URL & Network Tools

Wildcard Mask Calculator

Cisco access lists and OSPF network statements use wildcard masks, the inverse of subnet masks. Convert any mask or prefix to its wildcard, or enter address ranges and get exact ACL entries: each range is broken into the minimal set of aligned blocks, written with host, wildcard or any syntax, for numbered or named access lists.

  • Runs in your browser
  • No sign-up
  • Free to use
Calculate

How to use Wildcard Mask Calculator

  1. Choose wildcard conversion or ACL entries.
  2. Enter a mask or prefix, or address ranges.
  3. Choose permit or deny and the ACL name or number.
  4. Copy the lines into your router configuration.

Wildcard Mask Calculator features

Mask to wildcard

With binary form and number of matched addresses.

Exact ACLs for ranges

Ranges split into the minimal aligned blocks.

Correct syntax

host, any and wildcard forms; numbered and named ACLs.

OSPF example

Network statement with the wildcard.

Remarks

Each range labelled in the output.

Private

Runs in your browser.

When to use Wildcard Mask Calculator

  • Writing extended ACLs on Cisco routers and switches.
  • Configuring OSPF network statements.
  • Converting firewall ranges to ACL entries.
  • CCNA and CCNP exam practice.

Wildcard Mask Calculator FAQ

What is a wildcard mask?

The bitwise inverse of a subnet mask. In a wildcard, 0 means “this bit must match” and 1 means “ignore this bit”. The wildcard for 255.255.252.0 is 0.0.3.255.

Why does a range need several ACL lines?

A wildcard matches an aligned power-of-two block. Ranges that do not align need several blocks, each its own line, to match exactly.

What do host and any mean?

“host 10.1.1.5” is the same as 10.1.1.5 0.0.0.0, a single address; “any” matches every address.

Can wildcard masks be non-contiguous?

Cisco allows them, for example to match odd addresses, but they are hard to read and maintain. This tool produces contiguous wildcards only.

Do the ACLs include the implicit deny?

Every Cisco ACL ends with an implicit “deny any”. Add explicit permits for everything that must pass.

Is anything sent?

No.

Masks turned inside out

Cisco IOS inherited wildcard masks from its earliest access lists. Where a subnet mask marks network bits with ones, a wildcard marks the bits to ignore with ones. The two are bitwise inverses, so 255.255.255.0 becomes 0.0.0.255 and /22 becomes 0.0.3.255.

Converting is mechanical, but writing access lists for arbitrary ranges is not. A wildcard can only describe an aligned block whose size is a power of two. A range like 10.1.1.5 to 10.1.1.20 needs several entries, a /32, a /31, a /30, a /29 and so on, to match exactly. The calculator finds that minimal set and writes each entry in correct IOS syntax.

Precision matters in ACLs because they are security controls. Approximating a range with a single larger wildcard would permit addresses that were never meant to be allowed. Generated entries cover the range exactly.

Remember how ACLs are evaluated: top to bottom, first match wins, with an implicit deny at the end. Place specific entries before general ones, test on a lab device or with packet tracer tools, and document each block with a remark, as the output does.

Other useful tools