Subnet calculator
/tools/subnet-calculator
Inspect an IPv4 or IPv6 subnet without sending the input anywhere. Results include exact boundaries and counts, fixed-width representations, an embedded IANA registry snapshot, reverse-DNS arithmetic, membership testing, navigation, and a scalable equal-size split pager.
Below the analyzer, a source-preserving longest-prefix trace, IPv6 structure diagnostics, exact IP-set operations, and allocation tools cover common operator workflows without sending the inputs anywhere. A before-and-after review exposes exact coverage changes and source-entry overlap, while a vendor-labelled wildcard matcher handles IPv4 ACL patterns.
The allocation planner accepts slot-based or explicit-prefix requirements, eligible space, and exclusions, then reports occupancy and capacity evidence for every offline candidate it places.
Enter an explicit prefix. IPv4 also accepts a strict contiguous dotted mask after a slash or a space. Nothing is inferred from an address alone.
calculated range
Subnet result
exact arithmetic
Summary
- Address family
- Input notation
- Entered address
- IPv6 zone
- Prefix length
- Network CIDR
- Prefix base / network address
- Final address
- Broadcast address
- Subnet mask
- Bitwise inverse of prefix mask
- Total address slots
- Usable-address policy
- First usable address
- Last usable address
- Usable address count
context, not guesses
Operator notes
embedded registry evidence
Input classification
- Entered address
- Address-type bucket
- Most-specific label
- Matched CIDR
- Address-block qualifier
- Reference
- Multicast scope
- IANA snapshot date
- Registry source
- Network classification
- Special-purpose regions
- Ordinary-unicast region present
- Multicast region present
- IANA IPv6 allocation
- Allocation record
- Allocation snapshot
- Network allocation status
Intersecting IANA special-purpose records
Intersecting IANA IPv6 allocation records
fixed-width, exact values
Representations
| Value | Canonical | Expanded | IPv4-embedded form | Binary | Hexadecimal | Decimal |
|---|---|---|---|---|---|---|
| Entered address | ||||||
| Prefix base / network address | ||||||
| Final address | ||||||
| Subnet mask | ||||||
| Bitwise inverse of prefix mask |
entered address within this block
Address position and navigation
- Zero-based offset
- One-based ordinal
- Addresses after input
- Boundary role
- Subnet ordinal at /prefix
- Subnets at this prefix
arithmetic only · no DNS query
Reverse DNS
- Entered-address PTR name
- Delegation method
- Exact reverse zone
- Covering aligned zone
numeric containment
Address membership
Test one address against the current subnet. IPv6 zone identifiers are compared as separate local context and never change the numeric result.
- Tested address
- Member
- Relation
- Offset in subnet
- Addresses after test
- Zone comparison
equal-size allocation
Split this subnet
- Located child
- Child number
- Zero-based index
- Exact page / row
- Locator interpreted as
- New prefix length
- Subnets created
- New subnet mask
- New bitwise inverse
| No. | CIDR | Prefix base / network | Final address | Broadcast | Address slots | Usable policy / range |
|---|
address-slot planning
Capacity to prefix
Find the smallest exact block that can hold required endpoint slots plus an explicit reservation or headroom allowance. No usable-host policy is inferred.
IPv4 starts with 2 explicit reserved slots; change this to match the deployment. IPv6 starts with 0.
- Required endpoint slots
- Reserved / headroom slots
- Planned address slots
- Smallest prefix
- Block address slots
- Unused slots in block
- Subnet mask
- Bitwise inverse of prefix mask
inclusive exact cover
Range to minimal CIDRs
Convert one inclusive IPv4 or IPv6 address range into the smallest exact set of CIDR blocks. Both endpoints must use the same family.
| CIDR | First address | Final address | Address slots |
|---|
IPv4 + IPv6 · ordered containment trace
Longest-prefix match explorer
Compare one destination with a pasted prefix table. Every containing prefix is preserved and ordered from most to least specific; equal-length ties remain visible instead of being guessed away.
- Canonical destination
- Source rows
- Same-family rows
- Matching rows
- Longest matching prefix
- Equally most-specific rows
- Host-bit canonicalizations
Ordered matching trace
| Rank | Line | Label | Input | Canonical CIDR | Result |
|---|
Source-row audit
| Line | Family | Input | Canonical CIDR | Matches | Audit |
|---|
RFC field decoder · local forensic view
IPv6 structure diagnostics
Decode standardized bit fields that ordinary subnet output hides: embedded IPv4 formats, configured RFC 6052 translation, 6to4, Teredo, unique-local fields, multicast flags and scope, solicited-node multicast, and Ethernet destinations.
- Canonical address
- Recognized structures
- Embedded IPv4 endpoints
- Validation warnings
| Structure | Field | Value | Evidence boundary |
|---|
exact coverage · both address families
IP set lab
Normalize whole lists, combine them, find their exact overlap, or subtract list B from list A. Each entry may be a CIDR, inclusive range, or one address; IPv4 and IPv6 are always calculated separately.
- Unique result address slots
- Result blocks
- IPv4 result
- IPv6 result
- IPv4 enclosing supernet
- IPv6 enclosing supernet
| Family | CIDR | First address | Final address | Address slots |
|---|
two-sided exact delta · source-line audit
Before / after coverage review
Compare intended and existing address coverage without confusing entry identity with address identity. Coverage is normalized first; source-line canonicalization, duplicates, containment, and strict partial overlaps are audited separately.
- Coverage equivalent
- Before unique slots
- After unique slots
- Removed / before-only
- Shared
- Added / after-only
- Entry audit findings
Exact coverage partition
| Partition | Family | CIDR | First address | Final address | Address slots |
|---|
Source-entry audit
| Side | Line | Kind | Input | Canonical | Findings |
|---|
Cisco-style IPv4 ACL semantics · arbitrary bit pattern
IPv4 ACL wildcard matcher
Analyze a base address plus wildcard mask where 0 means “must match” and 1 means “ignore.” Noncontiguous masks are valid here and are not treated as subnet masks.
- Normalized rule
- Fixed-bit mask
- Bit pattern
- Fixed / ignored bits
- Exact matching addresses
- Candidate test
- Contiguous CIDR equivalent
- Minimal CIDR decomposition
| CIDR |
|---|
eligibility-aware · exact occupancy · deterministic placement
Address-space candidate plan
Place raw-slot or explicit-prefix requests inside declared eligible space while preserving exact exclusions. Requirements are sorted largest first, then placed in the lowest aligned free range that fits.
- Canonical parent
- Placement policy
- Eligible address slots
- Outside eligible space
- Requested + headroom
- Allocated block slots
- Excluded slots
- Remaining slots
- Address-space occupancy
Allocated blocks
| Input | Label | Request | CIDR | Required | Headroom | Block slots | Unused | First address | Final address |
|---|
Remaining capacity by requested prefix
| Prefix | Block slots | Aligned blocks available | First candidate | Largest free block |
|---|
Remaining free space
| CIDR | First address | Final address | Address slots |
|---|
Exact arithmetic and address policy
Network boundaries, final addresses, masks, offsets, counts, and minimal covers use exact integer arithmetic. Traditional IPv4 host ranges exclude the network and directed-broadcast endpoints; /31 and /32 are handled separately. IPv6 has no broadcast and no universal usable-address subtraction.
Classification evidence
Classification comes from the embedded IANA IPv4 or IPv6 special-purpose registry snapshot shown with each result. Exact registry flags and qualifiers are evidence about that record, not a claim that an address is currently routed, reachable, safe, or suitable for a particular deployment.
Reverse DNS and splitting
The PTR and delegation guidance is arithmetic only; it does not query or change DNS. Reverse zones align on IPv4 octets or IPv6 nibbles. Equal-size splits are paged 64 rows at a time, including exact large page numbers. A one-based number, contained address, or same-prefix CIDR can jump directly to one child and its page without full enumeration.
Prefix matching and IPv6 structures
The longest-prefix explorer proves only which pasted prefixes contain a destination and which matching rows have the greatest prefix length; it does not choose a device route. IPv6 diagnostics decode standardized address bits or an explicit RFC 6052 prefix. They do not establish endpoint ownership, interface configuration, tunnel or NAT state, multicast membership, routing, or reachability.
Set math and allocation policy
Set summaries, overlap, and subtraction are exact address coverage, calculated separately for IPv4 and IPv6. A single enclosing supernet is only an approximation when it adds addresses. The allocation planner uses declared address slots and a named largest-block-first, lowest-address-first-fit policy; it does not prove route-policy equivalence or reserve space in an external IPAM system.
Privacy and local exports
All calculations run in this browser. Inputs and results are not transmitted, written to browser storage, or placed in the URL. Copy actions use the browser clipboard, and downloads are temporary local Blob files created from the visible result. Clear removes the in-page state.