Your home router has one public IP address, yet every phone, laptop and TV in the house can use the internet at the same time. The trick is NAT (Network Address Translation): the router rewrites private addresses into its public address on the way out, and back again on the way in. This course explains how that works and how to set it up on a Cisco router.
Every lesson uses the same small office below. The PCs and the web server Web1 use private addresses in 192.168.10.0/24. R1 is the edge router: Gi0/0 faces the office (inside), and Gi0/1 faces the ISP (outside) with the public address 203.0.113.2/30. The server on the internet is 198.51.100.10.
- 1. PC1 sends a request. Its source address is private. The internet can't route it.
- 2. R1 translates it. The packet leaves with R1's public address, and R1 writes the swap in its translation table.
- 3. The reply comes back. R1 finds the entry, puts PC1's private address back, and forwards the reply inside.
What you'll learn
Why NAT exists
Private addresses can't cross the internet. NAT swaps them for public ones at the edge router.
Speak the language
Inside local, inside global, outside local and outside global, explained with one picture.
Three kinds of NAT
Static NAT for servers, dynamic NAT from a pool, and PAT so a whole office shares one address.
Prove it works
Read the translation table and statistics, and track down the faults that break NAT.
Skills you'll gain
- Private vs. public IPv4
- NAT terminology
- Static NAT
- Dynamic NAT
- PAT / overload
- show ip nat translations
- NAT troubleshooting
Who is this for?
CCNA students and anyone who wants to know what their router does with addresses. You should know what an IP address and a subnet are (see IP Addressing), and roughly how a router forwards packets.