IP ADDRESS TOOLS
CIDR Subtraction
Subtract excluded IPv4 or IPv6 networks from your included address space. Get the smallest exact CIDR list, with no added addresses.
Calculated in your browser · No API request
Your address lists
Remaining address space
Your result will appear here
Enter an include list and optional exclusions to calculate the exact remainder.
What the result means
The calculation subtracts the union of exclusions from the union of included ranges. Overlaps count once, host bits are normalized, and no addresses are added. All addresses in a range count, including network and broadcast addresses.
Use the result for WireGuard exceptions or to inspect gaps after known allocations. Gaps are relative to your inputs; they do not prove addresses are unused on the live network. Review the list before applying it.
Subtraction examples
IPv4
Remove 203.0.113.64/26 from 203.0.113.0/24:
203.0.113.0/26 203.0.113.128/25
IPv6
Remove 2001:db8::4/126 from 2001:db8::/124:
2001:db8::/126 2001:db8::8/125
Questions about CIDR subtraction
How do I prepare WireGuard AllowedIPs exceptions?
Put the intended tunnel ranges in Include and the exceptions in Exclude. Copy AllowedIPs copies the exact remaining CIDRs as a setting value. Review it before applying; Packetrove does not configure WireGuard or change routes.
Do remaining ranges prove that addresses are unused?
They show gaps relative to your include and exclude lists. The tool does not inspect live network usage or find subnets of a requested size.
What happens to overlapping or out-of-range exclusions?
Overlaps on each side count once. Only addresses also present in Include are removed; exclusions outside it remove nothing. Complete removal succeeds with an empty CIDR list and zero remaining addresses.
How does subtraction differ from a covering CIDR?
Subtraction preserves the exact remainder of union(include) minus union(exclude), including gaps. It returns a minimal sorted list of canonical CIDRs without adding addresses. A single covering CIDR can include extra addresses.
Can I call subtraction through MCP, the Web API, or CLI?
Subtraction currently runs in the browser and shared calculation core. Browser inputs stay local. MCP, Web API, and CLI offer the covering-CIDR and public-IP operations; they do not expose subtraction. The MCP guide documents those available operations.