Routelearn.net
Course menu

Course 11: NAT ConfigurationLesson 2.1 (2 of 7 in this course)68 of 91 in the CCNA series

Static NAT

A fixed one-to-one mapping, used when a server inside must be reachable from outside.

Intermediate · 7 min read

Static NAT is a form of NAT that permanently maps one inside local address to one inside global address, as configured by an administrator. Because the mapping always exists, it works in both directions, which lets outside hosts start connections to an inside server.

In simple terms: One inside device always gets the same public address. That means people on the internet can always find it, for example to reach your web server.

A server the world must reach

The office runs its website on Web1 (192.168.10.50). Customers on the internet type the site's name, DNS gives them a public address, and their browser connects. But Web1 has a private address, and nobody outside can reach it. Web1 needs a public address that always leads to Web1.

The ISP has given the office a small extra block, 203.0.113.16/29, and routes it to R1. You will use 203.0.113.21 for Web1.

What static NAT is

Static NAT is a fixed, one-to-one mapping between one inside local address and one inside global address. You type it once, and the router keeps it forever. It works in both directions:

  • Traffic to 203.0.113.21 from outside is sent to 192.168.10.50.
  • Traffic from 192.168.10.50 going out leaves as 203.0.113.21.
Gi0/0 · insideGi0/1 · outsidePC1192.168.10.11PC2192.168.10.12Web1192.168.10.50SW1NATR1 (NAT)edge routerISP203.0.113.1InternetServer198.51.100.10
  1. 1. A visitor connects. The client at 198.51.100.10 sends to 203.0.113.21. The ISP routes that block to R1.
  2. 2. R1 uses its fixed mapping. No outbound packet was needed first. R1 changes the destination to 192.168.10.50 and delivers it.
  3. 3. The reply goes out. R1 changes Web1's source back to 203.0.113.21, so the client sees the address it expected.

Why it works this way

With the other kinds of NAT, an entry only appears after an inside device sends something out. A visitor on the internet can't start a connection, because R1 wouldn't know which inside device to send it to. Static NAT solves that: the entry exists before any traffic. The cost is one public address per server, which is why static NAT is used for servers, not for every PC.

Static NATDynamic NAT / PAT
Entry createdWhen you configure itWhen an inside host sends traffic
Outside can start a connection?YesNo
Public addresses usedOne per inside hostShared
Typical useWeb, mail and VPN serversPCs and phones

Configure it

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device.

interface GigabitEthernet0/0 ip address 192.168.10.1 255.255.255.0 ip nat inside interface GigabitEthernet0/1 ip address 203.0.113.2 255.255.255.252 ip nat outside

Mark which side is which. Every kind of NAT needs this step.

ip nat inside source static 192.168.10.50 203.0.113.21

Global config: inside local first, then inside global.

Sometimes you only have one public address, the one on Gi0/1. Then you can map a single port instead of the whole address. This is called static PAT, or port forwarding:

ip nat inside source static tcp 192.168.10.50 443 interface GigabitEthernet0/1 443

HTTPS (TCP 443) arriving on R1's outside address is sent to Web1. Other ports are not forwarded.

How to verify it

This output is based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip nat translations
Pro Inside global         Inside local          Outside local         Outside global
--- 203.0.113.21          192.168.10.50         ---                   ---
tcp 203.0.113.21:443      192.168.10.50:443     198.51.100.10:50122   198.51.100.10:50122
Total number of translations: 2
The first row, with --- in the protocol and outside columns, is the static entry itself. It is always there, even with no traffic. The second row appeared when the client at 198.51.100.10 opened an HTTPS connection to Web1.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show running-config | include ip nat
 ip nat inside
 ip nat outside
ip nat inside source static 192.168.10.50 203.0.113.21
A quick way to check both interfaces and the mapping at once.

Check yourself

Predict · scenario 1

In 'ip nat inside source static 192.168.10.50 203.0.113.21', which address is the inside global?

Predict · scenario 2

The office has 3 servers that must each be reachable on all ports. How many public addresses does static NAT need?

Predict · scenario 3

With no traffic at all, does a static NAT entry show in show ip nat translations?