Distinguishing local addresses from public internet addresses is the first step when preparing inventory and investigating routing problems. Not every address starting with 172 is private.

Basic approach

RFC 1918 defines three IPv4 blocks: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. These can be reused in different organizations. Therefore, simply seeing the address 192.168.1.20 does not tell you which office the device is in; The network to which the address belongs should also be recorded.

Application steps

  1. Check if the address falls into one of three private address blocks.
  2. Separate networks that use the same address by adding location, VLAN, or network name to the inventory.
  3. When accessing via VPN, examine whether the address ranges on both sides overlap.

Practical example

If home and office networks use 192.168.1.0/24, the VPN client may search for some targets locally. Compare the route table and VPN policy without confusing the issue with the device being turned off.

Interpret the result correctly

Using a private address alone does not provide security. Access rules are also evaluated. 172.15.1.1 and 172.32.1.1 are not covered by RFC 1918; 100.64.0.0/10 is a different shared address block.

Source and follow-up reading

Protocol or command details: RFC 1918. The steps and example scenario are IPScans editorial narrative.