IP Subnet Overlap Checker
Check a list of subnets for overlaps, containment and duplicates before they collide in a VPN, a VPC peering or a network merge, and see which specific addresses conflict.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Overlaps surface at the worst moment
Two networks with overlapping address space cannot be routed together. That is fine while they are separate and becomes an immediate problem the day a site to site VPN is configured, two cloud VPCs are peered, or two companies merge their networks. The failure is not subtle: traffic destined for the remote network is delivered locally instead, because the local route always wins, and the symptom is that some remote hosts are unreachable while others work.
The default ranges collide constantly
An enormous proportion of networks use 192.168.0.0/24 or 192.168.1.0/24 because those are the factory defaults on consumer routers, and 10.0.0.0/24 because it is the obvious first choice. Any VPN connecting two such sites overlaps immediately. RFC 1918 provides nearly eighteen million private addresses; using a randomly chosen /24 from deep inside 10.0.0.0/8 costs nothing at design time and avoids the problem entirely.
Containment is an overlap too
A frequent pattern is a broad allocation such as 10.0.0.0/8 alongside specific subnets like 10.20.30.0/24 that sit inside it. Within one routing domain that is normal and the longest prefix wins. Between two domains being joined it is a conflict, because the broad prefix on one side claims addresses the other side is using. The checker reports containment separately from partial overlap for that reason.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
What happens when two networks overlap on a VPN?
The local route wins, so traffic for the overlapping remote addresses never leaves the local network. The result is that some remote hosts are unreachable while others work, which is a confusing symptom until the overlap is noticed.
Can I fix an overlap without renumbering?
NAT on the tunnel can translate one side into a spare range, and most VPN concentrators support it. It works and it makes every subsequent diagnosis harder, because addresses in logs on one side do not correspond to addresses on the other. Renumbering is usually cheaper over the life of the network.
How do I pick ranges that will not collide?
Choose randomly from deep inside 10.0.0.0/8 rather than starting at 10.0.0.0, and avoid 192.168.0.0/24 and 192.168.1.0/24 entirely since they are consumer router defaults. RFC 1918 has nearly 18 million private addresses; the collisions come from everyone picking the same few.
Is containment the same as an overlap?
It is a special case where one subnet lies entirely inside another. Within a single routing domain that is normal and longest prefix match resolves it. Between two domains being joined it is a conflict, because the broader prefix claims addresses the other side uses.
Does this apply to cloud VPCs?
Very much so. AWS, Azure and Google all refuse to create a peering connection between VPCs with overlapping CIDR blocks, and the default VPC ranges in each provider are well known and frequently collide with on premises networks.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste your subnets to see every overlapping pair and the addresses they share.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.