How Subnetting Works: Static IPs and NAT Type Explained
Subnetting defines the local address plan: which IPs belong to the same LAN, which address is the gateway, and which ranges can be handed out by DHCP. A static IP is only safe when it fits that plan and does not overlap with an active lease or another reserved device.
That local setup is separate from NAT behavior on the way to the internet. A device can have a perfectly valid static LAN address and still sit behind single NAT, double NAT, or carrier-grade NAT. The practical order is to calculate the subnet, pick a conflict-free local address, enter the full network settings, and then check what NAT path exists beyond the gateway.
How subnetting works: calculate the local subnet
Work through one subnet example
Subnetting uses the prefix length to split an IP address into a network part and a host part. The prefix also tells devices how big the local LAN is and when traffic should go to the default gateway instead of staying on the same subnet.
Example: a small office uses 192.168.50.0/26. The /26 prefix leaves 6 host bits, so each subnet contains 64 total addresses. The subnet mask is 255.255.255.192. In the last octet, the block size is 256 – 192 = 64, so the subnets start at 0, 64, 128, and 192.
For the first block, the address plan is:
- Network ID: 192.168.50.0
- Usable host range: 192.168.50.1 to 192.168.50.62
- Broadcast address: 192.168.50.63
- Default gateway: usually 192.168.50.1
If the router’s DHCP scope is set to 192.168.50.20-192.168.50.50, that means the router may automatically lease those addresses to clients. A static address should either sit outside that leased range or be protected by a reservation so DHCP never hands it to a different device.
Find the usable range, network ID, and broadcast address
The network ID is the first address in the subnet and is not assigned to a device. The broadcast address is the last address in the subnet and is also not assigned to a device. Everything between those two values is potentially usable, but only if the address is not already taken by the gateway, a DHCP lease, or a reservation.
A quick way to verify the range is to compare the device IP with the prefix:
- If the prefix is /24, the subnet mask is usually 255.255.255.0 and the host range is one full last octet, such as 192.168.1.1-192.168.1.254.
- If the prefix is /26, the range is smaller and the blocks move in steps of 64.
That distinction matters because a static IP must match the subnet mask. A device on 192.168.50.10 with a /26 mask belongs to the 192.168.50.0 subnet, but the same IP with a different mask could point it at the wrong local network and break access to the gateway or nearby devices.
How to make an IP static safely
Check the DHCP scope first
Before assigning a static address, check the router’s DHCP pool, current leases, and any saved reservations. The goal is to avoid duplicate addresses, which can cause intermittent drops, failed logins, or a device that works only until another client receives the same IP.
There are two safe approaches:
- Use a DHCP reservation: the router always gives the same IP to a device’s MAC address. This keeps the device on automatic addressing while still making the IP stable.
- Pick a manual static IP outside the DHCP pool: choose an address inside the subnet, but outside the leased range, and not equal to the gateway, network ID, or broadcast address.
In the example subnet, if DHCP leases 192.168.50.20-192.168.50.50, then 192.168.50.10 is a reasonable manual choice as long as no reservation or other device already uses it. A printer or media server often works better with a reservation, because the router can police the address and prevent conflicts.
Prevent duplicate addresses with a reservation or by staying outside the pool
Duplicate prevention is more than choosing a number that looks unused. A router may still hand that IP to another client later unless the address is protected. Reservations solve this cleanly because the router binds one IP to one MAC address in its lease table.
If manual static addressing is preferred, the chosen IP should be documented and kept out of the DHCP pool. That usually means recording the device name, MAC address, IP, mask, gateway, and DNS in the router admin page or a simple network list. On a busy LAN, that record is the difference between a stable setup and a hard-to-diagnose conflict months later.
Configure the address, mask, gateway, and DNS
What each field means
When a device is set to static IPv4, four fields matter most:
- IP address: the unique local address for the device.
- Subnet mask: defines which addresses are local to the device.
- Default gateway: the router address used for traffic outside the subnet.
- DNS servers: resolve names such as example.com into IP addresses.
The gateway is not the same as DNS. The gateway forwards traffic to other networks. DNS translates names. Many home routers can act as DNS forwarders, so entering the router address as DNS is often enough. Public DNS options such as Cloudflare 1.1.1.1 or Google Public DNS 8.8.8.8 can also be used if the network allows them.
For the example subnet, a safe static configuration could be:
- IP: 192.168.50.10
- Mask: 255.255.255.192
- Gateway: 192.168.50.1
- DNS: 192.168.50.1, 1.1.1.1
If the router uses a different gateway, that value must match the actual LAN interface on the router. A wrong gateway can still let the device talk to local neighbors but block internet access.
Enter the values on the device or router
On most devices, the path is to open IPv4 settings, switch from automatic to manual, and enter the four values above. After saving, the device should reconnect and receive the same local address every time it comes online.
On some networks, a router reservation is preferable to manual static entry on the device. That is especially true for laptops, consoles, or phones that move between networks. A reservation gives the same practical result on the local LAN without requiring the user to edit settings on every device.
After the change, confirm three things: the device can reach the gateway, it can reach another host on the same subnet, and it can resolve a domain name. If local access works but name lookup fails, the DNS field is wrong. If DNS works but internet access fails, the gateway or upstream path is the likely problem.
Check NAT type beyond the local network
Direct, double, and carrier-grade NAT
NAT type is about the path between the router and the wider internet, not about whether a device has a static LAN address. A static local IP changes only the device’s identity inside the subnet. It does not remove an upstream NAT layer or by itself produce a public IP.
The three most useful cases are:
- Direct or single NAT: the router has a public WAN address and translates traffic once. This is the cleanest setup for inbound access, gaming, and remote services.
- Double NAT: one router sits behind another NAT device, such as an ISP modem-router plus a personal router. The outer and inner routers both translate traffic, which can complicate port forwarding and peer-to-peer connections.
- Carrier-grade NAT (CGNAT): the ISP shares one public IPv4 address across many customers. The router’s WAN address is usually private or in the 100.64.0.0/10 shared range, and inbound connections are often blocked unless the ISP offers a workaround.
Evidence is usually easy to spot. If the router’s WAN IP matches the public IP shown by an external lookup, the connection is probably direct or single NAT. If the WAN IP is in 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16, there is usually another NAT device upstream. If the WAN address is in 100.64.0.0/10, CGNAT is likely.
Which NAT type is best for gaming and remote access?
The best NAT type is the one with the least translation between the device and the internet: a direct public connection or a single well-configured NAT layer. That setup gives the best chance of stable voice chat, matchmaking, and remote access. Double NAT and CGNAT are less favorable because they make inbound connections harder and can break port forwarding entirely.
For gaming consoles and similar devices, the practical target is usually an open or moderate result rather than a strict one, but the exact labels vary by platform. The useful test is still the same: if the router has a public WAN address and only one NAT device exists, the NAT path is usually healthy. If the WAN address is private or shared, the NAT issue is upstream and changing the local IP will not fix it.
When the WAN shows a private address, the fix is to remove the extra router, place the ISP gateway into bridge mode if available, or ask the ISP whether a public IPv4 address can be assigned. For CGNAT, the deciding factor is the provider’s network, not the device’s LAN configuration.