Routelearn.net
Course menu

Unit 5: IP Addressing BasicsLesson 5.2 (2 of 6 in this unit)26 of 84 in the Network Fundamentals course

Public and Private IP Addresses

Some IPv4 addresses work across the whole internet; others only work inside a home or company network. Learn the difference, the three private ranges every network engineer knows by heart, and how devices with private addresses still reach the internet.

Beginner · 13 min read · Before this: What is an IP address?

Public and private IP addresses are the two main types of IPv4 unicast address. Public addresses are globally unique and routed across the internet. Private addresses come from the RFC 1918 ranges (10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16), can be reused inside any organisation and are not routed on the public internet.

In simple terms: A public address is like a street address that anyone in the world can send post to. A private address only works inside your own home or company network, so the router translates it (NAT) when you go online.

What are public and private IP addresses?

Every IP address is either public or private (or one of a few special addresses covered later in this lesson).

🌍 Public address

Unique on the whole internet. Assigned to internet providers and organisations by official registries. Internet routers know how to reach it. Example: 203.0.113.20, a web server.

🏠 Private address

Free for anyone to use inside their own network, without asking permission. Internet routers do not route it. It only has to be unique inside that one network. Example: 192.168.1.10, your laptop.

💡 In simple terms: a private address is like an office extension number ("call 214"). It works fine inside the building, and every company can have its own extension 214. A public address is like the company's main phone number: unique in the world, and the only number outsiders can dial.

Why private addresses exist

IPv4 addresses are 32 bits long, so there are only about 4.3 billion of them. Today there are far more phones, laptops, TVs, cameras and servers than that. The regional registries ran out of free public IPv4 addresses during the 2010s.

In 1996, a standard called RFC 1918 set aside three blocks of addresses for private use. The idea is simple:

Reserve some address blocks for private use
Nobody owns them, and internet routers do not carry them.
Every home and company reuses the same blocks
Millions of networks can use 192.168.1.0/24 at the same time, because they never talk to each other directly.
Each network gets only one (or a few) public addresses
The internet provider assigns them to the router at the edge.
The edge router translates private to public (NAT)
Hundreds of private devices share one public address on the internet.
How private addressing delayed IPv4 address exhaustion by many years.

Private addresses bring two extra benefits. You can design your internal network freely, without asking a provider for addresses. And if you change provider, only the public address on the router changes; nothing inside the network needs new addresses.

The three private ranges (RFC 1918)

Learn these three blocks by heart. Every network engineer knows them.

Private blockFull rangeAddressesHow to spot it
10.0.0.0/810.0.0.0 – 10.255.255.25516,777,216First octet is 10
172.16.0.0/12172.16.0.0 – 172.31.255.2551,048,576First octet 172, second octet 16 to 31
192.168.0.0/16192.168.0.0 – 192.168.255.25565,536First two octets are 192.168

10.0.0.0/8

Large companies, data centres, cloud networks and VPNs. Big enough for thousands of separate subnets.

172.16.0.0/12

Medium-sized networks and many container and cloud platforms. The least familiar range, and the easiest to get wrong.

192.168.0.0/16

Home routers and small offices. Most home networks are 192.168.0.0/24 or 192.168.1.0/24.

The /8, /12 and /16 show how many bits at the start of the address are fixed (the subnet mask length). A network can use any part of a block. A home router might use only 192.168.1.0/24, while a company might use 10.0.0.0/8 split into hundreds of smaller subnets.

Is this address private? A quick check

  1. Does it start with 10.? → Private.
  2. Does it start with 192.168.? → Private.
  3. Does it start with 172.? Look at the second octet. 16 to 31 → private. Anything else → not private.
  4. Does it start with 127., 169.254. or 100.64–100.127? → Special (see below), not public.
  5. None of the above? → Most likely a public address.
AddressVerdictReason
10.45.2.9PrivateStarts with 10
172.20.1.5Private172 with second octet 20 (between 16 and 31)
172.32.1.5Not privateSecond octet 32 is outside 16–31
192.169.1.1Not privateOnly 192.168 is private, not 192.169
169.254.10.20Link-localAPIPA: no DHCP server answered
203.0.113.20Documentation (used as a public example)Not private; reserved to stand in for public addresses in examples

Where each type of address is used

Private addresses are used inside the network: on PCs, phones, printers and the inside interface of the router. The public address is on the outside (WAN) interface of the router that connects to the internet provider. The router is the border between the two, and in a home or small office it is usually also every device's default gateway.

How private devices reach the internet

If internet routers don't route private addresses, how does your laptop at 192.168.1.10 load a website? The home router changes the address on the way out. This is NAT (Network Address Translation), or more exactly PAT (Port Address Translation), which also changes port numbers so that many devices can share one public address. Follow a request step by step:

Laptop192.168.1.10 (private)Home routerin 192.168.1.1 · out 198.51.100.7Internetpublic addresses onlyWeb server203.0.113.20 (public)
  1. 1. The laptop sends to its gateway. The packet is from 192.168.1.10 port 51000, to 203.0.113.20 port 443. The destination is on another network, so the laptop sends it to the router.
  2. 2. The router translates. It replaces the private source address with its public address, 198.51.100.7, picks a source port such as 40001, and records the mapping in its NAT table.
  3. 3. Only public addresses on the internet. Internet routers see a normal public source address and forward the packet to the web server.
  4. 4. The reply comes back to the router. The server replies to the public address. It never learns the laptop's private address.
  5. 5. The router translates back. It looks up port 40001 in its NAT table, changes the destination back to 192.168.1.10:51000 and forwards the reply to the laptop.
Private addresses stay inside. The router's public address is the only one the internet sees.

What changes in the packet

Where the packet isSource IP : portDestination IP : port
Laptop → router (inside)192.168.1.10:51000203.0.113.20:443
Router → internet (outside)198.51.100.7:40001203.0.113.20:443
Server → router (reply)203.0.113.20:443198.51.100.7:40001
Router → laptop (reply)203.0.113.20:443192.168.1.10:51000

Only the laptop's private address and port are rewritten. The server's public address never changes. Later lessons explain how the translation table works.

Learn more: Why NAT ExistsHow NAT and PAT Work

A side effect: devices on the internet cannot start a connection to your laptop, because there is no NAT table entry for their traffic to match. That is why hosting a game server at home needs port forwarding, a fixed rule on the router that sends one public port to one private address.

Carrier-grade NAT (CGNAT): 100.64.0.0/10

Many internet providers no longer have enough public addresses to give one to every customer. So they add a second layer of NAT inside their own network. This is carrier-grade NAT (CGNAT). Your router gets an address from the special block 100.64.0.0/10 (100.64.0.0 to 100.127.255.255), and the provider translates that to a public address shared by many customers.

Laptop
192.168.1.10
Home router NAT
WAN 100.64.12.34
Provider CGNAT
public 203.0.113.50
Internet
sees 203.0.113.50
With CGNAT, traffic is translated twice: once at home and once at the provider.

100.64.0.0/10 is not one of the RFC 1918 ranges, and it is not public either. It exists so that providers don't clash with the private ranges customers already use at home. If your router's WAN address starts with 100.64 to 100.127, you are behind CGNAT, and port forwarding from the internet will usually not work.

Other special addresses you will see

Loopback

127.0.0.0/8

Means “this device”. Traffic to 127.0.0.1 never leaves the computer. It is used to test the network software and to reach services running on the same machine.

Link-local (APIPA)

169.254.0.0/16

A device gives itself one of these addresses when it asks for an address and no DHCP server answers. It only works on the local link, so it usually signals a problem.

Shared address space (CGNAT)

100.64.0.0/10

Used by internet providers between their own NAT and your router. It is neither an RFC 1918 private range nor public.

Documentation

192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24

Reserved for books, courses and examples like this one. They are not used on the real internet.

How to find your private and public IP addresses

Your private address

Ask your own computer. On Windows:

Example output from a Windows PC, shortened and written for this lesson
C:\> ipconfig
Wireless LAN adapter Wi-Fi:

   Connection-specific DNS Suffix  . : home.arpa
   IPv4 Address. . . . . . . . . . . : 192.168.1.10
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.1
What to look for: IPv4 Address 192.168.1.10 is private (it starts with 192.168). Default Gateway 192.168.1.1 is the inside address of the home router. Your public address does not appear here.

On Linux (macOS: ipconfig getifaddr en0):

Example output from a Linux PC, written for this lesson
$ ip -brief address
lo               UNKNOWN        127.0.0.1/8 ::1/128
wlan0            UP             192.168.1.10/24 fe80::ff:fe00:10/64
What to look for: lo is the loopback interface, with 127.0.0.1. wlan0 is the Wi-Fi interface, and 192.168.1.10/24 is its private address. The fe80:: address is an IPv6 link-local address, which is normal.

Your public address

Your computer usually doesn't know its public address, because the router translates its traffic. You have to ask a service on the internet which source address it sees: open What Is My IP. You can also look at the WAN or Internet status page of your home router. If the router's WAN address is different from the one the website shows, you are probably behind CGNAT.

When it goes wrong

SymptomLikely causeWhat to check
Laptop has 169.254.x.xNo DHCP reply, so no proper private addressCable or Wi-Fi, then the DHCP server (see DHCP)
Port forward doesn't workThe router is behind CGNAT (WAN in 100.64.0.0/10), or a second router is also doing NATCompare the router's WAN address with What Is My IP
VPN connects but can't reach office serversHome and office use the same private range, e.g. both 192.168.1.0/24Use a less common range at the office, such as a 10.x.x.x subnet
Private devices reach each other but not the internetNAT or the router's internet link is down, or the default gateway is wrongping the gateway, then a public address

Common mistakes

  • Thinking all 172.x.x.x addresses are private. Only 172.16.0.0 to 172.31.255.255 is private. Addresses such as 172.32.1.5 are public.
  • Thinking a private address means “safe”. The firewall decides what traffic is allowed, not the address type. Malware and phishing still reach private devices.
  • Expecting the internet to reach a server that only has a private address. Without static NAT or port forwarding on the router, there is no way in from outside.
  • Assuming any non-private address is public. Loopback, link-local, CGNAT and documentation ranges are special and are not routed as normal public addresses.
  • Using 192.168.0.0/24 or 192.168.1.0/24 for a company network. Many home networks use the same ranges, so staff connecting over VPN will see address clashes.
✅ Key takeaways
  • Public addresses are unique on the internet; private addresses are reused inside many separate networks.
  • The private ranges are 10.0.0.0/8, 172.16.0.0/12 (172.16–172.31) and 192.168.0.0/16.
  • Private ranges exist because there are not enough public IPv4 addresses.
  • The edge router uses NAT/PAT to swap private source addresses for its public address.
  • 100.64.0.0/10 is for carrier-grade NAT; 127.0.0.0/8 is loopback; 169.254.0.0/16 usually means no DHCP server answered.
  • Find your private IP address with ipconfig or ip address; find your public IP address with a website such as What Is My IP.

Check yourself

Predict · scenario 1

You are checking a list of addresses from a firewall log. Which one is a private address?

Predict · scenario 2

Your laptop, 192.168.1.10, visits a website. Which source IP address does the web server see?

Predict · scenario 3

Your router's WAN page shows 100.72.8.9, but What Is My IP shows 203.0.113.50. What does this tell you?

Predict · scenario 4

You and your neighbour both have a laptop at 192.168.1.10. Why is there no conflict?

Next, learn how a device knows which part of an address is the network.

Learn more: Subnet Mask Basics

FAQ

Is a private IP address more secure than a public one?
Not by itself. A private address can't be reached directly from the internet, which helps, but real protection comes from the firewall rules on the router. Devices with private addresses can still be attacked through malware, phishing or a badly configured port forward.
Why do so many homes use the same 192.168.1.x addresses?
Many home routers use 192.168.1.0/24 by default, and private addresses only have to be unique inside one network. Your 192.168.1.10 and your neighbour's 192.168.1.10 never meet, because each home is hidden behind its own public address.
Is 172.32.0.1 a private address?
No. The private 172 block only covers 172.16.0.0 to 172.31.255.255 (172.16.0.0/12). Addresses such as 172.32.0.1 and 172.15.0.1 are outside it.
Why does my router's WAN address start with 100.64?
Your provider is using carrier-grade NAT (CGNAT). Your router gets an address from the shared 100.64.0.0/10 block, and the provider translates it to a public address that many customers share. Port forwarding from the internet usually won't work in this setup.