A server the world must reach
The office runs its website on Web1 (192.168.10.50). Customers on the internet type the site's name, DNS gives them a public address, and their browser connects. But Web1 has a private address, and nobody outside can reach it. Web1 needs a public address that always leads to Web1.
The ISP has given the office a small extra block, 203.0.113.16/29, and routes it to R1. You will use 203.0.113.21 for Web1.
What static NAT is
Static NAT is a fixed, one-to-one mapping between one inside local address and one inside global address. You type it once, and the router keeps it forever. It works in both directions:
- Traffic to
203.0.113.21from outside is sent to192.168.10.50. - Traffic from
192.168.10.50going out leaves as203.0.113.21.
- 1. A visitor connects. The client at 198.51.100.10 sends to 203.0.113.21. The ISP routes that block to R1.
- 2. R1 uses its fixed mapping. No outbound packet was needed first. R1 changes the destination to 192.168.10.50 and delivers it.
- 3. The reply goes out. R1 changes Web1's source back to 203.0.113.21, so the client sees the address it expected.
Why it works this way
With the other kinds of NAT, an entry only appears after an inside device sends something out. A visitor on the internet can't start a connection, because R1 wouldn't know which inside device to send it to. Static NAT solves that: the entry exists before any traffic. The cost is one public address per server, which is why static NAT is used for servers, not for every PC.
| Static NAT | Dynamic NAT / PAT | |
|---|---|---|
| Entry created | When you configure it | When an inside host sends traffic |
| Outside can start a connection? | Yes | No |
| Public addresses used | One per inside host | Shared |
| Typical use | Web, mail and VPN servers | PCs and phones |
Configure it
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device.
interface GigabitEthernet0/0
ip address 192.168.10.1 255.255.255.0
ip nat inside
interface GigabitEthernet0/1
ip address 203.0.113.2 255.255.255.252
ip nat outsideMark which side is which. Every kind of NAT needs this step.
ip nat inside source static 192.168.10.50 203.0.113.21Global config: inside local first, then inside global.
Sometimes you only have one public address, the one on Gi0/1. Then you can map a single port instead of the whole address. This is called static PAT, or port forwarding:
ip nat inside source static tcp 192.168.10.50 443 interface GigabitEthernet0/1 443HTTPS (TCP 443) arriving on R1's outside address is sent to Web1. Other ports are not forwarded.
How to verify it
This output is based on Cisco documentation, not run on a lab device.
R1#show ip nat translations Pro Inside global Inside local Outside local Outside global --- 203.0.113.21 192.168.10.50 --- --- tcp 203.0.113.21:443 192.168.10.50:443 198.51.100.10:50122 198.51.100.10:50122 Total number of translations: 2
--- in the protocol and outside columns, is the static entry itself. It is always there, even with no traffic. The second row appeared when the client at 198.51.100.10 opened an HTTPS connection to Web1.R1#show running-config | include ip nat ip nat inside ip nat outside ip nat inside source static 192.168.10.50 203.0.113.21
Check yourself
In 'ip nat inside source static 192.168.10.50 203.0.113.21', which address is the inside global?
The office has 3 servers that must each be reachable on all ports. How many public addresses does static NAT need?
With no traffic at all, does a static NAT entry show in show ip nat translations?