Your laptop has an IP address, your office router has an IP address, and if you check "what is my IP" online you get yet another number. That is because devices typically have two kinds of address: a private one used inside your building, and a public one that represents your whole network on the internet. Understanding public vs private IP addresses explains a lot of everyday puzzles, from why a colleague cannot reach your shared folder from home to why a firewall rule did not work.
Private IP addresses: for use inside a network
Private addresses are reserved ranges, defined in RFC 1918, that anyone may use inside their own network without asking permission. Internet routers do not forward traffic to them, so the same addresses can be reused in millions of homes and offices at once.
| Range | CIDR | Number of addresses | Where you typically see it |
|---|---|---|---|
| 10.0.0.0 – 10.255.255.255 | 10.0.0.0/8 | About 16.7 million | Larger companies, cloud networks |
| 172.16.0.0 – 172.31.255.255 | 172.16.0.0/12 | About 1 million | Corporate networks, Docker defaults |
| 192.168.0.0 – 192.168.255.255 | 192.168.0.0/16 | 65,536 | Home and small-office routers |
A common mistake: 172.32.0.1 is not private. The 172 range only runs from 172.16 to 172.31.
A few other non-public ranges are worth recognizing:
127.0.0.0/8: loopback.127.0.0.1always means "this computer".169.254.0.0/16: link-local. If a computer shows an address like169.254.x.x, it failed to get an address from the network's DHCP server, which usually points to a cable, Wi-Fi or router problem.100.64.0.0/10: shared address space for carrier-grade NAT, used by some internet providers between your router and their network.
Public IP addresses: your identity on the internet
A public IP address is globally unique and routable on the internet. Regional Internet Registries allocate them to internet providers and organizations, and your provider assigns one (or a block) to your connection. Websites, email servers and anything else that must be reachable from the internet need a public address, either directly or through a load balancer or proxy that has one.
When you visit a website, the site sees your network's public address, not your laptop's private one. Every device in an office typically shares that one public address on the way out. You can see yours instantly with What Is My IP.
How the two connect: NAT
The bridge between private and public is Network Address Translation (NAT), performed by your router or firewall. When a laptop at 192.168.1.23 requests a web page, the router replaces the private source address with its own public address, remembers the conversation, and passes replies back to the right device. To the outside world, the whole office looks like a single address.
NAT is the reason the world has not completely run out of IPv4 addresses, and it has a side effect: devices behind it cannot be reached from the internet unless you deliberately set up port forwarding or a similar rule.
Public vs private IP: side-by-side
| Private IP | Public IP | |
|---|---|---|
| Scope | Inside one local network | Unique across the internet |
| Assigned by | Your router's DHCP server or you | Your internet or cloud provider |
| Reachable from the internet | No, not directly | Yes, subject to firewalls |
| Cost | Free to use | Included with service; extra static addresses may cost more |
| Example | 192.168.1.23 | 203.0.113.45 |
What about IPv6?
The public/private split is mostly an IPv4 workaround for address shortage. IPv6 has so many addresses that devices normally receive globally unique addresses directly, and NAT is rarely used. IPv6 does have an equivalent of private space, called Unique Local Addresses (fc00::/7, in practice fd00::/8), and every interface also has a link-local address starting fe80::. Because IPv6 devices may be directly addressable, a properly configured firewall matters even more than on IPv4.
How to find each address
Private IP:
- Windows: run
ipconfigin Command Prompt and look for "IPv4 Address". - macOS:
ipconfig getifaddr en0in Terminal (en0 is often Wi-Fi), or System Settings > Network. - Linux:
ip addr showorhostname -I.
Public IP: open What Is My IP in a browser, or from a server's command line run curl https://ifconfig.me or a similar service.
Why the difference matters in practice
- Firewall and allow-list rules. When a supplier asks "which IP should we allow?", they need your public address. Giving them
192.168.x.xwill not work. - Remote access. A file server at
192.168.1.10cannot be reached from home by that address. Use a VPN rather than exposing the server to the internet. - Cloud servers. Cloud instances usually have a private address inside the virtual network and optionally a public one. Databases and internal services should stay on private addresses only.
- Email and DNS. DNS A records for websites and mail servers must point to public addresses. A record pointing at a private address works only inside your own network.
- Carrier-grade NAT. If your router's "WAN" address is private or in
100.64.0.0/10but websites see a different public IP, your provider is sharing addresses between customers. Port forwarding will not work; ask the provider for a public or static IP if you need inbound connections.
When planning how to divide private ranges into segments for different teams or devices, a subnet calculator helps you avoid overlaps.
Key takeaways
- Private addresses (10/8, 172.16/12, 192.168/16) are for internal networks and are not routed on the internet.
- Public addresses are globally unique and are how the internet sees your network.
- NAT lets many private devices share one public address.
- Give partners your public IP for allow-lists, and keep internal servers on private addresses behind a VPN.