Public IP vs private IP addresses.
A public address can be reached from anywhere. A private one only works inside your office. What that means for remote access and hosting.
A public IP address is unique across the whole internet, so a device that has one can be reached from anywhere. A private IP address is only unique inside one network, such as your office, and the same numbers are reused in other offices and homes everywhere.
The private ranges
Three blocks of addresses are set aside for private use by an internet standard known as RFC 1918:
- 10.0.0.0 to 10.255.255.255
- 172.16.0.0 to 172.31.255.255
- 192.168.0.0 to 192.168.255.255
Anyone may use these inside their own network without asking a registry or an internet provider. In return, they mean nothing outside it. Internet providers are expected to filter them out, so traffic addressed to a private number does not travel across the internet. If the office printer is 192.168.1.20, that is a private address.
Public addresses are the opposite. They come from a registry by way of your internet provider, and no two networks share one. IPv6 has its own local kind, called unique local addresses, which are meant for use inside a site and are not expected to be routed on the internet.
How private devices reach the internet
The answer is network address translation (NAT), which is usually done by the router or firewall. When a computer in the office opens a website, the router replaces the computer’s private address with the office’s public address before the request leaves. When the reply comes back, the router works out which computer asked and passes it on. From outside, the whole office looks like a single public address, and the addresses inside stay hidden.
Why it matters for remote access
Because a private address only works inside the office, a person at home cannot connect to the office computer at 192.168.1.20. That address means a different device, or nothing, on their home network. Something at the edge of the office network has to let them in.
The usual answer is a business VPN, which places the remote laptop on the office network over an encrypted connection. The other way is to set the router to pass outside connections straight through to one inside device. That puts the device in front of the whole internet. The Australian Signals Directorate’s advice for equipment at the edge of a network is to turn off any internet connection that is not needed and to keep what remains patched.
Private ranges can also collide. Two offices that both use 192.168.1.x work fine apart. Join them into one network and some addresses are no longer unique, so one side has to be renumbered. Plan the ranges before linking sites.
Why it matters for hosting from the office
A server that customers or staff reach from outside, such as a web server, a camera recorder or a phone system, needs a public address that leads to it, and usually a DNS record that points a name at that address. Ask your internet provider whether the office’s public address is fixed. If it can change, the name will stop finding the server.
Everything hosted this way is one more thing exposed to the internet that has to be kept up to date. That is one reason many businesses keep public services with a hosting or cloud provider and leave the office network private. When the cloud is the right choice, and when it isn’t covers that decision, and our network services team can map what your office exposes today.
Sources
- RFC 1918: Address allocation for private internets (IETF) rfc-editor.org
- RFC 4193: Unique local IPv6 unicast addresses (IETF) rfc-editor.org
- Network address translation: glossary (NIST) csrc.nist.gov
- Number resources (IANA) iana.org
- Security considerations for edge devices (Australian Signals Directorate) cyber.gov.au