Routelearn.net
Course menu

Course 11: NAT ConfigurationLesson 2.3 (4 of 7 in this course)70 of 91 in the CCNA series

PAT (NAT overload)

Many inside devices sharing one public address, kept apart by port numbers.

Intermediate · 8 min read

PAT (Port Address Translation) is a form of NAT, called NAT overload by Cisco, that lets many inside hosts share one public IP address. The router translates both the address and the TCP or UDP port number and records each address-and-port pair, so it can tell the conversations apart and send replies to the right host.

In simple terms: A whole office can go online through a single public address. The router uses port numbers like extension numbers to keep track of whose traffic is whose.

Twenty PCs, one address

Most offices, and every home, have just one public address: the one on the router's outside interface. In the office that is 203.0.113.2. Dynamic NAT would let only one PC online at a time. Yet all twenty PCs need the internet at once. PAT makes this possible.

What PAT is

PAT (Port Address Translation), which Cisco calls NAT overload, lets many inside hosts share one public address. To tell the conversations apart, the router also looks at port numbers. A port is a number from 0 to 65535 in the TCP or UDP header that identifies one conversation on a device. A browser, for example, picks a random source port such as 51000 for each connection.

So instead of recording "address ↔ address", R1 records "address and port ↔ address and port". R1 tries to keep the original source port. If another host is already using that port on the public address, R1 picks a different free one.

Gi0/0 · insideGi0/1 · outsidePC1192.168.10.11PC2192.168.10.12Web1192.168.10.50SW1NATR1 (NAT)edge routerISP203.0.113.1InternetServer198.51.100.10
  1. 1. Two PCs, same source port. PC1 and PC2 both open HTTPS to the server, and by chance both pick source port 51000.
  2. 2. R1 keeps them apart. PC1 keeps port 51000. That is taken for PC2, so R1 gives PC2 port 1024. Both leave as 203.0.113.2.
  3. 3. Replies are sorted by port. A reply to port 1024 must belong to PC2, so R1 rewrites it to 192.168.10.12:51000.
Inside localInside globalOutside
192.168.10.11:51000203.0.113.2:51000198.51.100.10:443
192.168.10.12:51000203.0.113.2:1024198.51.100.10:443

Why it works so well

Every row in a PAT table is unique, because the public port is unique. With about 64,000 usable ports per protocol, one address can carry tens of thousands of conversations at once. That is plenty for a home or a small office. Large sites can use a small pool of addresses with overload to get more ports.

Static NATDynamic NATPAT
Mapping1 to 1, fixed1 to 1, from a poolMany to 1, by port
Public addressesOne per hostOne per active hostOften just one
Keywordstaticpooloverload

Configure it

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. The interfaces are marked inside and outside as in the “Static NAT” lesson.

access-list 1 permit 192.168.10.0 0.0.0.255

The inside hosts that may use PAT.

ip nat inside source list 1 interface GigabitEthernet0/1 overload

Interface PAT: share the address on Gi0/1. If the ISP changes that address (for example by DHCP), NAT follows it.

Or, to overload a pool of addresses instead of the interface:

ip nat pool PUBLIC 203.0.113.17 203.0.113.20 netmask 255.255.255.248 ip nat inside source list 1 pool PUBLIC overload

Pool PAT: the same as dynamic NAT, plus the overload keyword.

How to verify it

This output is based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip nat translations
Pro Inside global         Inside local          Outside local         Outside global
tcp 203.0.113.2:51000     192.168.10.11:51000   198.51.100.10:443     198.51.100.10:443
tcp 203.0.113.2:1024      192.168.10.12:51000   198.51.100.10:443     198.51.100.10:443
udp 203.0.113.2:53122     192.168.10.12:53122   198.51.100.10:53      198.51.100.10:53
icmp 203.0.113.2:7        192.168.10.11:7       198.51.100.10:7       198.51.100.10:7
Total number of translations: 4
Every inside global address is the same, 203.0.113.2. Only the port changes. There are no --- rows: PAT creates a row per conversation, not per host. For ping (ICMP), the router uses the ICMP query ID in place of a port.

Check yourself

Predict · scenario 1

What lets R1 tell apart replies for PC1 and PC2 when both use 203.0.113.2?

Predict · scenario 2

Which keyword turns dynamic NAT into PAT?

Predict · scenario 3

PC1 uses source port 49200 and no one else is using it. What port will R1 most likely use outside?