What are public and private IP addresses?
Every IP address is either public or private (or one of a few special addresses covered later in this lesson).
🌍 Public address
Unique on the whole internet. Assigned to internet providers and organisations by official registries. Internet routers know how to reach it. Example: 203.0.113.20, a web server.
🏠 Private address
Free for anyone to use inside their own network, without asking permission. Internet routers do not route it. It only has to be unique inside that one network. Example: 192.168.1.10, your laptop.
💡 In simple terms: a private address is like an office extension number ("call 214"). It works fine inside the building, and every company can have its own extension 214. A public address is like the company's main phone number: unique in the world, and the only number outsiders can dial.
Why private addresses exist
IPv4 addresses are 32 bits long, so there are only about 4.3 billion of them. Today there are far more phones, laptops, TVs, cameras and servers than that. The regional registries ran out of free public IPv4 addresses during the 2010s.
In 1996, a standard called RFC 1918 set aside three blocks of addresses for private use. The idea is simple:
Private addresses bring two extra benefits. You can design your internal network freely, without asking a provider for addresses. And if you change provider, only the public address on the router changes; nothing inside the network needs new addresses.
The three private ranges (RFC 1918)
Learn these three blocks by heart. Every network engineer knows them.
| Private block | Full range | Addresses | How to spot it |
|---|---|---|---|
10.0.0.0/8 | 10.0.0.0 – 10.255.255.255 | 16,777,216 | First octet is 10 |
172.16.0.0/12 | 172.16.0.0 – 172.31.255.255 | 1,048,576 | First octet 172, second octet 16 to 31 |
192.168.0.0/16 | 192.168.0.0 – 192.168.255.255 | 65,536 | First two octets are 192.168 |
10.0.0.0/8
Large companies, data centres, cloud networks and VPNs. Big enough for thousands of separate subnets.
172.16.0.0/12
Medium-sized networks and many container and cloud platforms. The least familiar range, and the easiest to get wrong.
192.168.0.0/16
Home routers and small offices. Most home networks are 192.168.0.0/24 or 192.168.1.0/24.
The /8, /12 and /16 show how many bits at the start of the address are fixed (the subnet mask length). A network can use any part of a block. A home router might use only 192.168.1.0/24, while a company might use 10.0.0.0/8 split into hundreds of smaller subnets.
Is this address private? A quick check
- Does it start with
10.? → Private. - Does it start with
192.168.? → Private. - Does it start with
172.? Look at the second octet. 16 to 31 → private. Anything else → not private. - Does it start with
127.,169.254.or100.64–100.127? → Special (see below), not public. - None of the above? → Most likely a public address.
| Address | Verdict | Reason |
|---|---|---|
10.45.2.9 | Private | Starts with 10 |
172.20.1.5 | Private | 172 with second octet 20 (between 16 and 31) |
172.32.1.5 | Not private | Second octet 32 is outside 16–31 |
192.169.1.1 | Not private | Only 192.168 is private, not 192.169 |
169.254.10.20 | Link-local | APIPA: no DHCP server answered |
203.0.113.20 | Documentation (used as a public example) | Not private; reserved to stand in for public addresses in examples |
Where each type of address is used
Private addresses are used inside the network: on PCs, phones, printers and the inside interface of the router. The public address is on the outside (WAN) interface of the router that connects to the internet provider. The router is the border between the two, and in a home or small office it is usually also every device's default gateway.
How private devices reach the internet
If internet routers don't route private addresses, how does your laptop at 192.168.1.10 load a website? The home router changes the address on the way out. This is NAT (Network Address Translation), or more exactly PAT (Port Address Translation), which also changes port numbers so that many devices can share one public address. Follow a request step by step:
- 1. The laptop sends to its gateway. The packet is from 192.168.1.10 port 51000, to 203.0.113.20 port 443. The destination is on another network, so the laptop sends it to the router.
- 2. The router translates. It replaces the private source address with its public address, 198.51.100.7, picks a source port such as 40001, and records the mapping in its NAT table.
- 3. Only public addresses on the internet. Internet routers see a normal public source address and forward the packet to the web server.
- 4. The reply comes back to the router. The server replies to the public address. It never learns the laptop's private address.
- 5. The router translates back. It looks up port 40001 in its NAT table, changes the destination back to 192.168.1.10:51000 and forwards the reply to the laptop.
What changes in the packet
| Where the packet is | Source IP : port | Destination IP : port |
|---|---|---|
| Laptop → router (inside) | 192.168.1.10:51000 | 203.0.113.20:443 |
| Router → internet (outside) | 198.51.100.7:40001 | 203.0.113.20:443 |
| Server → router (reply) | 203.0.113.20:443 | 198.51.100.7:40001 |
| Router → laptop (reply) | 203.0.113.20:443 | 192.168.1.10:51000 |
Only the laptop's private address and port are rewritten. The server's public address never changes. Later lessons explain how the translation table works.
Learn more: Why NAT ExistsHow NAT and PAT Work
A side effect: devices on the internet cannot start a connection to your laptop, because there is no NAT table entry for their traffic to match. That is why hosting a game server at home needs port forwarding, a fixed rule on the router that sends one public port to one private address.
Carrier-grade NAT (CGNAT): 100.64.0.0/10
Many internet providers no longer have enough public addresses to give one to every customer. So they add a second layer of NAT inside their own network. This is carrier-grade NAT (CGNAT). Your router gets an address from the special block 100.64.0.0/10 (100.64.0.0 to 100.127.255.255), and the provider translates that to a public address shared by many customers.
100.64.0.0/10 is not one of the RFC 1918 ranges, and it is not public either. It exists so that providers don't clash with the private ranges customers already use at home. If your router's WAN address starts with 100.64 to 100.127, you are behind CGNAT, and port forwarding from the internet will usually not work.
Other special addresses you will see
Loopback
127.0.0.0/8
Means “this device”. Traffic to 127.0.0.1 never leaves the computer. It is used to test the network software and to reach services running on the same machine.
Link-local (APIPA)
169.254.0.0/16
A device gives itself one of these addresses when it asks for an address and no DHCP server answers. It only works on the local link, so it usually signals a problem.
Shared address space (CGNAT)
100.64.0.0/10
Used by internet providers between their own NAT and your router. It is neither an RFC 1918 private range nor public.
Documentation
192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24
Reserved for books, courses and examples like this one. They are not used on the real internet.
How to find your private and public IP addresses
Your private address
Ask your own computer. On Windows:
C:\> ipconfig Wireless LAN adapter Wi-Fi: Connection-specific DNS Suffix . : home.arpa IPv4 Address. . . . . . . . . . . : 192.168.1.10 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.1.1
192.168.1.10 is private (it starts with 192.168). Default Gateway 192.168.1.1 is the inside address of the home router. Your public address does not appear here.On Linux (macOS: ipconfig getifaddr en0):
$ ip -brief address lo UNKNOWN 127.0.0.1/8 ::1/128 wlan0 UP 192.168.1.10/24 fe80::ff:fe00:10/64
lo is the loopback interface, with 127.0.0.1. wlan0 is the Wi-Fi interface, and 192.168.1.10/24 is its private address. The fe80:: address is an IPv6 link-local address, which is normal.Your public address
Your computer usually doesn't know its public address, because the router translates its traffic. You have to ask a service on the internet which source address it sees: open What Is My IP. You can also look at the WAN or Internet status page of your home router. If the router's WAN address is different from the one the website shows, you are probably behind CGNAT.
When it goes wrong
| Symptom | Likely cause | What to check |
|---|---|---|
Laptop has 169.254.x.x | No DHCP reply, so no proper private address | Cable or Wi-Fi, then the DHCP server (see DHCP) |
| Port forward doesn't work | The router is behind CGNAT (WAN in 100.64.0.0/10), or a second router is also doing NAT | Compare the router's WAN address with What Is My IP |
| VPN connects but can't reach office servers | Home and office use the same private range, e.g. both 192.168.1.0/24 | Use a less common range at the office, such as a 10.x.x.x subnet |
| Private devices reach each other but not the internet | NAT or the router's internet link is down, or the default gateway is wrong | ping the gateway, then a public address |
Common mistakes
- Thinking all 172.x.x.x addresses are private. Only 172.16.0.0 to 172.31.255.255 is private. Addresses such as 172.32.1.5 are public.
- Thinking a private address means “safe”. The firewall decides what traffic is allowed, not the address type. Malware and phishing still reach private devices.
- Expecting the internet to reach a server that only has a private address. Without static NAT or port forwarding on the router, there is no way in from outside.
- Assuming any non-private address is public. Loopback, link-local, CGNAT and documentation ranges are special and are not routed as normal public addresses.
- Using 192.168.0.0/24 or 192.168.1.0/24 for a company network. Many home networks use the same ranges, so staff connecting over VPN will see address clashes.
- Public addresses are unique on the internet; private addresses are reused inside many separate networks.
- The private ranges are 10.0.0.0/8, 172.16.0.0/12 (172.16–172.31) and 192.168.0.0/16.
- Private ranges exist because there are not enough public IPv4 addresses.
- The edge router uses NAT/PAT to swap private source addresses for its public address.
- 100.64.0.0/10 is for carrier-grade NAT; 127.0.0.0/8 is loopback; 169.254.0.0/16 usually means no DHCP server answered.
- Find your private IP address with ipconfig or ip address; find your public IP address with a website such as What Is My IP.
Check yourself
You are checking a list of addresses from a firewall log. Which one is a private address?
Your laptop, 192.168.1.10, visits a website. Which source IP address does the web server see?
Your router's WAN page shows 100.72.8.9, but What Is My IP shows 203.0.113.50. What does this tell you?
You and your neighbour both have a laptop at 192.168.1.10. Why is there no conflict?
Next, learn how a device knows which part of an address is the network.
Learn more: Subnet Mask Basics