CIDR to IP RangeInternet Tools
CIDR block to start and end IP, and an IP range back to CIDR.
A block such as 192.168.0.0/22 hides its first address, its last address, and how many devices fit in it. Read the range from the prefix, check the usable hosts, then write the addresses in the form your firewall or database wants.
CIDR notation writes a network as an address and a prefix length. An IPv4 address is 32 bits, and the prefix says how many of those bits, counted from the left, name the network. The rest number the hosts. So 192.168.1.0/24 covers 192.168.1.0 to 192.168.1.255, which is 256 addresses. Change the prefix by one and the size doubles or halves.
Guessing the range causes real mistakes. A firewall rule that ends one address too early locks out a server. An allow list that starts in the middle of a block lets in addresses you did not mean to allow. Counting every address as a device is another trap: in a normal subnet the first address is the network address and the last is the broadcast address, and neither can be given to a device. A /24 has 256 addresses but 254 usable hosts.
A range that does not line up with a power of 2 is a third problem. A CIDR block always has a size that is a power of 2 and starts on a matching boundary. A range like 10.0.0.0 to 10.0.0.5, six addresses, cannot be one block. It needs a block of 4 and a block of 2.
Start with CIDR to IP Range. On the CIDR to range tab, enter a block such as 192.168.0.0/22 and press Calculate. It returns 192.168.0.0 to 192.168.3.255, 1,024 addresses. Tick List every address to get them one per line, and copy the result or download it as a .txt file for a firewall rule. The list stops at 65,536 entries, but the count is always shown in full. The Range to CIDR tab works the other way: enter a start and an end address of the same IP version, and it returns the fewest blocks that cover them. 10.0.0.0 to 10.0.0.5 becomes 10.0.0.0/30 and 10.0.0.4/31. If you type an address that is not the start of its block, such as 10.0.0.5/30, it shows the range of the block that contains it, with a note.
When you need the network, broadcast, and host count, use the IPv4 Subnet Calculator. Enter an IP address and a mask as a prefix (/26), a netmask (255.255.255.192), or a wildcard mask (0.0.0.63). For 192.168.1.130/26 it gives network 192.168.1.128, broadcast 192.168.1.191, hosts 192.168.1.129 to 192.168.1.190, and 62 usable hosts. A /31 has 2 usable addresses and no broadcast, for point-to-point links, and a /32 is a single host. Split into smaller subnets divides a block by a count or a prefix: 192.168.1.0/24 split in 4 gives four /26 networks with 62 hosts each. A mask whose one-bits are not all on the left, such as 255.0.255.0, is rejected, and so is an octet with a leading zero.
Some tools want the address as a number. The IP Address Converter reads an IPv4 address in dotted decimal, as one integer, in hex, in binary, or as an IPv4-mapped IPv6 address, and fills in every other form. 192.168.1.1 is 3232235777 and 0xC0A80101. Storing the integer takes 4 bytes instead of up to 15 characters, and a range check becomes a simple comparison between the first and last address. A single integer must be between 0 and 4,294,967,295.
192.168.0.0/22, on the CIDR to range tab and note the first address, the last address, and the count.The first 24 bits are the network part, so the block covers 192.168.1.0 to 192.168.1.255, which is 256 addresses.
254. A /24 has 256 addresses, and two are reserved: the network address (.0) and the broadcast address (.255).
A CIDR block always has a power-of-2 size and starts on a matching boundary. 10.0.0.0 to 10.0.0.5 is 6 addresses, so it needs a block of 4 and a block of 2.
Multiply the first octet by 16,777,216, the second by 65,536, the third by 256, and add the fourth. 192.168.1.1 gives 3,232,235,777.
Tools used in this guide
CIDR block to start and end IP, and an IP range back to CIDR.
Network, broadcast, host range, and masks for any IPv4 block.
IPv4 to decimal, hex, octal, binary, and IPv4-mapped IPv6.