Turn A CIDR Block Into Its Exact IP Range
Paste a block like 10.0.0.0/22 and get the network address, broadcast address, netmask, wildcard mask, first and last usable host, and exact address counts. Reverse mode takes a start and end IP and finds the smallest CIDR that covers them. Everything is 32-bit integer math running in your browser — no lookups, no requests.
How the numbers are derived
An IPv4 address is nothing more than a 32-bit unsigned integer written as four 8-bit octets. 10.0.0.0 is 10×224 + 0 + 0 + 0 = 167772160. Once both the address and the prefix are integers, every value on this page falls out of three bitwise operations, so the results are exact rather than approximate.
Netmask and wildcard
A prefix length p means the leftmost p bits identify the network and the remaining 32 - p bits identify the host. The netmask is therefore p ones followed by 32 - p zeros:
Numerically the same mask equals 232 − 232−p. A /22 gives 255.255.252.0, and its wildcard — the form Cisco ACLs and many scanners expect — is 0.0.3.255.
Network and broadcast address
The network address is the address with every host bit cleared; the broadcast address is the same address with every host bit set. That is a single AND and a single OR:
Note that any address inside the block produces the same network address, which is why 10.0.2.55/22 and 10.0.0.0/22 describe the identical range. The tool reports whether the address you typed was already aligned to the block boundary, because an unaligned CIDR in a scope document is a common copy-paste error worth flagging.
Counting addresses and usable hosts
The block spans every integer from network to broadcast inclusive, so the total address count is a pure power of two:
Usable host counts are where naive calculators get it wrong. The general rule subtracts the network and broadcast addresses, but two prefixes are special cases defined by standards, not by the formula:
p ≤ 30→ usable =232−p − 2. A/24holds 256 addresses and 254 hosts.p = 31→ usable = 2. RFC 3021 permits 31-bit prefixes on point-to-point links, where there is no broadcast to reserve and both addresses are assignable.p = 32→ usable = 1. A single host route; the address is both network and broadcast.
The first usable host is network + 1 and the last is broadcast − 1, except in those two special cases where the first is the network itself and the last is the broadcast itself.
Reverse mode: smallest covering prefix
Given a start and end address, the smallest CIDR that contains both is found from the length of their shared binary prefix. XOR the two integers: every leading zero bit in the result is a bit they agree on. Counting how many bits remain after shifting the XOR down to zero gives the prefix directly:
The covering block is almost always larger than the range you asked for — 192.168.4.10 - 192.168.7.200 is covered by 192.168.4.0/22, which includes 1024 addresses rather than the 959 in the range. For that reason the tool also decomposes the range into the exact minimal set of CIDR blocks that cover it and nothing else, by repeatedly taking the largest block that is both aligned to the current start and no longer than the remaining span. That exact list is what you want when writing firewall rules or a scanner target file; the single covering prefix is what you want when summarising a scope.
Splitting a block
Equal subnets only exist in powers of two, so a request for N subnets is satisfied by borrowing b = ceil(log2 N) host bits, producing 2b children each of prefix p + b. Ask for 4 subnets of a /22 and you get four /24s; ask for 3 and you still get four, because 3 is not a power of two. The split is rejected when p + b > 32, since there are no host bits left to borrow.
Why bit math and not string parsing
JavaScript bitwise operators coerce to 32-bit signed integers, so 192.168.0.1 parsed naively becomes negative. Every operation here ends with >>> 0, the unsigned right shift, which reinterprets the result as an unsigned 32-bit value. Address totals above 231 are handled as ordinary doubles, which represent every integer up to 253 exactly, so the counts for /0 and /1 are precise and not rounded.
CIDR itself is specified in RFC 4632, which replaced the old class A/B/C split with arbitrary prefix lengths. This calculator is classless throughout: it never infers a prefix from the first octet, so 10.0.0.0 with no prefix is treated as /32, not as a class A block.