Skip to content
Skip to main content
IP Addresses & Networks Operational question
Pathway: I have been given an IP address

The record contains several IP addresses - which one matters?

The relevant IP address is not necessarily the first one in the record - or even the one labelled source. It is the address that answers your investigative question when interpreted from the position of the system that recorded it.

Begin with the observation point

Before selecting an address, establish:

  • which system created the record;
  • where that system sat in the communication path;
  • what each field is called;
  • whether a router, proxy, VPN, load balancer or other intermediary was involved; and
  • whether any network address translation took place.

Without that context, a technically valid address can still lead to the wrong enquiry.

Common fields and what they may mean

Field or address type What it may describe Main caution
Source IP Where traffic appeared to come from at that observation point It may belong to an intermediary rather than the originating connection
Destination IP The system or service being contacted Resolving it may identify the service, not the customer who connected to it
Client IP or remote address The connecting system as understood by the application or server Its meaning depends on the product and configuration
X-Forwarded-For or similar An earlier address reported through a proxy chain Trust it only when you understand which trusted system created or validated the value
Private IPv4 address A device or interface inside a local network Private ranges are reused and cannot normally identify an internet subscriber
Public address The internet-facing connection visible outside a local network Several devices - or customers - may share it
Original or pre-NAT address An address before translation You still need the matching translation record and time context
Translated or post-NAT address The address after translation It may identify shared infrastructure rather than one device or customer

Field names are clues, not conclusions. Different products can use the same label differently.

A short worked example

Imagine a firewall record containing:

  • internal source: 10.14.8.23;
  • translated source: 203.0.113.70; and
  • destination: 198.51.100.25.

If the question is which local device initiated the traffic?, 10.14.8.23 may be relevant, together with local DHCP, authentication or device records.

If the question is which public connection contacted the external service?, 203.0.113.70 may be relevant, together with the timestamp, time zone, port and translation records.

If the question is which service was contacted?, 198.51.100.25 may be the relevant starting point.

The three addresses describe different parts of the same event. None of them identifies a person by itself.

Checks before using an address

  1. State the fact you are trying to establish.
  2. Preserve the complete record, not just the address copied from it.
  3. Record the timestamp, time zone, port, protocol and relevant account or session identifiers.
  4. Confirm the meaning of the field with the system owner or reliable product documentation.
  5. Identify any translation or intermediary and preserve the records needed to follow it.
  6. Match the conclusion to what the address can actually show.

Evidential limits

A correctly interpreted address may identify a network, connection or point in a communication path. It does not automatically identify the originating device, the individual using it or the person responsible for the activity.

Operational takeaway

Choose the address that answers the investigative question, then explain the observation point, field meaning and any intermediary or translation that affects it.

Reference: IP-032IP Addresses & Networks