Packetrove

IP ADDRESS TOOLS

CIDR Subtraction

Subtract excluded IPv4 or IPv6 networks from your included address space. Get the smallest exact CIDR list, with no added addresses.

Calculated in your browser · No API request

Your address lists

One entry per line. Include at least one address or range.

One entry per line. Leave empty to simplify the include list without removing addresses.

Use one address family and at most 1,000 entries across both lists, with at most 64 characters per entry. Results may contain up to 10,000 CIDRs; larger results return an error with no partial list.

0 entries

Try an example

Remaining address space

Your result will appear here

Enter an include list and optional exclusions to calculate the exact remainder.

What the result means

The calculation subtracts the union of exclusions from the union of included ranges. Overlaps count once, host bits are normalized, and no addresses are added. All addresses in a range count, including network and broadcast addresses.

Use the result for WireGuard exceptions or to inspect gaps after known allocations. Gaps are relative to your inputs; they do not prove addresses are unused on the live network. Review the list before applying it.

Subtraction examples

IPv4

Remove 203.0.113.64/26 from 203.0.113.0/24:

203.0.113.0/26
203.0.113.128/25

IPv6

Remove 2001:db8::4/126 from 2001:db8::/124:

2001:db8::/126
2001:db8::8/125

Questions about CIDR subtraction

How do I prepare WireGuard AllowedIPs exceptions?

Put the intended tunnel ranges in Include and the exceptions in Exclude. Copy AllowedIPs copies the exact remaining CIDRs as a setting value. Review it before applying; Packetrove does not configure WireGuard or change routes.

Do remaining ranges prove that addresses are unused?

They show gaps relative to your include and exclude lists. The tool does not inspect live network usage or find subnets of a requested size.

What happens to overlapping or out-of-range exclusions?

Overlaps on each side count once. Only addresses also present in Include are removed; exclusions outside it remove nothing. Complete removal succeeds with an empty CIDR list and zero remaining addresses.

How does subtraction differ from a covering CIDR?

Subtraction preserves the exact remainder of union(include) minus union(exclude), including gaps. It returns a minimal sorted list of canonical CIDRs without adding addresses. A single covering CIDR can include extra addresses.

Can I call subtraction through MCP, the Web API, or CLI?

Subtraction currently runs in the browser and shared calculation core. Browser inputs stay local. MCP, Web API, and CLI offer the covering-CIDR and public-IP operations; they do not expose subtraction. The MCP guide documents those available operations.

Read the MCP connection guide