What is an IP address?
An IP address is a number that identifies a device's network connection so that data can reach it. IP stands for Internet Protocol, the set of rules that moves data between networks. IP works at Layer 3, the Network layer of the OSI model.
Together with its subnet mask (or prefix), an IP address identifies both a network interface and the network it belongs to. For example, a laptop might have these settings:
| Setting | Example | What it means |
|---|---|---|
| IP address | 192.168.10.25 | This laptop's own address |
| Subnet mask | 255.255.255.0 | Which part of the address is the network |
| Prefix notation | 192.168.10.25/24 | The same address and mask in short form |
| Default gateway | 192.168.10.1 | The router to use for other networks |
An address belongs to an interface (a network connection), not to the whole device. A laptop with Ethernet, Wi-Fi and a VPN adapter can have several addresses at the same time.
💡 In simple terms: an IP address works like the postal address on a letter. It says which street (the network) and which house (the device). Post offices (routers) only need the street part to move the letter closer to its destination.
Why IP addresses exist: logical addressing
Every network card already has a MAC address, usually set by the manufacturer. So why is a second address needed? Because a MAC address is a physical address: it identifies the network interface, but says nothing about where it is. MAC addresses are assigned by manufacturer, not by location, so a router could never tell in which direction a MAC address is.
An IP address is a logical address. A person (or a DHCP server) chooses it to match the network the device is connected to. All devices on one network share the same network part, so a router only needs one entry in its routing table to reach all of them. That is what makes it possible to route traffic across the internet, with its billions of devices.
| MAC address (physical) | IP address (logical) | |
|---|---|---|
| Layer | Layer 2 (Data Link) | Layer 3 (Network) |
| Who sets it | Usually the manufacturer (some devices use a random one) | An administrator or a DHCP server |
| Changes when you move? | Usually not (unless the device randomises it per network) | Yes: a new network means a new address |
| Size | 48 bits, e.g. 02:00:00:00:00:aa | 32 bits (IPv4), e.g. 192.168.10.25 |
| Used for | Delivery on the local link | Delivery across networks, end to end |
| Analogy | A person's name | The postal address where they live today |
Both addresses work together. The IP address says where the packet is finally going; the MAC address gets it across each local link. The link between the two is ARP (Address Resolution Protocol), which you will meet in the next unit.
Where the IP address sits in a packet
When an application sends data, each layer wraps it in its own header (this is called encapsulation). IP adds a header that holds the source IP address (the sender) and the destination IP address (the final receiver). That IP packet is then carried inside an Ethernet frame, with MAC addresses on the outside.
[ Ethernet: dst MAC | src MAC ] [ IP: src 192.168.10.25 → dst 203.0.113.20 ] [ TCP: ports ] [ data ]Simplified view of one frame on the wire.
Routers read the destination IP address to decide where to send the packet next. Normally, the IP addresses stay the same for the whole trip (unless NAT changes them), while the MAC addresses are rewritten at every router.
IPv4: understanding the numbers
IPv4 (Internet Protocol version 4) is the version that most networks still use every day. An IPv4 address has four important properties:
32 bits
Every IPv4 address is a string of 32 ones and zeros. Computers only work with the bits.
4 octets
The 32 bits are split into four groups of 8 bits. Each group is called an octet.
Dotted decimal
Each octet is written as a normal number from 0 to 255, with dots between them: 192.168.10.25.
Network + host
Part of the address identifies the network, and the rest identifies one device on it. The subnet mask shows where the split is.
The 32-bit structure and octets
An IPv4 address is 32 bits, written as four decimal numbers separated by dots. Each number is an octet (8 bits), so its value can only be 0 to 255. Writing an address this way is called dotted decimal notation. It exists only for humans: 11000000101010000000101000011001 is the same address as 192.168.10.25, just much harder to read.
| Octet | Decimal | Binary |
|---|---|---|
| First | 192 | 11000000 |
| Second | 168 | 10101000 |
| Third | 10 | 00001010 |
| Fourth | 25 | 00011001 |
This means 192.168.10.300 is not a valid address: 300 doesn't fit in 8 bits. 192.168.10 isn't valid either (it has only three octets). Avoid 192.168.010.025 too: some systems read leading zeros as a different number base (octal). Always write plain numbers.
Basic binary: reading an octet
Binary is counting with only two digits, 0 and 1. In an octet, each of the 8 positions has a fixed value, doubling from right to left. A 1 means “count this value” and a 0 means “skip it”. Add up the values that have a 1:
| Place value | 128 | 64 | 32 | 16 | 8 | 4 | 2 | 1 | Total |
|---|---|---|---|---|---|---|---|---|---|
| 192 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0 | 128 + 64 = 192 |
| 168 | 1 | 0 | 1 | 0 | 1 | 0 | 0 | 0 | 128 + 32 + 8 = 168 |
| 10 | 0 | 0 | 0 | 0 | 1 | 0 | 1 | 0 | 8 + 2 = 10 |
| 25 | 0 | 0 | 0 | 1 | 1 | 0 | 0 | 1 | 16 + 8 + 1 = 25 |
| 255 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | all eight = 255 |
To turn a decimal number into binary, work from the left. Does 128 fit? If yes, write 1 and subtract it; if no, write 0. Then try 64, 32 and so on, down to 1. For 25: 128 no, 64 no, 32 no, 16 yes (9 left), 8 yes (1 left), 4 no, 2 no, 1 yes → 00011001. That's all the binary you need for this unit. Splitting octets bit by bit is part of the Subnetting lesson in the CCNA course.
Learn more: Subnetting
Network part and host part
The subnet mask shows which bits are the network prefix and which are left for hosts. A mask bit of 1 means “network” and a 0 means “host”. For 192.168.10.25/24, the mask 255.255.255.0 is twenty-four 1s followed by eight 0s. So the network is 192.168.10.0/24, and the last 8 bits identify a host within it.
Learn more: Subnet Mask Basics
Here, the first three octets are the network part only because the prefix is /24. That isn't true for every address. Change the prefix below and watch the split move:
- Subnet mask
- 255.255.255.0
- Network address
- 192.168.10.0/24
- First usable
- 192.168.10.1
- Last usable
- 192.168.10.254
- Broadcast address
- 192.168.10.255
- Addresses
- 256 total · 254 usable
Different subnet: send to the default gateway
192.168.20.50 is outside 192.168.10.0/24. The frame goes to the gateway's MAC address ( 192.168.10.1 ), while the IP packet inside is still addressed to 192.168.20.50.
Network, usable and broadcast addresses
For the subnet 192.168.10.0/24:
| Address | Value | Purpose |
|---|---|---|
| Network address | 192.168.10.0 | Identifies the subnet itself |
| First usable | 192.168.10.1 | Can be assigned to an interface |
| Last usable | 192.168.10.254 | Can be assigned to an interface |
| Broadcast address | 192.168.10.255 | Reaches every host in the subnet |
The network and broadcast addresses aren't assigned to hosts. The default gateway can use any usable address; .1 is just a common convention.
In CIDR (Classless Inter-Domain Routing) slash notation, the number after the slash is simply the number of network bits. You don't need these sizes for the Fundamentals course; they belong to Subnetting. They are included here for reference.
| Prefix | Subnet mask | Total addresses | Usable hosts |
|---|---|---|---|
| /16 | 255.255.0.0 | 65,536 | 65,534 |
| /24 | 255.255.255.0 | 256 | 254 |
| /25 | 255.255.255.128 | 128 | 126 |
| /26 | 255.255.255.192 | 64 | 62 |
| /27 | 255.255.255.224 | 32 | 30 |
| /28 | 255.255.255.240 | 16 | 14 |
| /30 | 255.255.255.252 | 4 | 2 |
Total addresses = 2(32 − prefix), and usable hosts = total − 2 (the network and broadcast addresses). Two exceptions: a /31 point-to-point link uses both of its addresses, and a /32 is a single address. Don't apply “minus two” everywhere.
Worked example: 192.168.10.70/26. A /26 holds 64 addresses, so a /24 splits into four /26 subnets:
| Subnet | Address span |
|---|---|
192.168.10.0/26 | .0 – .63 |
192.168.10.64/26 | .64 – .127 ← 70 is here |
192.168.10.128/26 | .128 – .191 |
192.168.10.192/26 | .192 – .255 |
| Result | Value |
|---|---|
| Subnet mask | 255.255.255.192 |
| Network address | 192.168.10.64 |
| First usable | 192.168.10.65 |
| Last usable | 192.168.10.126 |
| Broadcast | 192.168.10.127 |
| Usable hosts | 62 |
This is also why you can't judge an address ending in .0 or .255 without its prefix: in a /22, 192.168.9.255 is a normal host address. You can practise with the Subnetting Practice tool.
Static vs dynamic IP addresses
A device can get its IP settings in two ways. Either a person types them in (a static address), or the device requests them automatically (a dynamic address). The same four settings are needed either way: IP address, subnet mask, default gateway and DNS server.
Static (manual)
- Someone types the IP address, subnet mask, default gateway and DNS server into the device.
- The address never changes unless a person changes it.
- Used for servers, printers, routers, switches and firewalls: devices that others must always find at the same address.
- Risk: typing mistakes and duplicate addresses, because nothing checks your work.
Dynamic (DHCP)
- The device asks a DHCP server for its settings when it joins the network.
- The address is leased for a period of time and may change later.
- Used for laptops, phones, tablets and most PCs: the vast majority of devices.
- Risk: if the DHCP server is down, the device gives itself a 169.254.x.x address that only works on the local link.
How a dynamic address is handed out
Dynamic addresses come from DHCP (Dynamic Host Configuration Protocol). In a home, the DHCP server is built into the home router. When the laptop joins the network, it broadcasts a request, and the router lends it a free address from its pool for a set time, called a lease. The printer below was configured by hand instead, with an address outside the pool, so DHCP never gives that address to another device.
- 1. The laptop joins. It has no address yet, so it broadcasts a DHCP request for its settings.
- 2. The router leases an address. The DHCP server picks a free address from its pool (for example, .20 to .200) and sends it with the subnet mask, default gateway and DNS server.
- 3. The phone does the same. Every DHCP client gets its own address from the pool. Tomorrow, it might get a different one.
- 4. The static printer is always at .5. Because the printer's address never changes, every laptop can be set up once to print to 192.168.10.5.
| Question | Static | Dynamic (DHCP) |
|---|---|---|
| Who sets it? | An administrator, by hand | A DHCP server, automatically |
| Does it change? | Never, unless edited | It can, when the lease ends |
| Effort for 500 laptops | Huge, and error-prone | None after the server is set up |
| Typical devices | Routers, servers, printers, cameras | PCs, laptops, phones, guests |
| Main failure | Typos, duplicate addresses | No server reply → 169.254.x.x |
💡 A middle option is a DHCP reservation: the DHCP server always gives the same address to one MAC address. The device still uses DHCP, but its address doesn't change. Many home routers call this “address reservation” or “static lease”.
Internet providers also use “static” and “dynamic” to describe your public address. That is a different topic, with its own lesson.
Learn more: Public and Private IP Addresses
Other ways addresses are assigned
| Method | How it works |
|---|---|
| Static | Settings typed in manually |
| DHCPv4 | A server leases an address and supplies options |
| APIPA / link-local | No DHCP reply: the device picks a 169.254.x.x address itself (local link only) |
| IPv6 SLAAC | The host builds its own address from the prefix that routers advertise |
| Stateful DHCPv6 | A server assigns IPv6 addresses |
| Stateless DHCPv6 | A server supplies extra settings (such as DNS), but not the address |
In IPv6, the default gateway is learned from routers' Router Advertisements. DHCPv6 doesn't provide it.
Local destination or gateway?
Before sending, a host compares the destination with its own subnet. (More precisely, it checks its routing table; the default gateway is used when no more specific route matches.) For the laptop at 192.168.10.25/24:
| Destination | Decision |
|---|---|
192.168.10.50 | Same subnet: deliver directly |
192.168.20.50 | Different subnet: send to the default gateway |
On Ethernet, ARP finds the MAC address of the next device on the path. For a remote destination, that is the default gateway. So the frame goes to the gateway's MAC address, while the IP packet inside is still addressed to the remote host. Tap a step to see the addresses:
Learn more: The Default Gateway
Public and private IPv4 addresses
These ranges are reserved for private, internal networks (RFC 1918):
| Private block | Full range |
|---|---|
10.0.0.0/8 | 10.0.0.0 – 10.255.255.255 |
172.16.0.0/12 | 172.16.0.0 – 172.31.255.255 |
192.168.0.0/16 | 192.168.0.0 – 192.168.255.255 |
Any organisation can reuse these ranges, and they aren't routed on the public internet. Only the exact ranges shown are private: 172.15.0.1 and 172.32.0.1 are not. An address outside these ranges isn't automatically public either; it may be a special-purpose address (see below). And having a public address doesn't make a device reachable: routing and firewalls still decide that.
Learn more: Public and Private IP Addresses
NAT: sharing one public address
Home and office gateways usually run PAT (Port Address Translation, also called NAPT or NAT overload). Many internal addresses share one public address, and translated port numbers keep the connections apart.
| Inside (private) | Outside (translated) |
|---|---|
192.168.10.25:51524 | 203.0.113.10:40001 |
192.168.10.30:51524 | 203.0.113.10:40002 |
NAT translates addresses; it isn't a firewall. Firewall policy decides which traffic is allowed.
Learn more: Why NAT ExistsHow NAT and PAT Work
Special IPv4 addresses
| Address or range | Meaning |
|---|---|
127.0.0.0/8 | Loopback, usually 127.0.0.1 (the device itself) |
169.254.0.0/16 | Link-local (APIPA when DHCP fails) |
100.64.0.0/10 | Shared address space, used for carrier-grade NAT |
0.0.0.0 | Unspecified (“no address yet”) |
255.255.255.255 | Limited broadcast (never routed) |
192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24 | Reserved for documentation examples |
Don't confuse 0.0.0.0 with 0.0.0.0/0: the second is the default route, which means “every destination”.
IPv6: a much larger address space
IPv4 has about 4.3 billion addresses (232), and the pool of unallocated addresses ran out years ago. IPv6 addresses are 128 bits long, written as eight groups of hexadecimal digits separated by colons:
2001:0db8:0010:0000:0000:0000:0000:0025Full form
2001:db8:10::25Shortened
There are two shortening rules. Drop leading zeros inside a group, and replace one run of all-zero groups with ::. You can use :: only once per address, or the address becomes ambiguous. IPv6 has unicast, multicast and anycast addresses, but no broadcast.
| Type | Prefix / example | Purpose |
|---|---|---|
| Global unicast | Usually within 2000::/3 | Globally routable addresses |
| Link-local | fe80::/10 | Only on the local link; every interface has one |
| Unique local | fc00::/7 (in practice fd…) | Internal addressing, like IPv4 private ranges |
| Multicast | ff00::/8 | Delivery to a group |
| Loopback | ::1 | The device itself |
| Unspecified | :: | No address |
2001:db8::/32 is reserved for documentation. A typical IPv6 LAN is a /64, and IPv6 has no “minus two” rule.
Going further with IPv6: one lesson shows how to read, shorten and expand IPv6 addresses and what prefixes such as /48 and /64 mean. Another covers link-local and multicast addresses, SLAAC, DHCPv6 and Neighbor Discovery.
Learn more: IPv6 Addressing BasicsIPv6 Address Types and Autoconfiguration
IP addresses and ports work together
An IP address identifies an interface; a TCP or UDP port number identifies an application on it (see Port numbers and sockets).
192.168.10.25:51524 → 203.0.113.20:443| Part | Meaning |
|---|---|
| Source IP | The sending interface |
| Source port | The client application (a temporary port) |
| Destination IP | The receiving interface |
| Destination port | The service, here 443 (HTTPS) |
IP itself has no port numbers; TCP and UDP carry them in their own headers.
What happens when IP addressing goes wrong
| Problem | What you see | Why |
|---|---|---|
| No DHCP reply | Address 169.254.x.x, no gateway, “No internet” | The device gave itself a link-local address that only works on the local link |
| Duplicate address | Connection drops, “address conflict” warning | Two devices claim the same IP address, so traffic reaches one or the other |
| Address from the wrong network | Nothing outside the PC works | The address doesn't match the subnet the cable is plugged into |
| Wrong subnet mask | Some devices reachable, others not | The PC misjudges which addresses are local (see the quiz below) |
Typo such as 192.168.10.256 | The OS refuses the setting | 256 does not fit in one octet |
Checking a device's address
Windows
ipconfig /allEvery adapter's IPv4 and IPv6 addresses, mask and default gateway.
C:\> ipconfig /all Ethernet adapter Ethernet: Connection-specific DNS Suffix . : home.arpa Physical Address. . . . . . . . . : 02-00-00-00-00-25 DHCP Enabled. . . . . . . . . . . : Yes IPv4 Address. . . . . . . . . . . : 192.168.10.25(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : Monday, 5 October 2026 09:12:40 Lease Expires . . . . . . . . . . : Tuesday, 6 October 2026 09:12:40 Default Gateway . . . . . . . . . : 192.168.10.1 DHCP Server . . . . . . . . . . . : 192.168.10.1 DNS Servers . . . . . . . . . . . : 192.168.10.1
Linux / macOS
ip addrEvery interface with its IPv4 and IPv6 addresses (macOS: ifconfig).
$ ip -4 addr show eth0 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000 inet 192.168.10.25/24 brd 192.168.10.255 scope global dynamic noprefixroute eth0 valid_lft 86234sec preferred_lft 86234sec
inet 192.168.10.25/24 is the address and prefix, and brd is the subnet's broadcast address. The word dynamic with a valid_lft countdown means the address was learned from DHCP. A static address shows valid_lft forever.To see the public address your network uses on the internet, use the What Is My IP tool. It is almost never the private address that these commands show.
Common mistakes
- Thinking the IP address belongs to the device. It belongs to an interface, and it changes when you move to another network.
- Mixing up IP and MAC addresses. An IP address is logical and used end to end; a MAC address is used only on the local link.
- Giving a device a static address from inside the DHCP pool. Sooner or later, DHCP gives the same address to another device and the two clash.
- Forgetting the subnet mask.
192.168.10.25alone doesn't tell you which network it is on; you also need the mask or prefix. - Using address classes to guess masks. Classes are historical; always read the configured prefix.
- Assuming the default gateway is always .1. That is only a convention. Check the configured gateway with
ipconfigorip route.
Practice: predict what happens
You are writing the address 192.168.10.25 in binary. What is the binary value of the second octet, 168?
A laptop shows the address 169.254.37.12 and no default gateway. What is the most likely cause?
A laptop is set to 192.168.10.25 with the mask 255.255.0.0 instead of 255.255.255.0. It tries to reach 192.168.20.50, which is on another subnet behind the router. What happens?
A PC has the correct address and mask, but its default gateway is set to 192.168.10.99, an address that no device uses. What works and what doesn't?
Two devices on the same subnet are both manually set to 192.168.10.50. What do the other devices notice?
An engineer sees 10.20.30.40 and assumes the mask is 255.0.0.0 because it is a "Class A" address. The interface is really configured as /24. What is the result?
- An IP address is a logical Layer 3 address; a MAC address is a physical Layer 2 address. Both are needed.
- An IPv4 address is 32 bits, split into four 8-bit octets and written in dotted decimal (each octet 0–255).
- The subnet mask decides which bits are the network part and which are the host part.
- Static addresses are typed in by hand; dynamic addresses are leased by DHCP. Servers and printers usually have static addresses; clients usually have dynamic ones.
- Same subnet: deliver directly. Different subnet: send the frame to the gateway, with the packet still addressed to the destination.
- Only 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 are private; not every non-private address is public.
- IPv6 addresses are 128 bits, IPv6 has no broadcast, and hosts learn their gateway from Router Advertisements.
Next, learn which addresses are used inside homes and offices and which are used on the internet, and how the subnet mask works.
Learn more: Public and Private IP AddressesSubnet Mask Basics