, including against the office and Docker networks
Summarize IPv4 and IPv6 separately, and do not rely on the order of the Ascending sort
Share this article
Share this article: