At home, your laptop, your phone and your TV all browse the internet at the same time, yet your internet provider gave you just one public IP address. The trick that makes this possible is NAT, and in particular a form of it called PAT. This lesson shows exactly what the router changes in each packet, and how it gets every reply back to the right device.
What NAT is
NAT (Network Address Translation) is a job done by a router at the edge of a network: it rewrites the IP addresses in packets as they pass through. The most common use is to swap the private address of an inside device for the router's own public address on the way out, and to swap it back on the way in.
PAT (Port Address Translation) goes one step further: it also rewrites the port numbers. That lets hundreds of devices share a single public address at once. Cisco calls this NAT overload; home routers just call it NAT.
Why it exists
The full story is in Why NAT exists. In short:
- IPv4 ran out. There are only about 4.3 billion IPv4 addresses, far fewer than the devices that want to be online.
- Private addresses fill the gap. Inside a home or company, devices use RFC 1918 ranges such as
192.168.1.0/24. Everyone can reuse them, because they never appear on the internet. - But private addresses can't be routed on the internet. Thousands of homes use
192.168.1.10right now, so a reply sent to that address would have nowhere to go. Internet routers drop such packets. - NAT is the bridge. It lets private devices talk to the internet using a small number of public addresses: often just one.
Where NAT happens
NAT happens on the device that sits between the private network and the internet: the home router, or the office's edge router or firewall. That device is also the default gateway for the inside devices, so every packet for the internet passes through it anyway. It has two sides:
| Side | Faces | Address in this example |
|---|---|---|
| Inside (LAN) | Your own devices | 192.168.1.1 (private) |
| Outside (WAN) | The internet provider | 203.0.113.5 (public, given by the ISP) |
- 1. Inside: the laptop sends from its private address. Nothing has changed yet.
- 2. At the edge: the router swaps the private source for its public address 203.0.113.5 and writes the swap in its translation table.
- 3. Outside: the internet only ever sees the router's public address.
- 4. Return: the reply comes back to 203.0.113.5. The router looks up the table and swaps the destination back to 192.168.1.10.
- 5. Shared: both devices browse at once, both appearing as 203.0.113.5. Ports keep them apart (PAT).
The important parts
Inside and outside interfaces
The router must know which side is private and which is public, so it knows which direction to translate.
Translation table
The router's memory of every active swap: which inside address and port belongs to which public address and port. Replies are matched against it.
Public address (or pool)
The address the inside devices appear as. Home routers use the one address the ISP gives the WAN port.
Timeouts
Entries are deleted after a period of no traffic (seconds for DNS, minutes or hours for TCP). Otherwise the table would fill up.
There are three classic kinds of NAT:
Static NAT
One to one, permanent
One private address is always swapped for the same public address. Used so a server inside can be reached from outside.
Dynamic NAT
One to one, from a pool
Inside devices borrow a public address from a pool while they need it. If the pool runs out, the next device must wait.
PAT (NAT overload)
Many to one, using ports
Every inside device shares one public address. Port numbers keep the conversations apart. This is what nearly every home and office uses.
Source NAT, step by step
Start with the simplest case: one laptop opens a website. Changing the source address of outgoing traffic is called source NAT. The laptop is 192.168.1.10, the router's public address is 203.0.113.5, and the web server is 198.51.100.20 on HTTPS port 443.
- The laptop builds a packet from
192.168.1.10(port 50001, an ephemeral port) to198.51.100.20port 443. The server is on another network, so the laptop sends the frame to its default gateway's MAC address. - The router receives it on the inside interface and decides to send it out of the outside interface toward the ISP.
- The router translates. It replaces the source address
192.168.1.10with203.0.113.5, and fixes the IP and TCP checksums so the packet is still valid. - The router remembers. It adds an entry to its translation table: inside
192.168.1.10:50001↔ outside203.0.113.5:50001, talking to198.51.100.20:443. - The packet crosses the internet with a public source address, so every router can route the reply.
- The server replies to
203.0.113.5. It has no idea a private address was ever involved.
- Source IP
- 192.168.1.10
- Source port
- 50001
- Destination IP
- 198.51.100.20
- Destination port
- 443
- Source IP
- 203.0.113.5 (rewritten)
- Source port
- 50001
- Destination IP
- 198.51.100.20
- Destination port
- 443
Highlighted fields were rewritten by the router.
The translation table
After that first packet, the router's table holds one row:
| Protocol | Inside (private) | Outside (public) | Remote server |
|---|---|---|---|
| TCP | 192.168.1.10:50001 | 203.0.113.5:50001 | 198.51.100.20:443 |
💡 Cisco uses special names for these columns: inside local (the private address), inside global (the public address it becomes), and outside local / outside global for the remote server. You don't need these names to understand NAT; they are explained in the CCNA-track lesson Inside local, inside global and friends.
PAT: many devices, one public address
With plain one-to-one NAT, two inside devices would need two public addresses. Most homes only have one. PAT solves this by using the source port as well. Each conversation gets its own public port number, and the router uses that number to tell the conversations apart.
Now the laptop and the PC both open the same website. By chance, both picked source port 50001:
- The laptop's packet arrives first. Public port
50001is free, so the router keeps it:192.168.1.10:50001 → 203.0.113.5:50001. - The PC's packet arrives from
192.168.1.11:50001. Public port 50001 toward that server is already taken, so the router changes the source port too, for example to50002:192.168.1.11:50001 → 203.0.113.5:50002. - Both packets leave with the same public source address, but with different source ports.
- When replies arrive, the destination port (50001 or 50002) tells the router which inside device each one belongs to.
- Source IP
- 192.168.1.11
- Source port
- 50001
- Destination IP
- 198.51.100.20
- Destination port
- 443
- Source IP
- 203.0.113.5 (rewritten)
- Source port
- 50002 (rewritten)
- Destination IP
- 198.51.100.20
- Destination port
- 443
Highlighted fields were rewritten by the router.
| Protocol | Inside (private) | Outside (public) | Remote server |
|---|---|---|---|
| TCP | 192.168.1.10:50001 | 203.0.113.5:50001 | 198.51.100.20:443 |
| TCP | 192.168.1.11:50001 | 203.0.113.5:50002 | 198.51.100.20:443 |
| UDP | 192.168.1.11:61000 | 203.0.113.5:61000 | 198.51.100.53:53 (DNS) |
Every row is unique on the outside, so every reply can be matched to exactly one inside device. A single public address has about 65,000 ports for TCP and as many again for UDP, which is plenty for a home or small office. ICMP messages such as ping have no ports, so PAT uses the ICMP query identifier in the same way.
💡 In simple terms: PAT is like a company with one phone number and many extensions. Callers outside only ever see the main number; the extension (the port) decides whose desk the call reaches.
The return path
Replies are where the translation table earns its keep. When a packet arrives on the outside interface, the router:
- Reads the destination address and port:
203.0.113.5:50002. - Looks for a table entry that matches (and that came from this remote server).
- Finds
192.168.1.11:50001and rewrites the destination address and port to those values. - Forwards the packet onto the LAN, using ARP to find the PC's MAC address.
- Source IP
- 198.51.100.20
- Source port
- 443
- Destination IP
- 203.0.113.5
- Destination port
- 50002
- Source IP
- 198.51.100.20
- Source port
- 443
- Destination IP
- 192.168.1.11 (rewritten)
- Destination port
- 50001 (rewritten)
Highlighted fields were rewritten by the router.
Why unsolicited inbound traffic fails
Now imagine a computer on the internet sends a packet to 203.0.113.5 port 3389 without anyone inside asking for it. The router looks in its table and finds nothing for port 3389. It has no idea which inside device, if any, should receive it, so it drops the packet.
- 1. Unsolicited: a packet arrives for 203.0.113.5 port 3389. Nobody inside started this conversation.
- 2. Dropped: no translation table entry matches, so the router cannot know which device it is for. The packet goes nowhere.
This is why people say NAT "hides" inside devices. It is a useful side effect, but it is not a security feature you should rely on by itself: the real protection comes from the firewall that runs on the same router. It is also why running a game server or a camera that must be reached from outside needs extra setup.
Destination NAT and port forwarding
Sometimes you want outside devices to reach something inside, such as a web server or a home security camera. The fix is a permanent rule that changes the destination address of incoming traffic. This is destination NAT; on a home router it is called port forwarding.
Example rule: "send anything arriving on TCP port 443 of my public address to 192.168.1.50 port 443".
- Source IP
- 192.0.2.99
- Source port
- 53122
- Destination IP
- 203.0.113.5
- Destination port
- 443
- Source IP
- 192.0.2.99
- Source port
- 53122
- Destination IP
- 192.168.1.50 (rewritten)
- Destination port
- 443
Highlighted fields were rewritten by the router.
- The inside server needs a fixed address (a static IP or a DHCP reservation). If its address changes, the rule points at nothing.
- One public port can be forwarded to only one inside device. Two web servers can't both have port 443 on one public address.
- Anything you forward is exposed to the whole internet. Forward only what you must, and keep that device patched.
CGNAT: NAT at the ISP
IPv4 addresses are now so scarce that many internet providers, especially mobile networks, don't give each customer a public address at all. Instead they run carrier-grade NAT (CGNAT): one big PAT device in the ISP's network shared by many customers. Your home router's WAN side gets an address from the shared range 100.64.0.0/10 (set aside for this purpose by RFC 6598), and the ISP translates again on the way to the internet.
- 1. First NAT: the home router swaps the private address for its WAN address 100.64.12.34.
- 2. Second NAT: the ISP's CGNAT device swaps that for a real public address, shared with many other customers.
- 3. Outside: the website sees 203.0.113.200, not your router's WAN address.
You can spot CGNAT yourself: if your router's WAN address starts with 100.64 to 100.127, or it doesn't match what What Is My IP shows, you are behind CGNAT. The big downside: port forwarding on your own router can't work, because the ISP's NAT drops the unsolicited traffic before it ever reaches you.
A real-world example
Open What Is My IP on your laptop and on your phone while both are on your home Wi-Fi. Both show the same public address. Then check each device's own address (ipconfig on Windows, Settings → Wi-Fi on a phone): each has a different private 192.168.x.x address. The difference between the two is NAT at work.
C:\> ipconfig Wireless LAN adapter Wi-Fi: Connection-specific DNS Suffix . : home IPv4 Address. . . . . . . . . . . : 192.168.1.10 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.1.1
203.0.113.5) exists only on the router, so you have to ask an outside service to see it.What happens when NAT fails
| Symptom | Likely cause |
|---|---|
| Outbound browsing works, but nobody outside can reach your server or game | Normal NAT behaviour: no port forward, wrong inside address in the rule, or CGNAT at the ISP |
| Port forward set up, but still unreachable | The inside device's address changed, its own firewall blocks the port, or you are behind CGNAT |
| New connections fail on a busy network, old ones keep working | The translation table or the pool of public ports is full |
| Long idle connections (SSH, games) drop after a while | The NAT entry timed out because no traffic passed; the next packet has no matching entry |
| Some apps (voice calls, old FTP) connect but audio or data fails | The app writes IP addresses inside its data, which NAT doesn't rewrite unless the router has a helper for that app |
| Nothing reaches the internet, but the LAN works | The router has no public address from the ISP, or NAT is not enabled on the outside interface |
Troubleshooting NAT
- Check the inside first. Can the device reach its default gateway? If not, NAT isn't the problem yet (see IP and gateway problems).
- Compare addresses. Your device's private address (
ipconfig/ip addr), the router's WAN address (on its status page) and your public address (What Is My IP). Three different values in three ranges tell you a lot. - Look for double NAT. A traceroute whose first two hops are both private or
100.64.x.xaddresses shows two NAT layers. - For port forwarding, test from outside. Testing from inside your own network often fails even when the rule works. Use the Port Checker tool.
C:\> tracert -d 198.51.100.20 Tracing route to 198.51.100.20 over a maximum of 30 hops 1 2 ms 1 ms 1 ms 192.168.1.1 2 9 ms 8 ms 9 ms 100.64.0.1 3 12 ms 11 ms 12 ms 203.0.113.1 4 14 ms 13 ms 14 ms 198.51.100.20 Trace complete.
100.64.0.0/10 shared range, a strong hint that the ISP runs CGNAT. Read more about this output in Traceroute.Common mistakes
- Thinking NAT is a firewall. It blocks unsolicited inbound traffic as a side effect, but it doesn't inspect or filter anything on purpose.
- Mixing up the directions. Outgoing traffic gets its source rewritten; replies get their destination rewritten. Port forwarding rewrites the destination of traffic started outside.
- Forwarding to a device that uses DHCP without a reservation. After a reboot it may get a new address and the rule breaks.
- Assuming your public IP belongs only to you. With CGNAT, many customers share it.
- Expecting the PC to know its public address. Only the router (or the ISP) knows it.
- NAT rewrites IP addresses at the network edge, usually private source → public on the way out.
- PAT also rewrites ports, so many inside devices share one public address.
- The translation table remembers every swap so replies can be swapped back.
- Traffic from outside with no matching entry is dropped, unless a port forward (destination NAT) rule exists.
- CGNAT adds a second NAT at the ISP and stops port forwarding from working.
Check yourself
A laptop at 192.168.1.10 sends a packet to a web server through a PAT router whose public address is 203.0.113.5. What source address does the web server see?
Two inside PCs both use source port 50001 to talk to the same server. How does the PAT router keep them apart?
A friend on the internet tries to connect to your public address on port 25565 to join your game server. You have no port forwarding set up. What happens?
Your router's WAN address is 100.72.18.4 and port forwarding doesn't work even though the rule is correct. Why?
Going further (CCNA)
This lesson explains how NAT behaves. Configuring it on Cisco routers is CCNA material, covered in the NAT configuration lessons: Inside local, inside global and friends, Static NAT, Dynamic NAT, PAT (NAT overload) and Verifying and troubleshooting NAT.
Next, see NAT as one step in a full journey in What happens when you open a website?, and compare it with the job of a firewall.