TanodTools
EN

MikroTik address list generator

Paste IP addresses, networks or ranges in any mix, and get a clean RouterOS address-list script with duplicates removed and adjacent networks merged.

Runs in your browser; your lists never leave your device

One per line or separated by commas. Text after # or ; is ignored.
Optional, such as 1h, 1d or 1w.

Reads IPv4 and IPv6 addresses, CIDR networks and ranges written as first-last; anything after # or ; on a line is ignored. Large lists (hundreds of thousands of entries) work but take a moment. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.

How to build a MikroTik address list

  1. Paste the addresses, one per line or separated by commas or spaces. Networks (203.0.113.0/24) and ranges (198.51.100.10-198.51.100.20) work too.
  2. Name the list, and add a timeout or comment if you want them on every entry.
  3. Leave merging on to get the fewest entries, then copy the script or download the .rsc file and run /import file-name=list.rsc.

Address lists on RouterOS

An address list is a named set of IP addresses and networks under /ip firewall address-list (and /ipv6 firewall address-list for IPv6). Firewall, NAT, mangle and raw rules can match a whole list with one condition, which keeps rule sets short and fast: RouterOS looks list membership up in a tree rather than walking one rule per network. Lists are the usual way to hold management networks, customer ranges, block lists from threat feeds, or addresses that a rule adds dynamically with action=add-src-to-address-list.

The same list can hold single addresses, CIDR networks and ranges, and overlapping entries are allowed, which is how imported feeds grow untidy. This page cleans a list before it reaches the router: it normalises each entry (a network written with host bits, such as 10.1.2.3/24, becomes 10.1.2.0/24), drops exact duplicates and, with merging on, collapses everything into the minimal set of CIDR blocks. The script uses the plain address for a single host, as RouterOS itself prints it.

Tips

Questions

What does merging do?

It sorts every entry, joins addresses and networks that overlap or touch, and writes the result as the fewest CIDR blocks that cover exactly the same addresses. 10.0.0.0/25 and 10.0.0.128/25 become 10.0.0.0/24, and a single address inside a network you already have disappears. Nothing is added that wasn't covered before.

Why did a range turn into several entries?

A range such as 10.0.0.5-10.0.0.20 doesn't line up with one network boundary, so it is written as the CIDR blocks that cover it exactly: 10.0.0.5/32, 10.0.0.6/31, 10.0.0.8/29, 10.0.0.16/30 and 10.0.0.20/32. RouterOS accepts ranges too, but CIDR entries are easier to read and compare.

My import stops halfway with "already have such entry". Why?

RouterOS refuses to add an address that is already in the list, and an import stops at the first error. Tick "Skip entries that already exist": each line is then wrapped in :do { … } on-error={} so duplicates are skipped and the import carries on. Or tick "Replace the list" to empty it first.

How do I use the list in a firewall rule?

Match it with src-address-list= or dst-address-list=, for example /ip firewall raw add chain=prerouting src-address-list=blocklist action=drop. Dropping in the raw table skips connection tracking, which is cheaper for large block lists.

Are my lists uploaded?

No. The parsing and merging run in your browser, and nothing you paste is sent anywhere.