IP Range to CIDR
Give it a start and an end address. It returns the smallest exact set of prefixes covering that range and nothing more.
Local toolYour network plan stays in your browser. Nothing you enter is uploaded, logged, or sent to any server.
Why a range often needs several prefixes
A CIDR prefix can only start on an address that is a multiple of its own size. So a range beginning at 192.168.1.1 cannot be a single block — the first address is not aligned to anything larger than a /32.
The algorithm walks from the start, taking the largest block that both begins at the current address and does not run past the end, then repeats. That produces the minimal exact set.
Exact means exact. The result never includes an address outside the range you gave. Tools that return a single "closest" prefix are giving you a supernet that covers addresses you did not ask for, which in a firewall rule is a security problem rather than a rounding convenience.
Why a range becomes several prefixes
A CIDR prefix cannot describe an arbitrary range. It can only describe a block whose size is a power of two and which starts on a multiple of its own size. So a range like 192.0.2.5 to 192.0.2.20 has no single prefix. It is covered exactly by five: 192.0.2.5/32, 192.0.2.6/31, 192.0.2.8/29, 192.0.2.16/30 and 192.0.2.20/32 — because the range starts and ends part-way through blocks at both ends, and the arithmetic has to step down to smaller and smaller blocks to land on them exactly.
The method is greedy and it is exact. At each step it takes the largest aligned block that starts at the current address and does not run past the end of the range, emits it, and moves on. That produces the smallest possible set covering the range and nothing outside it — never a prefix that spills over the boundary you gave.
The practical consequence: choose aligned ranges
Ranges written by people tend to start and end at round decimal numbers — .1, .10, .100 — and round decimal numbers are almost never aligned binary boundaries. A DHCP pool of .100 to .200 is a perfectly reasonable thing to write down, and it expands to six prefixes. Widen it slightly to .96 to .223 and it becomes three, while covering more addresses. The tidier-looking range is the more expensive one.
This matters most where prefixes are enumerated rather than stored as ranges: access lists, firewall objects, route filters, security-group rules. In those places, an unaligned range is not just untidy; it multiplies the number of lines somebody has to read, review and later modify. Deciding the boundary when you allocate the space costs nothing. Fixing it afterwards means renumbering.
Related tools
CIDR Aggregator merges a list of prefixes. CIDR Range Calculator goes from a prefix to its boundaries.