CIDR summarization and aggregation
Simplify your prefix list for a routing table, firewall or cloud security group. Paste prefixes, single addresses and ranges; adjacent prefixes merge and covered ones drop out. Optionally see how many extra addresses a single supernet would cover, or subtract a deny list from an allow list.
Write one or more entries per line (separated by space, comma or semicolon). Formats: 10.0.0.0/24, 10.0.0.5, 10.0.0.1-10.0.0.9, 2001:db8::/32, 2001:db8::1-2001:db8::9. Text after # is a comment.
Results
IPv4
- Aggregated prefixes
- 3
- 7 entries → 3 prefixes
- Unique addresses covered
- 1,034
- Sum of input addresses (with duplicates): 1,165
Aggregated set
- 10.0.0.0/22
- 192.168.10.0/29
- 192.168.10.8/31
IPv6
- Aggregated prefixes
- 1
- 3 entries → 1 prefixes
- Unique addresses covered
- ≈ 7.92 × 10^28
- Sum of input addresses (with duplicates): ≈ 7.92 × 10^28
Aggregated set
- 2001:db8::/32
Firewall warning: aggregation is a simplification that preserves the addresses exactly; a single supernet widens the scope. Review the extra addresses before using a supernet in an allow rule, and remember that in a deny rule unexpected addresses may be blocked too.
Calculation and assumptions
- Each entry becomes a [start, end] range: for a prefix, the network address and network address + 2^(bits − prefix) − 1; for a single address, start = end. IPv4 has 32 bits, IPv6 128; numbers are BigInt.
- Aggregation: ranges are sorted by start; overlapping or adjacent ranges (start ≤ previous end + 1) merge. Each resulting range is split into the largest blocks that fit address alignment, which gives the fewest prefixes for the same address set.
- Supernet: prefix = bits − bitLength(lowest start XOR highest end). Extra addresses = supernet size − unique addresses in the union.
- Subtraction: allow union − deny union is a range difference; the remaining ranges are again split into the fewest CIDRs. IPv4 and IPv6 are calculated separately.
The lists you enter are processed in your browser; they are not sent to a server and not stored.
This tool does address-set arithmetic; it does not take into account a routing protocol's summarization rules, metrics, route filters or your device's rule limits. Verify the output in your own environment and change process before applying it to a live configuration.
Shall we simplify and document your network, firewall and cloud security group rules together?
Request a meeting01
How to use
A
Paste your list of prefixes, single addresses or ranges; you can write one or several entries per line. Unreadable entries are shown with line and column.
B
Choose the operation: the smallest aggregated set, a single supernet (with its extra addresses), an overlap and duplicate report, or subtracting one list from another.
C
Copy the output or download it as a text file; if you plan to use a supernet, check the extra addresses it covers.
02
How are prefixes merged?
Two adjacent blocks of equal size merge into the parent prefix if they are aligned: 10.0.0.0/24 and 10.0.1.0/24 become 10.0.0.0/23. If they are not aligned (for example 10.0.1.0/24 and 10.0.2.0/24) they do not form one prefix, yet the same address set is still described. This tool merges the ranges and then splits each range into the largest blocks that fit address alignment, which gives the fewest prefixes for the same addresses.
Entries that lie inside another prefix are dropped and duplicates count once. Single addresses are treated as /32 (/128 in IPv6); a.b.c.d-e.f.g.h ranges are split into several CIDR blocks when necessary.
03
When is a single supernet fine, and when is it risky?
A supernet is the single prefix covering the lowest start and the highest end of the list. If the addresses are close together there is little excess; if they are scattered the supernet becomes very wide and includes addresses that are not in your list. The tool shows the number of extra addresses and what percentage of the supernet they make up.
In routing summarization this is often an acceptable trade-off; in a firewall allow rule the extra addresses may open access. Before deciding, look at the share of excess and who owns those addresses. If needed, use the aggregated set instead of a single supernet.
04
What are subtraction and the overlap report for?
Subtraction removes a deny list from an allow list and writes the remaining addresses with the fewest prefixes; for example, removing 10.0.1.0/24 from 10.0.0.0/22 leaves three prefixes. This is useful for turning a firewall allow rule with an exception into a set of prefixes without exceptions.
The overlap report shows duplicates, entries that lie inside another entry and partially overlapping ranges, with their line numbers. As a rule base grows it is a good starting point for cleaning out redundant entries.
FAQ
- Are my lists sent anywhere?
- No. The calculation runs in code in your browser; lists are not sent to any server and are not stored.
- What is the difference between aggregation and a supernet?
- Aggregation writes the same address set with the fewest prefixes; it neither adds nor removes addresses. A supernet gathers the whole list into one prefix and covers the gaps in between, so it may include extra addresses.
- Why do some prefixes not merge?
- Two blocks merge only if they are both adjacent and aligned to a parent-prefix boundary. 10.0.1.0/24 and 10.0.2.0/24 are adjacent but do not form a single /23; the tool leaves them as two prefixes.
- What happens to an entry with host bits set?
- Entries such as 10.0.0.5/24 are rounded down to the network address (10.0.0.0/24) and a note is shown. If you mean only that address, write /32 (/128 in IPv6) or enter the address without a prefix.
- Can I mix IPv4 and IPv6 in one list?
- Yes. Results are calculated and shown separately per type. Both ends of a range must be the same type.
- Can I paste the output straight into a router or firewall?
- The output has one CIDR per line; most devices accept this format, but the syntax varies by vendor. Verify it in your own environment before applying it to a live configuration.
Has your rule base become complicated?
Let us simplify and document your network, firewall and cloud security group rules together and add monitoring. In a free discovery call we discuss your current state.