The problem of removing sensitive information from data before it is released publicly, or turned over to less trusted analysts, underlies much of the unwillingness to share data. The solution is to sanitize, or deidentify, parts of the data. When dealing with network addresses, the set of available addresses is finite. This limits some aspects of the sanitization. We analyze this problem in detail, and suggest approaches to ameliorate it.