Extract IP prefix
Reduces an IP address to the network it belongs to and writes that value into another field.
| Configuration | Content |
|---|---|
| Source: IP address | text field holding the address |
| Destination: Prefix | text field that receives the prefix |
| Setting: IPv4 | prefix length, default 32, maximum 32 |
| Setting: IPv6 | prefix length, default 64, maximum 128 |
The reason it exists is IPv6. An IPv4 address identifies one access point, but an IPv6 subscriber gets a whole range to spend as it likes: a single connection can walk billions of addresses without ever repeating one. Counting individual IPv6 addresses, therefore, counts nothing: every attempt looks like a first-time visitor. Reducing the address to its prefix makes “attempts from this address” mean the same thing in both families.
The two lengths are configured separately because a single number cannot serve both, and because the right aggregation depends on the traffic, not on the protocol: /64 is the standard residential range in IPv6, but a provider handing out /56 requires a wider prefix, and an IPv4 estate behind NAT may justify grouping at /24.
The written value comes out in CIDR notation, with the /n suffix only when the address was actually reduced, so that a /32 and a /24 of the same address can never be read as the same value. A malformed address writes nothing.