Routelearn.net
Course menu

Course 11: NAT ConfigurationLesson 3.1 (5 of 7 in this course)71 of 91 in the CCNA series

Verifying and troubleshooting NAT

show ip nat translations, statistics and debug, plus the common faults and how to spot them.

Intermediate · 8 min read

The NAT translation table is the list of current address (and, for PAT, port) mappings that a NAT router maintains. On Cisco IOS it is shown with show ip nat translations, while show ip nat statistics and debug ip nat show whether packets are actually being translated.

In simple terms: It's the router's notebook of who has been given which public address. Reading it, and its counters, is the quickest way to see whether NAT is doing its job.

"The internet is down"

On Monday morning PC1 can't open any website. PC1 can ping its gateway, R1, at 192.168.10.1. R1 itself can ping the server at 198.51.100.10. So the LAN works and the ISP link works. The problem is in between, and that is exactly where NAT lives.

The three tools

CommandWhat it tells you
show ip nat translationsEvery current mapping. Is anything being translated at all?
show ip nat statisticsWhich interfaces are inside and outside, hit and miss counters, and pool usage.
debug ip natA live log line for every packet translated. Use briefly, on a quiet router.

Reading the statistics

Start with the statistics, because they show the setup and the counters on one screen. These outputs are based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip nat statistics
Total active translations: 0 (0 static, 0 dynamic; 0 extended)
Outside interfaces:
  GigabitEthernet0/0
Inside interfaces:
  GigabitEthernet0/1
Hits: 0  Misses: 0
Expired translations: 0
Dynamic mappings:
-- Inside Source
[Id: 1] access-list 1 interface GigabitEthernet0/1 refcount 0
Found it. Gi0/0 faces the office but is marked outside, and Gi0/1 faces the ISP but is marked inside. Packets from PC1 go from "outside" to "inside", so the inside source rule never fires. Hits and misses both stay at zero.
interface GigabitEthernet0/0 no ip nat outside ip nat inside interface GigabitEthernet0/1 no ip nat inside ip nat outside

The fix (based on Cisco documentation): put each interface on the right side.

Watching packets with debug

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#debug ip nat
IP NAT debugging is on
NAT: s=192.168.10.11->203.0.113.2, d=198.51.100.10 [21507]
NAT*: s=198.51.100.10, d=203.0.113.2->192.168.10.11 [40211]
NAT*: s=192.168.10.11->203.0.113.2, d=198.51.100.10 [21508]
s= is the source and d= the destination; an arrow shows the address being changed. The first line is PC1 going out, the second is the reply coming back in. The star means the packet was handled in the fast path (CEF). The number in brackets is the IP ID of the packet. Turn debug off with undebug all.

Faults and their clues

Almost every NAT problem is one of these. Each one leaves a clue in the outputs above.

FaultClueFix
Inside and outside swapped, or one missingWrong interface lists in statistics; no translationsCorrect ip nat inside / outside
ACL doesn't match the hostsNo rows for that host; a wrong subnet or wildcard in the ACLFix the ACL, e.g. 0.0.0.255, not 255.255.255.0
NAT rule names the wrong ACL or poolStatistics show refcount 0 while users send trafficMatch the numbers and names exactly
Pool used up (no overload)allocated 100% and rising missesAdd overload or more addresses
No route back to the public addressesTranslations appear, but replies never arriveThe ISP must route the pool or static block to R1
No default route on R1Packets dropped before NAT; ping from R1 to the internet failsip route 0.0.0.0 0.0.0.0 203.0.113.1
Gi0/0 · insideGi0/1 · outsidePC1192.168.10.11PC2192.168.10.12Web1192.168.10.50SW1NATR1 (NAT)edge routerISP203.0.113.1InternetServer198.51.100.10
  1. 1. Does the packet reach an inside interface? Check the gateway, then that Gi0/0 is ip nat inside and the ACL matches PC1.
  2. 2. Is a translation made? show ip nat translations and statistics: rows, hits, misses, pool use.
  3. 3. Can R1 route it out? Gi0/1 must be ip nat outside, and R1 needs a default route to the ISP.
  4. 4. Can the reply find R1? The ISP must route the inside global address back to R1. If not, the reply never arrives.

💡 Testing from the router? A plain ping from R1 uses R1's outside address and is not translated. To test NAT from R1, use an extended ping with source GigabitEthernet0/0, or better, test from a real inside PC.

Check yourself

Predict · scenario 1

show ip nat statistics shows Hits: 0 and the office-facing interface listed under Outside interfaces. What is wrong?

Predict · scenario 2

R1 uses a pool. A row maps PC1 to 203.0.113.17, but its web pages never load. What should you check next?

Predict · scenario 3

A pool shows 'allocated 4 (100%), misses 12'. What is the simplest fix?