systrexDiagnose the Internet

Subnet calculator

/tools/subnet-calculator

Inspect an IPv4 or IPv6 subnet without sending the input anywhere. Results include exact boundaries and counts, fixed-width representations, an embedded IANA registry snapshot, reverse-DNS arithmetic, membership testing, navigation, and a scalable equal-size split pager.

Below the analyzer, a source-preserving longest-prefix trace, IPv6 structure diagnostics, exact IP-set operations, and allocation tools cover common operator workflows without sending the inputs anywhere. A before-and-after review exposes exact coverage changes and source-entry overlap, while a vendor-labelled wildcard matcher handles IPv4 ACL patterns.

The allocation planner accepts slot-based or explicit-prefix requirements, eligible space, and exclusions, then reports occupancy and capacity evidence for every offline candidate it places.

Enter an explicit prefix. IPv4 also accepts a strict contiguous dotted mask after a slash or a space. Nothing is inferred from an address alone.

Use IPv4 or IPv6 CIDR, or IPv4 with a contiguous dotted mask. Spaces around the input are ignored; ambiguous shorthand is rejected.

examples
local analysis · no storage

address-slot planning

Capacity to prefix

Find the smallest exact block that can hold required endpoint slots plus an explicit reservation or headroom allowance. No usable-host policy is inferred.

IPv4 starts with 2 explicit reserved slots; change this to match the deployment. IPv6 starts with 0.

inclusive exact cover

Range to minimal CIDRs

Convert one inclusive IPv4 or IPv6 address range into the smallest exact set of CIDR blocks. Both endpoints must use the same family.

IPv4 + IPv6 · ordered containment trace

Longest-prefix match explorer

Compare one destination with a pasted prefix table. Every containing prefix is preserved and ordered from most to least specific; equal-length ties remain visible instead of being guessed away.

This is exact destination containment and prefix specificity only. It does not evaluate next hops, metrics, administrative distance, route class, policy, device state, or forwarding outcome.

RFC field decoder · local forensic view

IPv6 structure diagnostics

Decode standardized bit fields that ordinary subnet output hides: embedded IPv4 formats, configured RFC 6052 translation, 6to4, Teredo, unique-local fields, multicast flags and scope, solicited-node multicast, and Ethernet destinations.

This decoder reads address bits only. It does not infer reachability, tunnel state, NAT type, endpoint ownership, ULA uniqueness, interface assignment, or whether a device joined the derived multicast group. Organization-specific translation is decoded only from the explicit prefix you supply.

exact coverage · both address families

IP set lab

Normalize whole lists, combine them, find their exact overlap, or subtract list B from list A. Each entry may be a CIDR, inclusive range, or one address; IPv4 and IPv6 are always calculated separately.

Summarize returns the smallest CIDR list with exactly the same coverage. A single enclosing supernet is shown separately because it may add addresses.

One CIDR, inclusive first-last range, or address per nonblank line; up to 256 lines per set. Host bits are canonicalized and ranges are converted to an exact minimal CIDR cover.

two-sided exact delta · source-line audit

Before / after coverage review

Compare intended and existing address coverage without confusing entry identity with address identity. Coverage is normalized first; source-line canonicalization, duplicates, containment, and strict partial overlaps are audited separately.

Each line may be a CIDR, inclusive first-last range, or one address. “Equivalent coverage” means the two sides contain exactly the same addresses; it does not mean their source entries are identical. Partial overlaps include their exact shared interval and slot count.

Cisco-style IPv4 ACL semantics · arbitrary bit pattern

IPv4 ACL wildcard matcher

Analyze a base address plus wildcard mask where 0 means “must match” and 1 means “ignore.” Noncontiguous masks are valid here and are not treated as subnet masks.

This tool evaluates address/wildcard matching only. It does not generate an access list, infer protocol or ports, or prove a device uses the same surrounding policy.

eligibility-aware · exact occupancy · deterministic placement

Address-space candidate plan

Place raw-slot or explicit-prefix requests inside declared eligible space while preserving exact exclusions. Requirements are sorted largest first, then placed in the lowest aligned free range that fits.

Each address-space line may be a CIDR, inclusive first-last range, or one address. Slot headroom defaults to 0; prefix count defaults to 1. Results are offline candidates under the displayed Systrex ordering policy, not reservations in an external IPAM system.

Exact arithmetic and address policy

Network boundaries, final addresses, masks, offsets, counts, and minimal covers use exact integer arithmetic. Traditional IPv4 host ranges exclude the network and directed-broadcast endpoints; /31 and /32 are handled separately. IPv6 has no broadcast and no universal usable-address subtraction.

Classification evidence

Classification comes from the embedded IANA IPv4 or IPv6 special-purpose registry snapshot shown with each result. Exact registry flags and qualifiers are evidence about that record, not a claim that an address is currently routed, reachable, safe, or suitable for a particular deployment.

Reverse DNS and splitting

The PTR and delegation guidance is arithmetic only; it does not query or change DNS. Reverse zones align on IPv4 octets or IPv6 nibbles. Equal-size splits are paged 64 rows at a time, including exact large page numbers. A one-based number, contained address, or same-prefix CIDR can jump directly to one child and its page without full enumeration.

Prefix matching and IPv6 structures

The longest-prefix explorer proves only which pasted prefixes contain a destination and which matching rows have the greatest prefix length; it does not choose a device route. IPv6 diagnostics decode standardized address bits or an explicit RFC 6052 prefix. They do not establish endpoint ownership, interface configuration, tunnel or NAT state, multicast membership, routing, or reachability.

Set math and allocation policy

Set summaries, overlap, and subtraction are exact address coverage, calculated separately for IPv4 and IPv6. A single enclosing supernet is only an approximation when it adds addresses. The allocation planner uses declared address slots and a named largest-block-first, lowest-address-first-fit policy; it does not prove route-policy equivalence or reserve space in an external IPAM system.

Privacy and local exports

All calculations run in this browser. Inputs and results are not transmitted, written to browser storage, or placed in the URL. Copy actions use the browser clipboard, and downloads are temporary local Blob files created from the visible result. Clear removes the in-page state.