Every device that talks on a network needs an address so others can find it. On the internet, that’s the IP address. Here we explain how IPv4 and IPv6 addresses are built, what a subnet mask does, why your home network uses private addresses, and how IP addresses fit together with the other addresses on a network. Addresses are IP’s part of TCP/IP.
What is an IP address?
An IP address identifies a network connection, not a computer. A laptop with both Wi-Fi and a cable therefore has two, and a server can have many. The address has two parts: a network part, which says which network the connection belongs to, and a host part, which points to the individual connection within that network. The network part is what routers on the internet use to find their way, much like the postal service looks at the zip code first and the house number last.
IPv4 and subnet masks
An IPv4 address is a 32-bit number. To make it readable, it’s written as four numbers between 0 and 255 separated by dots, for example 192.168.1.20. Each of the four numbers stands for 8 bits.
Where the line between the network part and the host part falls isn’t in the address itself. That’s decided by the subnet mask, another 32-bit number in which every bit of the network part is 1 and every bit of the host part is 0. The mask 255.255.255.0 means the first 24 bits are the network. Today it’s usually written more briefly as a suffix after the address, called CIDR notation: 192.168.1.20/24.
An example makes it clear. When a computer needs to work out which network an address belongs to, it lays the address and the mask on top of each other bit by bit and keeps only the bits where the mask is 1:
Address 192.168.1.20 11000000.10101000.00000001.00010100
Mask 255.255.255.0 11111111.11111111.11111111.00000000
Network 192.168.1.0 11000000.10101000.00000001.00000000
So the network is 192.168.1.0/24, and the last 8 bits are for hosts. 8 bits give 256 combinations, but the first (the network’s own address, .0) and the last (the broadcast address, .255) are reserved, which leaves 254 usable addresses. If two devices have addresses in the same network, they can talk directly. If the recipient is on another network, the packet goes to the default gateway instead, usually the router, which passes it on.
This is also how you split a network into smaller parts, which is called subnetting. A /24 can be split into two /25s with 126 hosts each, for example, or you can give an office a /22 with room for just over a thousand devices. The longer the suffix, the smaller the network.
How to split a network
The math behind subnetting is the same every time. A /n suffix leaves 32 minus n bits for the hosts, and the number of usable addresses is 2 to the power of that number minus 2, because the network address and the broadcast address can’t be used by devices. A /26 has 6 host bits, so 64 addresses and 62 usable ones.
To split 192.168.1.0/24 into four equal parts, you borrow 2 bits from the host part, so the suffix becomes /26, and each subnet starts 64 addresses after the previous one:
| Subnet | Network address | Usable addresses | Broadcast |
|---|---|---|---|
| 1 | 192.168.1.0/26 | .1 to .62 | .63 |
| 2 | 192.168.1.64/26 | .65 to .126 | .127 |
| 3 | 192.168.1.128/26 | .129 to .190 | .191 |
| 4 | 192.168.1.192/26 | .193 to .254 | .255 |
You split a network to keep things apart: guest Wi-Fi away from the point-of-sale system, servers away from staff computers, cameras and printers in their own corner. Traffic between the subnets has to pass a router or firewall, where you decide what’s allowed through. The suffixes you’ll meet most often:
| Suffix | Subnet mask | Usable addresses |
|---|---|---|
| /8 | 255.0.0.0 | 16,777,214 |
| /16 | 255.255.0.0 | 65,534 |
| /22 | 255.255.252.0 | 1,022 |
| /24 | 255.255.255.0 | 254 |
| /25 | 255.255.255.128 | 126 |
| /26 | 255.255.255.192 | 62 |
| /27 | 255.255.255.224 | 30 |
| /28 | 255.255.255.240 | 14 |
| /30 | 255.255.255.252 | 2 |
| /32 | 255.255.255.255 | A single address |
A /32 isn’t a network but a way to point at exactly one address, for example when a firewall or an API provider should only let one specific server in.
Private addresses and NAT
32 bits give just over four billion addresses, and that isn’t enough for every device in the world. That’s why three ranges are reserved for private networks and are never sent out on the internet: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Your home network and most office networks use one of them.
When a device with a private address talks to the internet, the router swaps the sender address for its own public address and remembers which internal device the reply should go back to. This is called NAT (Network Address Translation), and it lets a whole network share one public address. The downside is that devices behind NAT can’t easily be reached from outside, which makes things like video calls and games more complicated.
A few other ranges are worth knowing too. 127.0.0.0/8 is the machine itself, and 127.0.0.1 is called localhost. An address in 169.254.0.0/16 means the device didn’t get an address from the network and picked one itself, so it usually can’t reach the internet. And 100.64.0.0/10 is used by internet providers that put many customers behind their own NAT. If your router shows an address from that range as its public one, you’re effectively sharing an address with other customers.
IPv6
IPv6 is the long-term fix for the address shortage. Addresses are 128 bits, which gives so many that there’s no need to economize, and each local network normally gets a whole /64 to itself. They’re written as eight groups of four hexadecimal digits separated by colons, for example 2001:0db8:0000:0000:0000:0000:0000:0001.
To make them manageable, leading zeros can be dropped, and one continuous run of all-zero groups can be replaced by two colons. The address above can therefore be written as 2001:db8::1. Subnet masks are always written as a CIDR suffix. Because there are enough addresses, NAT isn’t needed in the same way, and devices can in principle be reached directly, so the firewall plays a bigger role. IPv4 and IPv6 run side by side, and most devices and servers today have both.
Addressing across the stack
The IP address is only one of several addresses in play when data is sent. On the local network, every network card has a MAC address, which is what Ethernet and Wi-Fi actually deliver to. When a computer wants to send an IP packet to a machine on the same network, or to the router, it uses ARP (in IPv6: Neighbor Discovery) to ask which MAC address belongs to the IP address. The MAC address only applies on the local network and is replaced at every router, while the IP address follows the packet all the way.
Above IP, the port number points to which program on the machine the packet is for. And at the top are the names: people remember mystore.com, not 203.0.113.10, so DNS translates names into IP addresses. Together, the four levels, name, IP address, port and MAC address, provide everything needed to get a message from a program on one machine to the right program on another. How the protocols that use these addresses fit together is covered in our guide to network protocols.
Fixed and changing addresses
Most devices get their address automatically from a DHCP server, usually the router. The address is leased for a period and can change when the lease runs out or the device has been away. That’s fine for computers and phones, but not for anything others need to find: servers, printers and network equipment get a fixed address, either set directly on the device or reserved in the router.
For an online store, it’s the server’s public address that counts. It’s in the domain’s DNS, so if you move hosting, the site gets a new address, and DNS has to be updated. It’s also used by payment, shipping and ERP systems that only accept calls from addresses they know, so a new server address has to be reported to them before the move, or the integrations stop working.
Find your own addresses
- Windows: run
ipconfigin a command prompt. - macOS and Linux: run
ip addrorifconfigin a terminal. - Your public address: visit a service that shows “what is my IP”. If you’re behind NAT, that address belongs to the router, not your computer.
Frequently asked questions
Can two devices have the same IP address?
Not on the same network; that causes a conflict. But the same private address, such as 192.168.1.20, is used in millions of different home networks at the same time without any problem.
Does my IP address change?
Often, yes. Most devices get their address automatically via DHCP, and many internet providers give home customers an address that can change. Servers usually have fixed addresses.