🌐 English
User Guide - Methods and Boundaries

One IP address or a whole range? Understand CIDR first

Use 192.168.1.42/24 to perform a network range calculation, distinguishing between mathematical address ranges, ordinary subnets, and /31 ​​point-to-point links.

Content verified: 2026-10-08 · Edited by: Site maintainer

First, determine what type of target you are targeting.

If only one abnormal IPv4 address appears in the log, first record the complete address, the time of occurrence, the request path, and the reason for the rule being hit. Writing it as /32 represents a single address; changing it to /24 will overwrite 256 addresses in the same segment. The two rules have different scopes of influence and should not be interchanged simply because they are easier to write.

This website's calculator only helps you see the address range; it does not check reputation, identify attacks, or connect to servers to modify firewalls. Whether access should be restricted still depends on the network, proxy links, and business logs that you have the authority to manage.

Let's break down an example.

The input is 192.168.1.42/24. IPv4 has 32 bits, with 24 bits for the prefix and 8 bits remaining. Therefore, the block size is 2 to the power of 8, or 256. The network address is 192.168.1.0, the range ends at 192.168.1.255, and the mask is 255.255.255.0.

In a typical /24 subnet context, removing network and broadcast addresses, the usual host range is 192.168.1.1 to 192.168.1.254. When a firewall matches the entire /24 range, it still matches all addresses within that mathematical range; do not mistake "number of hosts in a typical subnet" for the number of rule matches.

/31, /32 cannot be mechanically reduced by two.

/31 has only two addresses. Point-to-point links, as described in RFC 3021, can use both as endpoints; the algorithm of subtracting the network and broadcast addresses from a regular subnet cannot be used. This tool will specify the intended use and conditions, rather than presenting the results as usable addresses for a regular local area network.

/32 is a prefix for an address, often used for single-address matching or host routing. /0 mathematically covers the entire IPv4 address space; the calculation result does not indicate which addresses are routable, assignable, or permitted on the public network.

Four checks when preparing to apply rules

First, verify whether you are seeing a client address or a reverse proxy address, and confirm that the proxy header is only received from trusted proxies. Second, put the proposed prefix into a calculator to see if the range header and footer include normal users or management entry points. Third, retain the current rules and recovery path, and verify a new rule in a rollback environment. Fourth, verify with the addresses that should and should not be hit, and then observe the logs.

Inputs such as 256.1.1.1/24, negative numbers, or prefixes greater than 32 should be rejected. Boundary behavior can be compared using 0.0.0.0/0, 192.168.1.42/24, 192.0.2.0/31, and 192.0.2.9/32. The order of operations described in this article is an editorial suggestion and does not represent actual test results for any particular network.

References

The links are for verifying technical definitions; the examples and operational suggestions are compiled by this site and do not masquerade as actual project evaluations.

Return to the tool and try a set of parameters.