WILD

Wildcard Mask Calculator

Invert a contiguous IPv4 subnet mask and compare Cisco ACL address matches

IP & Routing
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
IPV4 / CISCO ACL

Calculates the inverse of a contiguous subnet mask: 0 means match, 1 means ignore. An inline /prefix takes precedence over the separate mask field. /31 shows two point-to-point endpoints; /32 is one address.

Calculation result

CIDR, subnet mask, wildcard, network range, and address count will appear here.

About this tool

Wildcard Mask Calculator converts a contiguous IPv4 subnet mask to its bitwise inverse: zero bits must match the reference address, while one bits are ignored. Enter an address and a separate /prefix or dotted mask, or supply address/prefix directly; an inline prefix takes precedence. The normalized network, range and counts use exact integer arithmetic. /0–/30 use the traditional network-and-broadcast reservation model, /31 shows two point-to-point endpoints and /32 represents one address. Noncontiguous wildcard patterns are outside this converter. Three Cisco-style alternatives demonstrate standard, named and extended source-address matches; they are not a combined policy or a device validation.

Suggested Workflow

Production Snippets

A /31 wildcard expresses a two-address match

text

Input: 192.0.2.1/31
Network: 192.0.2.0/31
Subnet mask: 255.255.255.254
Wildcard: 0.0.0.1
Endpoints: 192.0.2.0 and 192.0.2.1

access-list 10 permit 192.0.2.0 0.0.0.1

The /31 endpoint 192.0.2.1 is not a directed broadcast.
This line expresses address matching, not a complete firewall policy.

Frequently Asked Questions

How is the wildcard obtained?

Invert each of the 32 subnet-mask bits, equivalently subtract each octet from 255. For /24, 255.255.255.0 becomes 0.0.0.255.

Are arbitrary Cisco wildcard patterns accepted?

No. Cisco matching can express some noncontiguous patterns, but this tool starts from a contiguous subnet mask. A mask such as 255.0.255.0 is rejected.

Which field wins when I enter address/prefix?

The inline prefix wins. For 192.0.2.1/31, the separate mask field is ignored. Use a bare address when you want the separate field to supply the mask.

Do /31 and /32 have a displayed broadcast address?

No. /31 is shown as a point-to-point pair and /32 as one address. Their final address is labeled a range endpoint, not a directed broadcast.

What do host and any mean in the snippets?

For /32, host matches the single address. For /0, any matches the whole IPv4 address space. Other prefixes use the normalized network plus its wildcard.

Can I apply all three ACL snippets as one configuration?

They are alternatives. Choose and adapt the relevant style, then check direction, protocol, ports, order, implicit deny, existing policy and device syntax. The tool does not contact or configure a router.

Keep browsing