Subnet masking explained: Calculate the Local Range and NAT Type

Subnet masking explained: an IPv4 address and its mask identify which devices share a local network and which destinations must be reached through a gateway. Calculate that local range first. Then compare the device address, gateway, router WAN address, public IP, upstream equipment, and application test results to determine how NAT translates traffic beyond the subnet.

For example, a device using 192.168.10.34/24 belongs to the local range 192.168.10.0 through 192.168.10.255. That calculation describes the LAN only; it does not reveal whether the router has a public address, sits behind another router, or is behind carrier-grade NAT.

Subnet masking explained: Calculate the local IPv4 range

Worked example: 192.168.10.34/24

The /24 suffix is CIDR notation for the subnet mask 255.255.255.0. The first 24 bits identify the network, and the remaining eight bits identify hosts inside it.

  • IP address: 192.168.10.34
  • Subnet mask: 255.255.255.0
  • Network address: 192.168.10.0
  • Broadcast address: 192.168.10.255
  • Usable host range: 192.168.10.1 through 192.168.10.254
  • Total addresses: 256, including the network and broadcast addresses
  • Usable addresses: 254 in the usual /24 configuration

The calculation comes from setting all host bits to zero for the network address and all host bits to one for the broadcast address. A device at 192.168.10.34 therefore treats another device such as 192.168.10.80 as local. It sends traffic for a destination such as 8.8.8.8 to its default gateway instead.

A common gateway for this example is 192.168.10.1, although a gateway can use any usable address in the same range. The gateway must normally be reachable through the local subnet. If the device has a /24 mask but the gateway is 192.168.11.1, the device sees that gateway as outside its local network and may be unable to reach it without an unusual route or configuration.

The prefix length can produce smaller or larger ranges. A /26 uses 255.255.255.192 and creates blocks of 64 addresses, while a /16 uses 255.255.0.0 and provides 65,536 addresses before network and broadcast reservations. The mask controls local address boundaries and routing decisions; it does not assign a public IP address or select a NAT policy.

Private ranges: 10/8, 172.16/12, and 192.168/16

Local networks commonly use IPv4 addresses from three private ranges. These addresses are not routed directly across the public internet and are normally translated by a router or firewall.

  • 10/8: 10.0.0.0 through 10.255.255.255
  • 172.16/12: 172.16.0.0 through 172.31.255.255
  • 192.168/16: 192.168.0.0 through 192.168.255.255

The suffix is important. For instance, 172.20.5.10 is private, but 172.40.5.10 is not part of the private 172.16/12 block. Similarly, every 192.168 address is private, while nearby ranges such as 192.0.2.0/24 are reserved for documentation rather than normal home networks.

Seeing a private address on a computer is expected. The diagnostic question is what address appears on the router’s internet-facing interface and what address an external service sees after traffic leaves the LAN.

Class B addresses: Classful labels versus CIDR

What Class B meant in classful IPv4

The original classful IPv4 system divided addresses by their first bits and assigned a default mask to each class. Class A covered first-octet values from 1 through 126 with a default /8 mask. Class B covered 128 through 191 with a default /16 mask. Class C covered 192 through 223 with a default /24 mask.

Under that older model, a Class B network used the first two octets for the network portion and the last two octets for hosts. A notional Class B network such as 150.20.0.0/16 could contain addresses from 150.20.0.0 through 150.20.255.255, subject to the usual network and broadcast reservations.

The label class b addresses still appears in older router documentation, certification material, and address-planning guides. It describes the historical default boundary, not necessarily the mask currently configured on a network.

Why CIDR matters more today

Classless Inter-Domain Routing, or CIDR, replaced the rigid class boundaries for practical network design. A network can now use /13, /20, /27, or another prefix length based on its actual size. The first octet alone no longer determines the network boundary.

The private range 172.16.0.0/12 illustrates the difference. It occupies the address space from 172.16.0.0 through 172.31.255.255, which historically falls within the broad Class B first-octet range. In CIDR terms, however, it is a /12 block containing sixteen /16-sized sections. Calling it a “Class B network” can therefore obscure the actual mask.

For troubleshooting, the configured prefix length is more useful than the class label. Record the IP address and mask together, calculate the network and usable range, and then check whether the gateway belongs to that range.

NAT sits beyond the subnet: Follow the translation path

Trace the local IP, gateway, public IP, and upstream device

Network Address Translation normally occurs at the gateway or firewall after a local device sends traffic outside its subnet. A typical path looks like this:

  1. Local device: A computer, console, or phone uses a private address such as 192.168.10.34 and an ephemeral source port.
  2. LAN gateway: The device sends the packet to 192.168.10.1 because the destination is outside 192.168.10.0/24.
  3. NAT router: The router changes the private source address and port to its WAN address and a translated port, then records that connection in a state table.
  4. ISP network: The translated packet travels toward the public internet.
  5. Remote service: A website, game service, or peer sees the public source address and translated port rather than 192.168.10.34.

Suppose the router’s LAN address is 192.168.10.1, its WAN address is 198.51.100.27, and an external IP-checking service also reports 198.51.100.27. That evidence is consistent with one customer-side NAT layer and a public IPv4 address on the router. The addresses above are documentation examples; an actual public address will differ.

If the router’s WAN address is 192.168.1.20, 10.12.4.8, or an address from 172.16.0.0 through 172.31.255.255, the router is receiving private space from another device. That upstream device may be an ISP modem-router, mesh gateway, firewall, or hotspot. The downstream router is then behind another translation layer, a condition commonly called double NAT.

A WAN address in 100.64.0.0 through 100.127.255.255 is different. That 100.64.0.0/10 block is shared address space commonly used by internet providers for carrier-grade NAT, or CGNAT. The provider translates many customers through a smaller pool of public addresses. An external IP service will show the provider’s public address rather than the router’s WAN address.

To trace the path accurately, compare the router’s WAN address with the public address reported by an external service using the same IP version. If they match, the router may have the public IPv4 endpoint. If they differ, inspect the device upstream of the router and repeat the comparison. A public website may report IPv6 while an application test uses IPv4, so those results should not be compared as though they describe the same path.

Why the subnet mask does not control upstream NAT

The subnet mask answers a local routing question: should the device deliver traffic directly on the LAN, or send it to the gateway? NAT answers a different question: how should the gateway or provider represent that traffic outside the local network?

Changing 192.168.10.34/24 to another mask can alter the perceived local range, cause address conflicts, or prevent the device from reaching its gateway. It does not give the router a public WAN address, remove an upstream router, or bypass CGNAT. A subnet change can fix an incorrect local configuration, but upstream NAT must be diagnosed and changed at the gateway, upstream device, or ISP level.

What’s my NAT type? Check and interpret the evidence

Use application test evidence to classify the result

To answer the practical question what’s my nat type, collect evidence in this order:

  1. Record the local configuration. On the device’s network details, note the IPv4 address, subnet mask or prefix length, and default gateway. Confirm that the gateway falls inside the calculated local range.
  2. Check the router’s WAN or internet status. Record its IPv4 address. Do not use the LAN address shown for the router; the relevant value is the address on its internet-facing interface.
  3. Check the observed public IP. Use a reputable external IP display or the service’s own connection diagnostic. Compare its IPv4 result with the router WAN address.
  4. Identify upstream equipment. If the WAN address is private or in 100.64.0.0/10, locate the modem, second router, mesh controller, firewall, or provider-managed gateway above the current router. Check its status page for another WAN address.
  5. Run the application test. Use the game, console, voice application, or peer-to-peer service that is showing the NAT status. Record whether it reports open, restricted, moderate, strict, or another vendor-specific label.

Application tests are important because a public IP comparison alone does not prove that unsolicited inbound connections can reach an application. The test may check port mapping, peer discovery, relay use, or whether a connection can be initiated from outside. A generic port checker also cannot prove a port is usable when no application is listening or when the service requires a particular protocol.

Open, restricted, double, or carrier-grade NAT

  • Open NAT: The application can establish the required inbound and outbound peer connections. This commonly occurs when the gateway has a public IPv4 address and uses an automatic mapping, such as UPnP, or a correctly configured manual port forward. “Open” does not mean that every port is exposed or that the firewall is absent; it describes the tested application’s connectivity.
  • Restricted NAT: Outbound connections work, but unsolicited inbound traffic is blocked or allowed only from peers with which the device has already communicated. Applications may call this restricted, moderate, or strict NAT. The exact label and test criteria vary by vendor.
  • Double NAT: The local router’s WAN address belongs to a private range, and another router performs an additional translation upstream. The application may report restricted or strict NAT because a port mapping must pass through both devices. The router and upstream gateway must be checked separately; changing only the local subnet mask will not remove the second translation.
  • Carrier-grade NAT: The router may show a 100.64.0.0/10 WAN address, while an external service shows a different public IPv4 address. The ISP performs the translation for multiple customers. Conventional inbound port forwarding usually cannot be completed from the customer router alone, so applications often report restricted or strict NAT.

These categories can overlap. A home router behind CGNAT is both behind an ISP translation layer and potentially behind its own local NAT. Likewise, double NAT is a network arrangement, while open or restricted NAT is an application’s observed result. The most reliable diagnosis comes from matching all four pieces of evidence: the local subnet and gateway, the router WAN address, the externally observed public IP, and the application’s actual connection test.