CIDR Exclude Calculator
Subtract contained IPv4 or IPv6 networks and inspect the exact minimal remainder
Exact IPv4/IPv6 set subtraction. Exclusions must share the parentβs family and be wholly contained. Limits: 256 exclusions, 64 KiB input and 10,000 output CIDRs. Duplicate and overlapping addresses are removed once.
The normalized, minimal, non-overlapping remainder will appear here.
About this tool
CIDR Exclude Calculator subtracts contained subnets from one IPv4 or IPv6 parent. It normalizes host bits, merges duplicate, overlapping and adjacent exclusion intervals, then emits a minimal exact CIDR cover of the remainder. Removed addresses are counted once. An exclusion equal to the parent produces a valid empty set with zero remaining addresses; there is then no CIDR text to copy or download. Every exclusion must belong to the same address family and lie wholly inside the parent. Outside blocks are rejected instead of clipped. Limits are 256 exclusions, 64 KiB of list text and 10,000 output CIDRs. Calculations are local and do not check allocation, route authorization or platform reservations.
Suggested Workflow
Production Snippets
A contained exclusion is not subtracted twice
text
Parent: 192.0.2.0/24
Exclude:
192.0.2.0/25
192.0.2.0/26
Remaining: 192.0.2.128/25
Excluded addresses: 128
Remaining addresses: 128
The /26 was already inside the excluded /25.
Excluding the parent itself would instead yield a valid empty set.Frequently Asked Questions
Why are overlapping exclusions not counted twice?
The tool merges their address intervals before subtracting. Excluding a /25 and a contained /26 removes the /25 once; duplicate lines do not reduce the remainder again.
What happens when exclusions cover the whole parent?
The calculation completes with zero remaining addresses and an empty CIDR list. The empty state is shown explicitly, and no empty copy or download action is offered.
Can an exclusion overlap the parent but extend outside it?
No. This tool requires full containment. An overlapping larger block and a completely unrelated block are both rejected, with an exclusion number in the diagnostic.
What makes the result minimal?
Each remaining inclusive interval is summarized into maximal aligned CIDRs. The combined result covers exactly the retained addresses, without gaps, overlaps or extra neighboring addresses.
How strict is the input and what are the limits?
Use complete decimal CIDR prefixes, one per line; commas or whitespace can also separate items. Empty prefixes, mixed address families and zone suffixes fail. Limits are 256 exclusions, 64 KiB list input, 256 bytes per field and 10,000 output CIDRs.
Can the result be treated as deployable firewall policy?
It is an address set, not a full policy. Action, rule order, ports, direction, existing rules and platform semantics need separate decisions. No firewall or router is contacted.
Keep browsing