IP Range to CIDR Converter
Convert an arbitrary IP address range into the minimum set of CIDR prefixes that covers it exactly, and convert prefixes back to a range, for firewall rules and access lists.
Last reviewed by the Radiatus Cloud team
CIDR back to a range
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Firewalls speak CIDR, humans think in ranges
Access control lists, security groups, routing tables and allow lists all express addresses as prefixes. People express them as ranges: this customer has 192.0.2.10 through 192.0.2.57. Those two forms rarely correspond to a single prefix, because a CIDR block must start at an address that is a multiple of its own size, so an arbitrary range decomposes into several blocks of different sizes.
Rounding to a bigger prefix is the common mistake
Faced with a range that does not fit one prefix, the shortcut is to pick the smallest prefix containing it and use that. That prefix almost always contains addresses outside the intended range, and in a firewall rule those are addresses being granted access that nobody meant to grant. The decomposition into several exact blocks is a few more lines in the rule set and it grants precisely what was asked for.
The decomposition is greedy and optimal
Starting at the first address, take the largest block that both aligns to the current position and does not overrun the end, then repeat from the new position. That greedy procedure produces the minimum number of prefixes covering the range exactly, which is why every implementation uses it. A range of 48 addresses starting at .10 needs six blocks; the same 48 addresses starting at .0 need one.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
Why does my range need several CIDR blocks?
Because a prefix must start at an address that is a multiple of its size. A range starting at .10 cannot begin a /28, which must start at .0 or .16, so it decomposes into smaller aligned blocks until it reaches an aligned boundary.
Can I just use the smallest prefix containing my range?
You can, and it will include addresses outside the range. In a firewall rule that means granting access to hosts nobody intended. The tool shows both the exact decomposition and the containing prefix with the number of extra addresses it would admit.
How many prefixes can a range need?
Up to 62 for an arbitrary IPv4 range, though most real ranges need far fewer. Aligning the range boundaries to powers of two, when you have any say in how addresses are allocated, reduces it dramatically.
What is the difference between a range and a network?
A network is a range that happens to start on an aligned boundary and have a power of two size, so it can be written as one prefix. Every network is a range; most ranges are not networks.
Does the same apply to IPv6?
The principle is identical, though the address space is large enough that ranges are almost always allocated on prefix boundaries in the first place. This tool handles IPv4; for IPv6 the alignment rule is the same with 128 bits instead of 32.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter a start and end address to get the CIDR blocks covering exactly that range.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.