IP range to CIDR

You can also paste a whole range into the first field: 10.0.0.5 - 10.0.1.20.

Examples:

CIDR blocks

    Copy as

    Transparency

    Everything is computed in your browser, by the scripts listed below. What you type never leaves this page.

    Enforced by your browser
    This page's Content Security Policy allows a single destination, the site's audience measurement (connect-src https://stats.r-no.fr, see below), and forbids any form submission (form-action 'none'). You can read the policy at the top of the page source.
    Audience measurement
    Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.
    • /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
      SHA-256 225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716
    • https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
    What is stored
    No cookie, and nothing in the address. What you type is not kept. Your language is given by the address itself (/en/ or /fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name). It never receives what you type.
    Code that runs here
    • app.js: the converter, written for R-no Toolbox. Not minified, no third-party library. IPv4 and IPv6 use the same arithmetic on 32- and 128-bit integers (BigInt). 12.9 kB
      SHA-256 9ed27f576f5df6de2327e1cf47bfa95495f9156c5d884a629096cf3a1f93eaae
    • textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 5.0 kB
      SHA-256 816bf6b8b0d54f41d20a8d7bbc43267edbd9947fab050efb50b7ad9a56488fa7
    • /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
      SHA-256 80f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
    How it works
    Starting from the first address, the tool takes the largest CIDR block that starts exactly there without going past the last address, then starts again right after it. This gives the shortest exact list: at most 62 blocks in IPv4, 254 in IPv6. The smallest single block is made of the bits the two addresses have in common.
    Tested
    The arithmetic is covered by automated tests, run on every deployment: single address, whole address space, worst cases, IPv6, pasted ranges, and the rejection of malformed input. The tests also check, on thousands of random ranges, that the blocks follow one another without gap or overlap and cover exactly the range.
    Check it yourself
    Download a script and compare its fingerprint with the one above:
    curl -s https://r-no.fr/ip/range/app.js | shasum -a 256
    Limits
    The blocks cover exactly the addresses you entered, including a network or broadcast address if the range contains one: whether those may appear in your rule is up to you. Both ends must be of the same family (IPv4 or IPv6).