Twenty PCs, one address
Most offices, and every home, have just one public address: the one on the router's outside interface. In the office that is 203.0.113.2. Dynamic NAT would let only one PC online at a time. Yet all twenty PCs need the internet at once. PAT makes this possible.
What PAT is
PAT (Port Address Translation), which Cisco calls NAT overload, lets many inside hosts share one public address. To tell the conversations apart, the router also looks at port numbers. A port is a number from 0 to 65535 in the TCP or UDP header that identifies one conversation on a device. A browser, for example, picks a random source port such as 51000 for each connection.
So instead of recording "address ↔ address", R1 records "address and port ↔ address and port". R1 tries to keep the original source port. If another host is already using that port on the public address, R1 picks a different free one.
- 1. Two PCs, same source port. PC1 and PC2 both open HTTPS to the server, and by chance both pick source port 51000.
- 2. R1 keeps them apart. PC1 keeps port 51000. That is taken for PC2, so R1 gives PC2 port 1024. Both leave as 203.0.113.2.
- 3. Replies are sorted by port. A reply to port 1024 must belong to PC2, so R1 rewrites it to 192.168.10.12:51000.
| Inside local | Inside global | Outside |
|---|---|---|
192.168.10.11:51000 | 203.0.113.2:51000 | 198.51.100.10:443 |
192.168.10.12:51000 | 203.0.113.2:1024 | 198.51.100.10:443 |
Why it works so well
Every row in a PAT table is unique, because the public port is unique. With about 64,000 usable ports per protocol, one address can carry tens of thousands of conversations at once. That is plenty for a home or a small office. Large sites can use a small pool of addresses with overload to get more ports.
| Static NAT | Dynamic NAT | PAT | |
|---|---|---|---|
| Mapping | 1 to 1, fixed | 1 to 1, from a pool | Many to 1, by port |
| Public addresses | One per host | One per active host | Often just one |
| Keyword | static | pool | overload |
Configure it
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. The interfaces are marked inside and outside as in the “Static NAT” lesson.
access-list 1 permit 192.168.10.0 0.0.0.255The inside hosts that may use PAT.
ip nat inside source list 1 interface GigabitEthernet0/1 overloadInterface PAT: share the address on Gi0/1. If the ISP changes that address (for example by DHCP), NAT follows it.
Or, to overload a pool of addresses instead of the interface:
ip nat pool PUBLIC 203.0.113.17 203.0.113.20 netmask 255.255.255.248
ip nat inside source list 1 pool PUBLIC overloadPool PAT: the same as dynamic NAT, plus the overload keyword.
How to verify it
This output is based on Cisco documentation, not run on a lab device.
R1#show ip nat translations Pro Inside global Inside local Outside local Outside global tcp 203.0.113.2:51000 192.168.10.11:51000 198.51.100.10:443 198.51.100.10:443 tcp 203.0.113.2:1024 192.168.10.12:51000 198.51.100.10:443 198.51.100.10:443 udp 203.0.113.2:53122 192.168.10.12:53122 198.51.100.10:53 198.51.100.10:53 icmp 203.0.113.2:7 192.168.10.11:7 198.51.100.10:7 198.51.100.10:7 Total number of translations: 4
203.0.113.2. Only the port changes. There are no --- rows: PAT creates a row per conversation, not per host. For ping (ICMP), the router uses the ICMP query ID in place of a port.Check yourself
What lets R1 tell apart replies for PC1 and PC2 when both use 203.0.113.2?
Which keyword turns dynamic NAT into PAT?
PC1 uses source port 49200 and no one else is using it. What port will R1 most likely use outside?