The tool compares the addresses covered by each list, regardless of how many CIDR rows describe them. Common contains addresses in both lists; Only in A and Only in B show coverage missing from the other list. Results use the smallest exact CIDR set and do not fill gaps. Compare one IP family at a time; IPv6 address counts remain exact.
Example: For the default lists, A ∩ B is 192.0.2.128/25 plus 198.51.100.0/25. Only A is 192.0.2.0/25; only B is 198.51.100.128/25. Each list covers 384 addresses, with 256 addresses shared. No gaps are filled.
An empty list is a valid empty set. Every nonblank line must contain one CIDR for the selected IP family; hosts need /32 or /128. Ranges and mixed families are rejected. Host bits are normalized and reported.
Limits are 2,048 CIDRs and 200,000 characters per list, and 8,192 total output prefixes. An oversized exact result is rejected rather than widened.
Address-set equality does not establish equivalent firewall policy, next hops or VPN negotiation.
Different rows, the same address space
A text comparison would flag these lists as different. This tool compares the addresses they cover:
List A
192.0.2.0/24
List B
192.0.2.0/25 192.0.2.128/25
Common: 192.0.2.0/24. Only in A and Only in B: (empty set). Both lists cover the same 256 addresses; splitting a prefix has not added or removed any addresses.
Loading this example will replace your current lists and select IPv4.
Read the relationships correctly
If an A row is partly covered, list B contains some of its addresses; use Only in A to find the missing part. Several smaller CIDRs in B can fully cover one larger A row. Duplicate and contained entries within each list are reported separately.
Use it before a network change
Put the current VPN selectors in A and the proposed selectors in B. The intersection is unchanged address coverage, A-only is removed coverage and B-only is newly included coverage. Review device-specific selector and policy behavior separately. The same comparison helps find address objects missing from a migration.
For example, A = 2001:db8:42::/126 and B = 2001:db8:42::2/127 share 2001:db8:42::2/127. Only A is 2001:db8:42::/127 and only B is empty.
To reduce a single route list, use exact aggregation and route summarization. Its covering-supernet mode is a separate operation that can introduce additional space. After reviewing IPv4 sets, prepare FortiGate address objects.