One packet, two addresses
PC1 visits the server at 198.51.100.10. Ask PC1 what its address is, and it says 192.168.10.11. Ask the server who just visited, and it says 203.0.113.2. Both are right. They see the same device from different sides of R1. Cisco gives each view a name, and those names appear in every NAT command and every show output.
Inside and outside
First, R1 splits its interfaces into two sides:
- Inside: the network you own and manage. Here, Gi0/0 toward the office.
- Outside: everything else, usually the ISP and the internet. Here, Gi0/1.
You tell the router which is which with ip nat inside and ip nat outside on each interface. Translation only happens when a packet crosses from one side to the other.
Local and global
The second word tells you where you are looking from:
- Local: the address as seen by devices on the inside network.
- Global: the address as seen by devices on the outside network.
Put the two words together and you get four names:
| Name | Which device? | Seen from | In the office |
|---|---|---|---|
| Inside local | An inside host | The inside | 192.168.10.11 (PC1's real address) |
| Inside global | An inside host | The outside | 203.0.113.2 (PC1 after translation) |
| Outside local | An outside host | The inside | 198.51.100.10 |
| Outside global | An outside host | The outside | 198.51.100.10 (the server's real address) |
💡 Memory trick: the first word says whose address it is (an inside or outside device). The second word says who is looking (local = inside eyes, global = outside eyes).
Why the outside addresses are usually the same
With the normal kind of NAT, called inside source NAT, R1 only changes the address of the inside device. The server's address passes through untouched, so its outside local and outside global are equal. They only differ if you also translate outside addresses, which is rare and outside the CCNA scope. Almost every NAT problem you meet is about the two inside addresses.
- 1. Before R1 (inside view): source = inside local 192.168.10.11, destination = outside local 198.51.100.10.
- 2. After R1 (outside view): source = inside global 203.0.113.2, destination = outside global 198.51.100.10. Only the source changed.
- 3. Reply, outside view: the server answers the inside global address. It never learns 192.168.10.11.
- 4. Reply, inside view: R1 swaps inside global back to inside local and delivers it to PC1.
How to verify it
The four names are the four columns of the translation table. This output is based on Cisco documentation, not run on a lab device.
R1#show ip nat translations Pro Inside global Inside local Outside local Outside global tcp 203.0.113.2:49812 192.168.10.11:49812 198.51.100.10:443 198.51.100.10:443 Total number of translations: 1
192.168.10.11) is talking to the server on port 443 (HTTPS), and the outside world sees PC1 as 203.0.113.2. The two outside columns match, as expected. The numbers after the colons are port numbers, covered in the “PAT (NAT overload)” lesson.Check yourself
In the office, which name describes 192.168.10.11?
The server at 198.51.100.10 sees requests coming from 203.0.113.2. What is 203.0.113.2?
With normal inside source NAT, which two addresses are usually the same?