Routelearn.net
Course menu

Course 11: NAT ConfigurationLesson 3.2 (6 of 7 in this course)72 of 91 in the CCNA series

Lab: static NAT and PAT

Publish a web server with static NAT and give an office internet access with PAT.

Intermediate · 20 min read

NAT (Network Address Translation) is a router function that rewrites the IP addresses in packet headers as packets pass between two networks, most often swapping private inside addresses for public ones. The router records each mapping in a translation table so that return traffic can be translated back.

In simple terms: Your office uses private addresses that the internet can't route. NAT lets the router swap them for a public address on the way out and swap them back on the way in.

The brief

You are setting up R1 for the office. Two goals: customers on the internet must reach the website on Web1, and every PC must be able to browse the web. Write your answer to each task before you open it. You can build this in Cisco Packet Tracer or any IOS lab.

Gi0/0 · insideGi0/1 · outsidePC1192.168.10.11PC2192.168.10.12Web1192.168.10.50SW1NATR1 (NAT)edge routerISP203.0.113.1InternetServer198.51.100.10
  1. 1. Goal 1: the internet reaches Web1 at 203.0.113.21 (static NAT).
  2. 2. Goal 2: all PCs share R1's outside address 203.0.113.2 (PAT).
DeviceInterfaceAddress
R1Gi0/0 (to SW1)192.168.10.1/24
R1Gi0/1 (to ISP)203.0.113.2/30
ISPGi0/0 (to R1)203.0.113.1/30
PC1 / PC2NIC192.168.10.11 / .12, gateway 192.168.10.1
Web1NIC192.168.10.50, gateway 192.168.10.1
ServerNIC198.51.100.10

The ISP routes the block 203.0.113.16/29 to R1. The IP addresses are already configured. All answers are based on Cisco IOS / IOS XE documentation, not run on a lab device.

Task 1: give R1 a way out

R1 has no route to the internet yet. Add one.

Show answer
ip route 0.0.0.0 0.0.0.0 203.0.113.1

A default route toward the ISP. Without it, nothing leaves R1, translated or not.

Task 2: mark inside and outside

Show answer
interface GigabitEthernet0/0 ip nat inside interface GigabitEthernet0/1 ip nat outside

Gi0/0 faces the office, Gi0/1 faces the ISP.

Task 3: publish Web1 with static NAT

Map Web1 to 203.0.113.21 so the internet can reach it.

Show answer
ip nat inside source static 192.168.10.50 203.0.113.21

Inside local first, inside global second.

Task 4: PAT for the office

Let every host in 192.168.10.0/24 share Gi0/1's address.

Show answer
access-list 1 permit 192.168.10.0 0.0.0.255 ip nat inside source list 1 interface GigabitEthernet0/1 overload

ACL 1 selects the office hosts; overload turns on PAT.

Web1 is also inside 192.168.10.0/24. That is fine: its static mapping takes priority, so Web1 always leaves as 203.0.113.21.

Task 5: predict the table

PC1 opens HTTPS to the server from source port 50500, and PC2 pings the server. A client at 198.51.100.10 then browses to 203.0.113.21 on port 443 from source port 61000. Write down the rows of show ip nat translations.

Show answer
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip nat translations
Pro Inside global         Inside local          Outside local         Outside global
--- 203.0.113.21          192.168.10.50         ---                   ---
tcp 203.0.113.21:443      192.168.10.50:443     198.51.100.10:61000   198.51.100.10:61000
tcp 203.0.113.2:50500     192.168.10.11:50500   198.51.100.10:443     198.51.100.10:443
icmp 203.0.113.2:1        192.168.10.12:1       198.51.100.10:1       198.51.100.10:1
Total number of translations: 4
The static entry is always present. The inbound HTTPS connection adds a row for Web1. PC1 and PC2 both appear as 203.0.113.2, told apart by port (or ICMP ID).

Task 6: test it

Which tests prove each goal, and where do you run them?

Show answer
  • From PC1: ping 198.51.100.10, or open a web page on the server. Then check that a 203.0.113.2 row appears on R1.
  • From the server: browse to http(s)://203.0.113.21. The request should reach Web1.
  • On R1: show ip nat statistics should list Gi0/0 as inside, Gi0/1 as outside, and a rising hit count.

Don't test PAT with a plain ping from R1: that traffic starts on R1 itself, uses R1's own address and is not translated.