CIDR Aggregator
Merge a list of CIDR prefixes into the smallest equivalent set, removing duplicates and overlaps and combining adjacent blocks, to shrink firewall rules and routing tables.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Prefix lists grow and never shrink
An allow list accumulates entries over years as customers are added, offices open and cloud ranges change. Nobody removes anything, because removing an entry requires knowing it is safe to remove. The result is a list where the same address appears in several entries, where adjacent blocks that could be one prefix are listed separately, and where a broad prefix silently contains a dozen narrower ones that are therefore doing nothing.
Aggregation is exact, not approximate
Two adjacent prefixes of the same size whose combined range aligns can be replaced by one prefix of the next size up, covering exactly the same addresses and no others. 10.0.0.0/25 and 10.0.0.128/25 become 10.0.0.0/24. This is not a simplification that admits extra addresses; it is the same set expressed more compactly, which is why it can be applied to a firewall rule without any change in what is permitted.
Smaller lists are faster and more reviewable
Hardware routers hold prefixes in a limited TCAM, and access control lists are evaluated per packet, so list length has a real cost. The larger benefit is human: a list of twelve entries can be reviewed and understood, while a list of four hundred containing sixty redundant entries cannot, and the redundancy hides genuine mistakes.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
Does aggregation change which addresses are allowed?
No. Merging only combines adjacent aligned prefixes and removes entries already contained in a broader one. The resulting set covers exactly the same addresses. Anything that changed the coverage would not be aggregation.
Why can 10.0.0.0/25 and 10.0.1.0/25 not be merged?
Because they are not adjacent: 10.0.0.128/25 sits between them. Two prefixes merge only when they are the same size, adjacent, and the lower one starts on a boundary of the combined size.
What is a supernet?
A prefix that contains several smaller ones, so 10.0.0.0/16 is a supernet of 10.0.1.0/24. When both appear in a list, the narrower one is redundant and can be removed with no effect.
Should I always aggregate?
For firewall rules and allow lists, yes. In BGP, aggregation removes information about which specific prefixes are reachable, so an aggregate covering a range you do not fully control can attract traffic for addresses you cannot deliver. Aggregate what you originate, not what you learn.
How do I find redundant entries?
That is what this does: any prefix contained in another is reported as removable, and any set of adjacent prefixes that combine is merged. Both are shown so the change can be reviewed rather than applied blindly.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste a list of CIDR prefixes to see them merged into the minimum equivalent set.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.