Routelearn.net
Course menu

NAT

How a whole office of private addresses reaches the internet through one router. Learn static NAT, dynamic NAT and PAT, and how to check the translation table on a Cisco router.

Intermediate · 6 lessons + lab and test · Before this: IP Addressing, Routing

NAT (Network Address Translation) is a router function that rewrites the IP addresses in packet headers as packets pass between two networks, most often swapping private inside addresses for public ones. The router records each mapping in a translation table so that return traffic can be translated back.

In simple terms: Your office uses private addresses that the internet can't route. NAT lets the router swap them for a public address on the way out and swap them back on the way in.

Your home router has one public IP address, yet every phone, laptop and TV in the house can use the internet at the same time. The trick is NAT (Network Address Translation): the router rewrites private addresses into its public address on the way out, and back again on the way in. This course explains how that works and how to set it up on a Cisco router.

Every lesson uses the same small office below. The PCs and the web server Web1 use private addresses in 192.168.10.0/24. R1 is the edge router: Gi0/0 faces the office (inside), and Gi0/1 faces the ISP (outside) with the public address 203.0.113.2/30. The server on the internet is 198.51.100.10.

Gi0/0 · insideGi0/1 · outsidePC1192.168.10.11PC2192.168.10.12Web1192.168.10.50SW1NATR1 (NAT)edge routerISP203.0.113.1InternetServer198.51.100.10
  1. 1. PC1 sends a request. Its source address is private. The internet can't route it.
  2. 2. R1 translates it. The packet leaves with R1's public address, and R1 writes the swap in its translation table.
  3. 3. The reply comes back. R1 finds the entry, puts PC1's private address back, and forwards the reply inside.

What you'll learn

Why NAT exists

Private addresses can't cross the internet. NAT swaps them for public ones at the edge router.

Speak the language

Inside local, inside global, outside local and outside global, explained with one picture.

Three kinds of NAT

Static NAT for servers, dynamic NAT from a pool, and PAT so a whole office shares one address.

Prove it works

Read the translation table and statistics, and track down the faults that break NAT.

Skills you'll gain

  • Private vs. public IPv4
  • NAT terminology
  • Static NAT
  • Dynamic NAT
  • PAT / overload
  • show ip nat translations
  • NAT troubleshooting

Who is this for?

CCNA students and anyone who wants to know what their router does with addresses. You should know what an IP address and a subnet are (see IP Addressing), and roughly how a router forwards packets.

Start the first lesson →

FAQ

Why can't someone outside my network connect directly to my laptop?
With PAT, the router only creates a translation entry when your device sends traffic out first. A device on the internet can't start a new connection inward, because the router has no entry telling it where to send it. The exception is port forwarding (static NAT or static PAT), which you set up on purpose for a server.
Is NAT the same thing as a firewall?
No. NAT changes addresses; a firewall decides what is allowed. Because PAT drops unexpected inbound traffic, it can feel like a firewall, but it was never designed for security. Use a real firewall or access lists to protect a network.
Does IPv6 use NAT?
Normally not, and that is on purpose. IPv6 has so many addresses that every device can have its own public address. That removes the shortage NAT was built to work around in IPv4.