Network Fundamentals

Public vs Private IP Addresses: A Practical Network Map

Private IPs identify devices inside a local network; public IPs route internet responses. See how NAT connects the two.

Muhammad Azhar August 14, 2026 Reviewed August 21, 2026 3 min read

A private IP identifies a device inside a home or organization. A public IP is reachable through internet routing and is normally assigned to the router or provider-facing connection.

Common IPv4 private ranges

  • 10.0.0.0/8
  • 172.16.0.0/12
  • 192.168.0.0/16

How NAT connects them

The router translates many internal connections through one public address and keeps a table so replies return to the correct device. A website normally sees the public address, not a laptop's private address.

Do not confuse privacy with secrecy

A private address is not globally routed, but devices on the same local network may still reach one another. Firewalls, guest networks and device permissions remain important.

IPv6

IPv6 changes address structure and can provide globally routable addresses, while firewalls and temporary privacy addresses manage exposure. The public/private IPv4 model should not be copied blindly to IPv6.

Find each address without confusion

The operating system's network details show the local address and gateway. A public-IP service shows the internet-facing address. They may match on some IPv6 setups but usually differ on home IPv4 networks.

Do not publish router screenshots carelessly

Private addresses are not internet secrets, yet screenshots can expose Wi-Fi names, device labels, public addresses and administration details together. Redact the whole context before asking for help publicly.

Use the address in the correct scope

A private IPv4 address identifies a device only within its local network and is translated at the router in common home setups. The public address identifies the internet-facing connection and may be shared by a household or many carrier customers. It is not reliable proof of one person.

IPv6 changes familiar assumptions

Devices can have globally routable IPv6 addresses while a firewall still blocks unsolicited inbound traffic. Privacy extensions may rotate interface identifiers, and multiple addresses can exist simultaneously. Do not disable the firewall because an address looks “public,” and do not assume NAT is the security boundary.

For troubleshooting, record the local address, gateway, public address, protocol and time. That context explains far more than posting an isolated screenshot.

Follow one packet through NAT

A device uses a private address on the local network and sends traffic to its default gateway. For IPv4, the router commonly replaces that source with its public address and records the translation so replies return to the correct device. Several devices can therefore share one public address while keeping distinct private addresses.

The operating system's network details show the local address and gateway. A public-IP service shows the internet-facing address. If they differ, that is ordinary routing, not evidence of compromise.

Interpret an IPv6 result correctly

IPv6 devices may receive globally routable addresses instead of sharing one translated IPv4 address. Firewall policy still controls unsolicited inbound traffic, and temporary privacy addresses can reduce long-term correlation. “Publicly routable” does not mean every device is automatically reachable.

When troubleshooting, record the address family, subnet, gateway and external result. Redact router screenshots before posting them because the surrounding page may expose Wi-Fi names, device labels, public addresses and administration details together.

For remote access, test reachability from a genuinely external connection. A successful check inside the same network may rely on local DNS or router loopback and does not prove that the public route works.

Sources and further reading