Private IP address

An IPv4 address from the ranges RFC 1918 reserves for internal networks: usable by any organisation, and not routed on the public internet.

A private IP address is one taken from address space reserved for use inside private networks. RFC 1918 sets aside three IPv4 blocks for the purpose: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Any organisation may use them without registration, so the same addresses recur in countless networks and are not routed on the public internet. A host with a private address reaches the internet through NAT or PAT at the network edge. The IPv6 counterpart is the unique local address range defined in RFC 4193.

Private addressing is easily confused with two neighbours. An APIPA address, from the 169.254.0.0/16 link-local range, is assigned automatically when a host cannot reach a DHCP server, and usually signals a fault rather than a design choice. A private address is also not a security control: anything that can reach the internal network can still reach the host. It does have a defensive use at the edge. Packets arriving from the internet with a private source address cannot legitimately have come from there, so ingress filtering drops them as spoofed.

Exam relevance: a scenario may give an address and ask whether it is internet-routable, or ask why an inbound packet with a private source address should be dropped. Candidates are expected to recognise the RFC 1918 ranges and their role in anti-spoofing filters.