Sharing a few public addresses
The office has four spare public addresses from its block: 203.0.113.17 to 203.0.113.20. Not every PC is online all the time, so instead of tying each address to one PC forever, R1 can lend them out. A PC that needs the internet borrows a free address, and gives it back when it is done.
What dynamic NAT is
Dynamic NAT maps inside hosts to public addresses taken from a pool (a range of addresses you define). Each mapping is still one-to-one, but it is made on demand and removed after a period of no traffic. It has three parts:
| Part | Job | In the office |
|---|---|---|
| Access list (ACL) | Picks which inside addresses may be translated | 192.168.10.0/24 |
| NAT pool | The public addresses to hand out | 203.0.113.17 – .20 |
| NAT rule | Links the ACL to the pool | ip nat inside source list 1 pool PUBLIC |
Here the ACL doesn't block anything. It is just a list that says "these source addresses qualify for NAT". A packet that doesn't match is still routed, but without translation.
- 1. PC1 sends first. Its address matches ACL 1, so R1 takes the first free pool address, 203.0.113.17.
- 2. PC1 now owns .17. Until the entry times out, every packet from PC1 uses 203.0.113.17.
- 3. PC2 gets the next one. Each inside host needs its own pool address. Four addresses means four hosts at a time.
When the pool runs out
Dynamic NAT is still one inside host per public address. If four hosts already hold the four pool addresses, a fifth host gets nothing. R1 drops its packets and counts a miss. That host has no internet until an entry expires. By default a dynamic entry with no traffic lasts 24 hours, so waiting is not much help. You can clear entries by hand, add more addresses, or use PAT (next lesson), which fixes this for good.
💡 This is why plain dynamic NAT is rare today. It saves fewer addresses than PAT and fails as soon as the pool is used up.
Configure it
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. The interfaces are already marked inside and outside, as in the “Static NAT” lesson.
access-list 1 permit 192.168.10.0 0.0.0.255Standard ACL: the inside hosts allowed to use NAT. Note the wildcard mask, not a subnet mask.
ip nat pool PUBLIC 203.0.113.17 203.0.113.20 netmask 255.255.255.248The pool: first address, last address and the mask of the block they belong to.
ip nat inside source list 1 pool PUBLICHosts matching ACL 1 get an address from pool PUBLIC.
How to verify it
These outputs are based on Cisco documentation, not run on a lab device.
R1#show ip nat translations Pro Inside global Inside local Outside local Outside global --- 203.0.113.17 192.168.10.11 --- --- --- 203.0.113.18 192.168.10.12 --- --- tcp 203.0.113.17:50211 192.168.10.11:50211 198.51.100.10:443 198.51.100.10:443 Total number of translations: 3
--- row (its borrowed address) and a row for each connection. Unlike static NAT, these rows disappear when they time out.R1#show ip nat statistics Total active translations: 6 (0 static, 6 dynamic; 2 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 2214 Misses: 7 Expired translations: 3 Dynamic mappings: -- Inside Source [Id: 1] access-list 1 pool PUBLIC refcount 4 pool PUBLIC: netmask 255.255.255.248 start 203.0.113.17 end 203.0.113.20 type generic, total addresses 4, allocated 4 (100%), misses 5
allocated 4 (100%) means the pool is full, and the rising misses count shows hosts being turned away.clear ip nat translation *Removes all dynamic entries (static ones stay). Open connections through R1 will break, so use it with care.
Check yourself
In dynamic NAT, what does the ACL do?
The pool has 4 addresses and 4 PCs are using them. A fifth PC sends to the internet. What happens?