Search

Why IPv4 Ran Out and How NAT Kept the Internet Alive

Why IPv4 Ran Out and How NAT Kept the Internet Alive

The short answer

Quick answer: Every device on the internet needs an IP address. IPv4 addresses are 32 bits long, which allows about 4.3 billion of them, and far fewer are usable once reserved ranges are removed. That seemed endless in 1981. With billions of phones, laptops and servers, it wasn't. The regional registries ran out of fresh addresses in the 2010s. NAT (Network Address Translation) kept things going by letting a whole network of devices share one public address. IPv6, with 128-bit addresses, is the permanent fix, and its adoption is finally passing the halfway mark.

Why IPv4 ran out

An IPv4 address like 203.0.113.10 is four numbers from 0 to 255, which is 32 bits. That gives 2³² = 4,294,967,296 possible addresses. Big chunks are reserved for private networks, multicast, testing and future use, and early allocations were generous: some organisations received blocks of 16 million addresses each.

Addresses flow down a hierarchy. IANA hands large blocks to five Regional Internet Registries (RIRs), which allocate them to ISPs and companies in their region. Exhaustion happened in stages as each pool emptied:

DateEvent
April 2026Google reports that half its users now reach it over IPv6
November 2019RIPE NCC (Europe, Middle East) runs out of IPv4 addresses and moves to a waiting list
September 2015ARIN (North America) exhausts its free pool
September 2012RIPE NCC reaches its last /8 block and starts rationing
April 2011APNIC (Asia-Pacific) reaches its final /8 block
February 2011IANA hands out its last five /8 blocks, one to each RIR
December 1998IPv6 is first specified
February 1996Private address ranges are reserved in RFC 1918
1994NAT is proposed as a short-term fix
1981IPv4 is specified in RFC 791

Today, IPv4 addresses are bought and sold on a secondary market, and cloud providers charge for public IPv4 addresses. The internet didn't stop growing, though. That's thanks almost entirely to NAT.

How NAT works

Diagram: Three home devices sharing one public IPv4 address through NAT

The trick behind NAT is private addresses. RFC 1918 set aside three ranges that are never routed on the public internet, so every home and office can reuse them:

  • 10.0.0.0 to 10.255.255.255
  • 172.16.0.0 to 172.31.255.255
  • 192.168.0.0 to 192.168.255.255

Your router has one public address from your ISP and hands out private ones to your devices. When a device talks to the internet, the router rewrites each packet on the way through. This is usually NAPT (Network Address and Port Translation), which also changes port numbers so many connections can share one address:

  1. Your laptop sends a packet from 192.168.1.10:51000 to a web server.
  2. The router rewrites the source to its public address and a free port, say 203.0.113.7:40001, and records the pair in its translation table.
  3. The server replies to 203.0.113.7:40001. It has no idea your laptop exists.
  4. The router looks up port 40001 in its table, rewrites the destination back to 192.168.1.10:51000, and forwards the reply to your laptop.

Ports are 16-bit numbers, so one public IP can carry tens of thousands of simultaneous connections. TCP and UDP both carry port numbers, which is what makes this possible; see TCP vs UDP for how ports fit in.

NAT works invisibly for most traffic, including every step of loading a web page. Entries expire after a period of inactivity, which is one reason long-lived connections like WebSockets send regular heartbeats.

Carrier-grade NAT: NAT on top of NAT

As addresses ran out, ISPs, especially mobile networks, stopped giving every customer a public IPv4 address at all. Instead they run carrier-grade NAT (CGNAT): your home router gets an address from a shared range reserved for this purpose (100.64.0.0/10, defined in RFC 6598), and the ISP translates again at its edge. Hundreds or thousands of customers can share one public IPv4 address.

You can spot it yourself: if your router's "WAN" address differs from what a "what is my IP" site reports, you're behind CGNAT.

The downsides of NAT

NAT saved IPv4, but it broke one of the internet's original ideas: that any device can reach any other directly.

  • Incoming connections fail by default. The router only knows where to send replies to connections started from inside. To host a game server or camera at home, you need manual port forwarding, which is impossible behind CGNAT.
  • Peer-to-peer gets complicated. Video calls and file sharing use tricks like STUN, TURN and ICE (all part of WebRTC) to punch through NAT, and fall back to relaying traffic through a server when that fails.
  • Shared reputation. Under CGNAT, many strangers share your public IP. If one of them spams or attacks a site, everyone behind that address can get rate-limited or blocked.
  • State and logging costs. The NAT device must track every connection, and ISPs must log port mappings to identify users for abuse or legal requests.
  • Server-side headaches. Load balancers and CDNs that rate-limit by IP address risk treating a whole office or mobile network as one client.

IPv6: the permanent fix

IPv6, specified today in RFC 8200, uses 128-bit addresses like 2001:db8::10. That's 2¹²⁸, roughly 3.4 × 10³⁸ addresses, enough to give every device its own globally unique address with plenty to spare.

IPv4IPv6
Address size32 bits128 bits
Number of addressesAbout 4.3 billionAbout 3.4 × 10³⁸
Example203.0.113.102001:db8::10
NAT needed?Almost alwaysNo; every device can have a public address
Address setupUsually DHCPAutomatic (SLAAC) or DHCPv6
DNS recordAAAAA

Without NAT, security comes from a firewall that blocks unsolicited incoming traffic, which is what home routers do for IPv6 by default.

So why hasn't IPv6 simply replaced IPv4? IPv4 and IPv6 aren't directly compatible, so networks run both side by side (dual stack), and NAT made the pain of IPv4 scarcity tolerable enough that many organisations delayed. Adoption has climbed steadily anyway: in April 2026, Google reported that half of its users now reach it over IPv6. When both are available, your device's DNS lookup asks for both A and AAAA records and usually prefers IPv6.

Frequently asked questions

Has the world actually run out of IPv4 addresses?

The free pools at IANA and the regional registries are essentially empty. Addresses still change hands through transfers and a paid market, and recovered addresses go to waiting lists, but there's no longer an easy supply of new ones.

Is NAT a security feature?

Not by design, though it has a side effect: devices behind NAT can't be reached by unsolicited connections. A proper firewall provides that protection deliberately, and IPv6 networks rely on firewalls instead of NAT.

What is the difference between a public and a private IP address?

A public IP address is unique on the internet and reachable from anywhere. A private address, such as 192.168.1.10, is only meaningful inside a local network and is reused by millions of networks.

How do I know if I'm behind CGNAT?

Compare the WAN address shown in your router's settings with the address a "what is my IP" website reports. If they differ, or the router's address starts with 100.64 to 100.127, there's another layer of NAT at your ISP.

Does IPv6 get rid of NAT?

Mostly, yes. With enough addresses for every device, NAT isn't needed for address sharing. Some networks still use translation to connect IPv6-only devices to IPv4-only services (NAT64).

Conclusion

IPv4's 4.3 billion addresses were never going to cover a world of phones, laptops and cloud servers. NAT bought decades of extra time by hiding whole networks behind one public address, at the cost of direct connectivity and a lot of engineering workarounds. IPv6 removes the scarcity for good, and after a long, slow start, it now carries a large share of real traffic.

Related articles

Sources and further reading

Usama Muneer

Usama Muneer

Coder, Blogger, Tech Speaker & Web Technologies Enthusiast. Passionate about working on open-source Programming languages & Tools while utilizing my Product Development skills.

Your experience on this site will be improved by allowing cookies Cookie Policy