Blog

Networking articles

Public vs Private IP Addresses: What's the Difference?

Public vs private IP addresses explained: the reserved private ranges, how NAT connects them, how to find each one, and why the difference matters.

4 min read Networking

Your laptop has an IP address, your office router has an IP address, and if you check "what is my IP" online you get yet another number. That is because devices typically have two kinds of address: a private one used inside your building, and a public one that represents your whole network on the internet. Understanding public vs private IP addresses explains a lot of everyday puzzles, from why a colleague cannot reach your shared folder from home to why a firewall rule did not work.

Private IP addresses: for use inside a network

Private addresses are reserved ranges, defined in RFC 1918, that anyone may use inside their own network without asking permission. Internet routers do not forward traffic to them, so the same addresses can be reused in millions of homes and offices at once.

RangeCIDRNumber of addressesWhere you typically see it
10.0.0.0 – 10.255.255.25510.0.0.0/8About 16.7 millionLarger companies, cloud networks
172.16.0.0 – 172.31.255.255172.16.0.0/12About 1 millionCorporate networks, Docker defaults
192.168.0.0 – 192.168.255.255192.168.0.0/1665,536Home and small-office routers

A common mistake: 172.32.0.1 is not private. The 172 range only runs from 172.16 to 172.31.

A few other non-public ranges are worth recognizing:

  • 127.0.0.0/8: loopback. 127.0.0.1 always means "this computer".
  • 169.254.0.0/16: link-local. If a computer shows an address like 169.254.x.x, it failed to get an address from the network's DHCP server, which usually points to a cable, Wi-Fi or router problem.
  • 100.64.0.0/10: shared address space for carrier-grade NAT, used by some internet providers between your router and their network.

Public IP addresses: your identity on the internet

A public IP address is globally unique and routable on the internet. Regional Internet Registries allocate them to internet providers and organizations, and your provider assigns one (or a block) to your connection. Websites, email servers and anything else that must be reachable from the internet need a public address, either directly or through a load balancer or proxy that has one.

When you visit a website, the site sees your network's public address, not your laptop's private one. Every device in an office typically shares that one public address on the way out. You can see yours instantly with What Is My IP.

How the two connect: NAT

The bridge between private and public is Network Address Translation (NAT), performed by your router or firewall. When a laptop at 192.168.1.23 requests a web page, the router replaces the private source address with its own public address, remembers the conversation, and passes replies back to the right device. To the outside world, the whole office looks like a single address.

NAT is the reason the world has not completely run out of IPv4 addresses, and it has a side effect: devices behind it cannot be reached from the internet unless you deliberately set up port forwarding or a similar rule.

Public vs private IP: side-by-side

Private IPPublic IP
ScopeInside one local networkUnique across the internet
Assigned byYour router's DHCP server or youYour internet or cloud provider
Reachable from the internetNo, not directlyYes, subject to firewalls
CostFree to useIncluded with service; extra static addresses may cost more
Example192.168.1.23203.0.113.45

What about IPv6?

The public/private split is mostly an IPv4 workaround for address shortage. IPv6 has so many addresses that devices normally receive globally unique addresses directly, and NAT is rarely used. IPv6 does have an equivalent of private space, called Unique Local Addresses (fc00::/7, in practice fd00::/8), and every interface also has a link-local address starting fe80::. Because IPv6 devices may be directly addressable, a properly configured firewall matters even more than on IPv4.

How to find each address

Private IP:

  • Windows: run ipconfig in Command Prompt and look for "IPv4 Address".
  • macOS: ipconfig getifaddr en0 in Terminal (en0 is often Wi-Fi), or System Settings > Network.
  • Linux: ip addr show or hostname -I.

Public IP: open What Is My IP in a browser, or from a server's command line run curl https://ifconfig.me or a similar service.

Why the difference matters in practice

  • Firewall and allow-list rules. When a supplier asks "which IP should we allow?", they need your public address. Giving them 192.168.x.x will not work.
  • Remote access. A file server at 192.168.1.10 cannot be reached from home by that address. Use a VPN rather than exposing the server to the internet.
  • Cloud servers. Cloud instances usually have a private address inside the virtual network and optionally a public one. Databases and internal services should stay on private addresses only.
  • Email and DNS. DNS A records for websites and mail servers must point to public addresses. A record pointing at a private address works only inside your own network.
  • Carrier-grade NAT. If your router's "WAN" address is private or in 100.64.0.0/10 but websites see a different public IP, your provider is sharing addresses between customers. Port forwarding will not work; ask the provider for a public or static IP if you need inbound connections.

When planning how to divide private ranges into segments for different teams or devices, a subnet calculator helps you avoid overlaps.

Key takeaways

  • Private addresses (10/8, 172.16/12, 192.168/16) are for internal networks and are not routed on the internet.
  • Public addresses are globally unique and are how the internet sees your network.
  • NAT lets many private devices share one public address.
  • Give partners your public IP for allow-lists, and keep internal servers on private addresses behind a VPN.

Need help with this?

Netifi helps businesses around the world with Networking. Tell us what you are working on.