Routelearn.net
Course menu

Course 11: NAT ConfigurationLesson 2.2 (3 of 7 in this course)69 of 91 in the CCNA series

Dynamic NAT

A pool of public addresses handed out on demand, and what happens when the pool runs out.

Intermediate · 7 min read

Dynamic NAT is a form of NAT that maps inside local addresses, chosen by an access list, one-to-one to public addresses taken from a configured pool. Mappings are created when traffic needs them and removed after a period of inactivity, so hosts that find the pool empty cannot be translated.

In simple terms: The router has a small stack of public addresses and lends one to each inside device while it is using the internet. When the stack runs out, the next device has to wait.

Sharing a few public addresses

The office has four spare public addresses from its block: 203.0.113.17 to 203.0.113.20. Not every PC is online all the time, so instead of tying each address to one PC forever, R1 can lend them out. A PC that needs the internet borrows a free address, and gives it back when it is done.

What dynamic NAT is

Dynamic NAT maps inside hosts to public addresses taken from a pool (a range of addresses you define). Each mapping is still one-to-one, but it is made on demand and removed after a period of no traffic. It has three parts:

PartJobIn the office
Access list (ACL)Picks which inside addresses may be translated192.168.10.0/24
NAT poolThe public addresses to hand out203.0.113.17 – .20
NAT ruleLinks the ACL to the poolip nat inside source list 1 pool PUBLIC

Here the ACL doesn't block anything. It is just a list that says "these source addresses qualify for NAT". A packet that doesn't match is still routed, but without translation.

Gi0/0 · insideGi0/1 · outsidePC1192.168.10.11PC2192.168.10.12Web1192.168.10.50SW1NATR1 (NAT)edge routerISP203.0.113.1InternetServer198.51.100.10
  1. 1. PC1 sends first. Its address matches ACL 1, so R1 takes the first free pool address, 203.0.113.17.
  2. 2. PC1 now owns .17. Until the entry times out, every packet from PC1 uses 203.0.113.17.
  3. 3. PC2 gets the next one. Each inside host needs its own pool address. Four addresses means four hosts at a time.

When the pool runs out

Dynamic NAT is still one inside host per public address. If four hosts already hold the four pool addresses, a fifth host gets nothing. R1 drops its packets and counts a miss. That host has no internet until an entry expires. By default a dynamic entry with no traffic lasts 24 hours, so waiting is not much help. You can clear entries by hand, add more addresses, or use PAT (next lesson), which fixes this for good.

💡 This is why plain dynamic NAT is rare today. It saves fewer addresses than PAT and fails as soon as the pool is used up.

Configure it

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. The interfaces are already marked inside and outside, as in the “Static NAT” lesson.

access-list 1 permit 192.168.10.0 0.0.0.255

Standard ACL: the inside hosts allowed to use NAT. Note the wildcard mask, not a subnet mask.

ip nat pool PUBLIC 203.0.113.17 203.0.113.20 netmask 255.255.255.248

The pool: first address, last address and the mask of the block they belong to.

ip nat inside source list 1 pool PUBLIC

Hosts matching ACL 1 get an address from pool PUBLIC.

How to verify it

These outputs are based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip nat translations
Pro Inside global         Inside local          Outside local         Outside global
--- 203.0.113.17          192.168.10.11         ---                   ---
--- 203.0.113.18          192.168.10.12         ---                   ---
tcp 203.0.113.17:50211    192.168.10.11:50211   198.51.100.10:443     198.51.100.10:443
Total number of translations: 3
Each host gets a simple --- row (its borrowed address) and a row for each connection. Unlike static NAT, these rows disappear when they time out.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip nat statistics
Total active translations: 6 (0 static, 6 dynamic; 2 extended)
Outside interfaces:
  GigabitEthernet0/1
Inside interfaces:
  GigabitEthernet0/0
Hits: 2214  Misses: 7
Expired translations: 3
Dynamic mappings:
-- Inside Source
[Id: 1] access-list 1 pool PUBLIC refcount 4
 pool PUBLIC: netmask 255.255.255.248
        start 203.0.113.17 end 203.0.113.20
        type generic, total addresses 4, allocated 4 (100%), misses 5
allocated 4 (100%) means the pool is full, and the rising misses count shows hosts being turned away.
clear ip nat translation *

Removes all dynamic entries (static ones stay). Open connections through R1 will break, so use it with care.

Check yourself

Predict · scenario 1

In dynamic NAT, what does the ACL do?

Predict · scenario 2

The pool has 4 addresses and 4 PCs are using them. A fifth PC sends to the internet. What happens?