CIDR calculator
Examples:
Addresses
Transparency
Everything is computed in your browser, by the scripts listed below. What you type never leaves this page.
- Enforced by your browser
- This page's Content Security Policy allows a single destination, the site's audience measurement (
connect-src https://stats.r-no.fr, see below), and forbids any form submission (form-action 'none'). You can read the policy at the top of the page source. - Audience measurement
- Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (
stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
SHA-256225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716 - https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
- What is stored
- No cookie, and nothing in the address. What you type is not kept. Your language is given by the address itself (
/en/or/fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name). It never receives what you type. - Code that runs here
-
- app.js: the calculator, written for R-no Toolbox. Not minified, no third-party library. IPv4 and IPv6 use the same arithmetic on 32- and 128-bit integers (BigInt). 12.9 kB
SHA-2562f26e62b357a9494cb132fde18c7b860d5e705902d0c532364c8068dabf5834b - textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 5.1 kB
SHA-256d6fc6621c65d6b71645447778121f431d1b4e974c366d89c0822f464ee2a0c98 - /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
SHA-25680f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
- app.js: the calculator, written for R-no Toolbox. Not minified, no third-party library. IPv4 and IPv6 use the same arithmetic on 32- and 128-bit integers (BigInt). 12.9 kB
- Tested
- The arithmetic is covered by automated tests, run on every deployment: /31 and /32 ranges, /0, IPv6 compression (RFC 5952), IPv4 inside IPv6, and the rejection of malformed input.
- Check it yourself
- Download a script and compare its fingerprint with the one above:
curl -s https://r-no.fr/ip/cidr/app.js | shasum -a 256 - Limits
- The full list is shown up to 65,536 addresses (an IPv4 /16, an IPv6 /112). In IPv4, the first and last addresses of a range up to /30 are counted as network and broadcast, and are not usable by hosts; /31 and /32 follow RFC 3021. IPv6 has no broadcast. The range type comes from the usual IANA special-purpose registries, not from a live lookup.