TOPIC #4Beginner 7 min read

IP Addressing (IPv4/IPv6, Public vs Private)

CSD
CompleteSystemDesign Editorial
Report an issue
Key takeawayCore Architecture Summary

Explore numerical addressing schemes, subnetting (CIDR), NAT (Network Address Translation), and why private VPCs shield internal architectures.

Key Glossary Concepts in this TopicAll Glossary Terms
Interactive Lab · 🧮 IP & CIDR Subnet CalculatorFull lab guide

IP Addressing & CIDR Subnet Bench

Mask a real address with bitwise AND, size any /prefix, and see why private VPC subnets need NAT.

Address space comparison

IPv4 is 32-bit: ~4.3×10⁹ addresses (your /24 holds 8 host bits). IPv6 is 128-bit: 3.4×10³⁸ addresses — enough to end NAT forever.

10.0.1.47 is PRIVATE (RFC 1918, block 10.0.0.0/8) — never routable on the Internet; outbound traffic is masqueraded behind the NAT Gateway public IP, and no inbound connection can reach it directly.
Bitwise subnet computation
address  = 10.0.1.47 = 00001010 00000000 00000001 00101111
mask    = 255.255.255.0 = 11111111 11111111 11111111 00000000
AND → network = 10.0.1.0
Total addresses: 256Usable hosts: 251First usable: 10.0.1.4Last usable: 10.0.1.254Broadcast: 10.0.1.255AWS reserves: network+2112 (router), .2 DNS, .3 future, broadcast
Architecture rule: place ALBs and NAT Gateways in public subnets (e.g. 10.0.1.0/24), keep app servers, Redis, and databases in private subnets (10.0.2.0/24) with no route to an Internet Gateway — blocking 100% of direct internet-borne attacks against your data tier.

Public Internet vs Private VPC Subnet 🛡️

How NAT Gateways allow private instances to access the internet without exposing their private IP addresses.

Public Internet vs Private VPC Subnet 🛡️
100%
Touchpad: Pinch to zoom • Drag to pan
Rendering visual architecture flowchart...

01.IPv4 vs IPv6 Fundamentals

  • IPv4: 32-bit address space yielding ≈ 4.3 × 10^9 unique addresses (e.g. 192.0.2.1). Addresses are virtually exhausted worldwide.
  • IPv6: 128-bit address space yielding 3.4 × 10^{38} addresses (e.g. 2001:0db8:85a3:0000:0000:8a2e:0370:7334), eliminating address scarcity and reducing the need for NAT.

02.Public vs Private IP Spaces (RFC 1918)

Private IP ranges are reserved strictly for local networks and VPCs and are never routable over the public internet:

  • 10.0.0.0 to 10.255.255.255 (10.0.0.0/8)
  • 172.16.0.0 to 172.31.255.255 (172.16.0.0/12)
  • 192.168.0.0 to 192.168.255.255 (192.168.0.0/16)

03.CIDR Notation & Subnet Calculations

Classless Inter-Domain Routing (CIDR) defines network masks. A /24 prefix leaves 32 - 24 = 8 host bits, creating 2^8 = 256 IPs (with 5 IPs typically reserved by cloud providers like AWS).

bash— Subnet breakdown for 10.0.1.0/24
# Network Address: 10.0.1.0
# Usable Range:    10.0.1.4 - 10.0.1.254 (in AWS VPC)
# Broadcast IP:    10.0.1.255
# Total addresses: 256

Architectural Trade-offs & Production Realities

Architectural Advantages

  • Private subnets block 100% of direct internet-borne attacks against databases

Trade-offs & Constraints

  • Requires NAT gateways and bastion hosts for egress/maintenance
Production Implementation in Big Tech
Amazon Web Services (AWS)• VPC Isolation

RDS databases are placed in isolated database subnets with no route table entry to an Internet Gateway, accessible solely via security groups linked to application compute clusters.

Staff+ Engineering Takeaways

  • IPv4 is 32-bit; IPv6 is 128-bit.
  • RFC 1918 private IPs (10.x.x.x, 192.168.x.x) are never routed on the public internet.
  • Keep internal data stores in private subnets behind security groups.

Topic Knowledge Check

Exercise 1 of 1 • Test your architectural comprehension.

Exercise 1 of 10 answered
1

How many total IP addresses are contained in a /28 CIDR block?

Rate This Architecture ChapterFeedback & Rating

How clear and actionable was this distributed systems breakdown?

Interactive Engineering Workbenches: