IP in CIDR Checker
Check IPv4/IPv6 membership with longest-prefix matches
Check mathematical IPv4/IPv6 membership including network and end addresses. Show the longest prefix first, then other matches. Mapped IPv6 stays IPv6; zones are rejected. CIDRs are deduplicated and any invalid CIDR blocks conclusions. Limit: 1 MiB, 1000 lines per list, 250,000 IP Γ unique-CIDR comparisons.
Addresses and networks are processed in this page. No network probes or input drafts; analytics contains fixed action names and counts only.
About this tool
Compare an IP list with a CIDR list to review mathematical network membership. Each address is tested only against its own address family, with the longest matching prefix shown first and other matches preserved. Network and last addresses count as members even when a platform reserves them; IPv4-mapped IPv6 remains IPv6 and is not silently converted to IPv4. Host bits in CIDRs normalize to their network and duplicate normalized CIDRs are removed. Zone identifiers are rejected for address arithmetic. An invalid network blocks all conclusions because a missing network could change a no-match result; invalid IP rows remain visible but prevent export. Limits are 1 MiB combined input, 1000 non-empty lines per list and 250000 IP-by-unique-CIDR comparisons. This local check does not evaluate routes, firewall order or reachability, and saves no drafts.
Failure Clinic (Common Pitfalls)
No match is accepted after dropping a broken network
Cause: The omitted network might contain the address. A partial network list cannot support a reliable negative conclusion.
Fix: Correct every CIDR error before checking membership. If you split a large list, combine all partial results before interpreting an address as unmatched.
A longest match is treated as the selected route or firewall rule
Cause: This table compares numeric intervals only. Real routing includes route availability and policy, while firewalls may use ordered actions and protocol or port conditions.
Fix: Carry the matching prefixes into the appropriate configuration review. Separately verify route selection, rule order and assignable-host restrictions.
Suggested Workflow
Scenario Recipes
Check a host against nested inventory ranges
Goal: Keep the most specific match and broader context
- Enter 192.0.2.1 and 198.51.100.1 in the IP list.
- Enter 192.0.2.0/24 and 192.0.2.0/25 in the CIDR list, then run.
- Confirm .1 matches /25 with /24 as another match, while 198.51.100.1 shows No match.
Result: A family-aware membership table, not a route or firewall decision.
Production Snippets
Longest prefix is descriptive membership evidence
text
IP: 192.0.2.1
Networks: 192.0.2.0/24, 192.0.2.0/25
Longest match: 192.0.2.0/25
Other matches: 192.0.2.0/24
IP: ::ffff:192.0.2.1
Network: 192.0.2.0/24
No match: address families differ.Frequently Asked Questions
What does longest match mean?
Among containing networks of the same family, the largest prefix length is shown first. For 192.0.2.1 against 192.0.2.0/24 and /25, /25 is first and /24 remains in other matches.
Do network and broadcast addresses belong to a CIDR?
Yes, membership includes both numeric bounds. Whether an address can be assigned to a host is a different question and depends on prefix semantics and the platform.
Does ::ffff:192.0.2.1 match 192.0.2.0/24?
No. The mapped value is a 128-bit IPv6 address and the network is IPv4. Enter an appropriate IPv6 prefix or explicitly transform the data elsewhere if your policy requires that mapping.
Why does one invalid CIDR stop all results?
A missing or incorrectly parsed network can turn a real match into a misleading no-match. The tool reports the CIDR line error and withholds membership conclusions until every network is valid.
How are duplicate networks and zones handled?
CIDRs are normalized and deduplicated, so 192.0.2.1/24 and 192.0.2.0/24 count once. Zones such as %eth0 are rejected rather than discarded, because this arithmetic input has no interface context.
Why can two lists below 1000 lines exceed the limit?
The check also caps IP count multiplied by unique normalized CIDR count at 250000. For example, 501 IPs times 500 unique networks exceeds the bound. Split one list and retain complete network context when reviewing no-match results.
Keep browsing