Home › Networking › CIDR Aggregator

CIDR Aggregator

Paste a list of prefixes. It drops the ones already covered, merges true siblings, and leaves the smallest equivalent set.

Local toolYour network plan stays in your browser. Nothing you enter is uploaded, logged, or sent to any server.

What it will and will not merge

Two prefixes merge only when they are genuine siblings: the same length, adjacent, and sharing a parent one bit shorter. 10.0.0.0/25 and 10.0.0.128/25 merge into 10.0.0.0/24.

10.0.1.0/24 and 10.0.2.0/24 do not merge, even though they look adjacent. The smallest prefix covering both is 10.0.0.0/22, which also covers 10.0.0.0/24 and 10.0.3.0/24 — addresses that were not in your list. Silently including them would be wrong, and in a firewall rule or a route filter it would be a security problem.

Prefixes already contained in another are dropped, since listing both adds nothing. IPv4 and IPv6 are aggregated separately and never mixed.

Why two prefixes do not always merge

Summarising is not simply a matter of two blocks being next to each other. Two prefixes merge into one shorter prefix only if they are the same length, adjacent, and aligned — that is, the first of the pair must start on a boundary that is itself a multiple of the combined size. 192.0.2.0/25 and 192.0.2.128/25 merge into 192.0.2.0/24. But 192.0.2.128/25 and 192.0.3.0/25 are adjacent and the same size, and they do not merge, because the combined block would have to start at 192.0.2.128, which is not a /24 boundary.

This is why an address plan that was allocated tidily summarises into a handful of routes and one that grew by grabbing the next free block summarises into almost nothing. The alignment is decided when the space is handed out, not when someone later tries to compress it.

What over-aggregation costs

It is always possible to make a route table shorter by advertising a bigger block. It is rarely safe. Announcing a summary that covers space you do not actually carry means traffic for those addresses is drawn towards you and then dropped, and from the sender's point of view the destination is simply unreachable — with nothing in your own logs to suggest why. This tool never widens a prefix to make a set smaller. It only removes entries already covered by another entry you supplied, and merges true siblings, so the result covers exactly the same addresses as the input and not one more.

Summarising for a firewall rule is a different exercise from summarising for a routing table. A route that is slightly too broad sends traffic somewhere it can be dropped later; an access list that is slightly too broad permits something you meant to deny. It is worth knowing which of the two you are doing before you compress anything.

Related tools

IP Range to CIDR converts two addresses into prefixes. Subnet Calculator inspects one prefix in detail.