Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

An IP address usually answers two questions at once: which endpoint is involved, and where that endpoint is attached to the network. Because one value does both jobs, a changed address can look like a changed device, and a device’s address can look like its permanent identity. Separating the two roles explains how mobility and multihoming work, why privacy is harder than it looks, and why names, IP addresses and MAC addresses are not interchangeable.

Identity and location answer different questions

Identity asks which thing is being referred to. Location asks where traffic has to go so that it reaches that thing. Both questions matter in every network, but ordinary IP addressing answers them with the same number, so the distinction is easy to miss.

Identity

An identity is a name or identifier that distinguishes a node, endpoint, interface, user or device for a stated purpose. The first step is always to say what is being identified. A node is not the same thing as one of its interfaces, and a network access identifier can identify a user inside a particular domain without identifying a machine at all.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Location, or locator

In networking, “location” means a position in the network topology, not geographic coordinates. A locator is a value that indicates a network attachment or subnet and can be used to route or forward packets toward it. An IP address that lets routers pick the next hop is doing locator work.

Address

An address is a value whose meaning depends on the protocol and the layer. In conventional IP, an address takes part in network-layer delivery, and endpoint protocols or applications may also treat the same value as the identity of a host. It should not be reduced to only one role.

Name

A name is a higher-level label, such as a DNS domain name, that resolves to one or more current network addresses. A stable name can hide changes in the underlying address, provided the DNS mapping is updated.

Following one connection through the layers

The clearest way to see the separation is to follow a request for a server called example.net from start to finish. The domain name is what a person or application keeps. The network addresses are what the network uses at each hop.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. The client asks DNS for the name example.net. The answer is a currently usable IP address. The name is the identity the user recognises; the address is only a current locator.
  2. The client sends IP packets addressed to that address. Routers use network-layer addressing to move each packet toward the network that holds the server.
  3. On each local link, frames are delivered to the next hop using link-layer addresses. The MAC address names an interface on that link, not the server as a whole.
  4. If the server moves to another network and its address changes, the DNS record is updated. Clients that re-resolve the name reach the server at its new locator. Clients holding a cached answer keep using the old address until the cache expires, which depends on the record’s time-to-live value.

Source for the addressing concepts: Apple Developer Documentation, Addressing Schemes and Domain Names. That page is an archived explanatory reference, not a guide to a current operating system.

IP and MAC addresses: where the boundaries lie

An IP address is used at the IP layer and can be IPv4 or IPv6. A MAC address is a link-layer address tied to a network interface and used for local delivery. A host with several interfaces, such as a wired and a wireless adapter, has a separate link-layer address for each one.

Value Layer or role Scope Says where it is attached? Stable identity for a device?
DNS name (FQDN) Application-facing label Global namespace No, it resolves to addresses Stable as a label, but it names a service or host, not a physical machine
IP address (IPv4 or IPv6) Network layer Routing domain or global routing Yes, it reflects the attachment and subnet Not automatically; it can change and can be shared behind NAT
MAC address Link layer, per interface Local link or administrative domain Only on the local link Tied to an interface; not a universal identity for the whole device

Why one interface address is not a device identity

RFC 6155 states that a MAC address is appropriate for the device using the interface as long as the two stay together. It also notes that locally assigned MAC addresses are not guaranteed unique outside their administrative domain. Treating a MAC address as the permanent name of a computer therefore overstates what the value guarantees. The same RFC discusses location services that must use more than an IP address. Behind NAT, several devices can share one externally visible address, so a location service may need port or flow context and knowledge of the NAT mapping to tell an internal device apart. An IP address alone is not a durable, globally unique device identity. (RFC 6155)

Why separate identity from location?

If the identity of an endpoint is kept stable while its locator is updated, a node can change where it attaches to the network without every higher layer treating it as a new node. That is the core motivation for mobility and multihoming designs. The separation is a design choice, not a description of ordinary IP connections, which combine both roles in one address.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identifier/locator separation in ILNP

RFC 6740 describes the Identifier-Locator Network Protocol (ILNP), an architecture that gives each role its own value. It defines an identifier as “a non-topological name for uniquely identifying a node” and a locator as “a topologically bound name for an IP subnetwork” (RFC 6740, section 2.1). Its layered view places the values as follows:

Layer in the ILNP model Value named in RFC 6740 Question it answers
Application Fully qualified domain name (FQDN) Which service or host name is wanted?
Transport Identifier Which node is this session for?
Network Locator Where in the topology is that node attached?
Physical interface MAC address Which interface is delivering the frame locally?

RFC 6740 is labelled Experimental. Present ILNP as an architectural model that makes the roles explicit, not as a claim that everyday Internet connections already use a pure split. (RFC 6740)

Host Identity Protocol: a cryptographic identity

RFC 9063 explains that conventional IP addresses carry a dual locator and endpoint-identifier role. The Host Identity Protocol (HIP) takes a different route. Its Host Identity is a cryptographic identity based on a public key, and the holder of the matching private key proves that identity. The identity is therefore not derived from where the host is attached. (RFC 9063)

What the separation does and does not promise

The architectural benefit is that the identity can stay constant while the locator changes. It does not mean that an ordinary IP session survives an address change. Surviving that change needs a mechanism designed for it, such as the ones these architectures describe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Privacy: stable values make correlation easy

Stable identifiers make activity easier to link together. RFC 8981 explains that changing an IPv6 interface identifier reduces some of that correlation. A stable network prefix can still group activity by network, and a DNS name can remain a recognisable identifier. Temporary addressing therefore limits some exposure. It does not make a user anonymous, and it does not hide the network the device is attached to. (RFC 8981)

Key points to keep

  • Identity and location are different functions, even when one IP address value serves both.
  • Conventional IP addresses combine the locator and endpoint-identifier roles, and how they behave depends on the protocol layer and the application.
  • DNS names can stay stable while the address records behind them change.
  • MAC addresses belong to interfaces on a local link. They are not universal identities for an entire device.
  • NAT, temporary addressing and multiple interfaces make claims of a single permanent, unique address unreliable.
  • Identifier/locator separation is an architectural approach, and the RFCs above describe it as such. It is not a description of every deployed IP network.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.