Routelearn.net
Course menu

Unit 8: Core Network ServicesLesson 8.4 (4 of 4 in this unit)57 of 84 in the Network Fundamentals course

How NAT and PAT work

How your router lets a whole house or office share one public IP address: what NAT changes in each packet, how PAT uses port numbers to keep conversations apart, how replies find their way back, why the internet can't start a connection to you, and how port forwarding and CGNAT fit in.

Beginner · 16 min read · Before this: Public and private IP addresses, Port numbers and sockets, Why NAT exists

NAT (Network Address Translation) is the rewriting of IP addresses in packet headers as they pass through a router, most often to replace private inside addresses with a public one. PAT (Port Address Translation) is the common form that also rewrites port numbers, so many inside hosts can share a single public address.

In simple terms: NAT lets a whole house or office share one public IP address. The router swaps the addresses on the way out, remembers each conversation, and swaps them back when replies arrive.

At home, your laptop, your phone and your TV all browse the internet at the same time, yet your internet provider gave you just one public IP address. The trick that makes this possible is NAT, and in particular a form of it called PAT. This lesson shows exactly what the router changes in each packet, and how it gets every reply back to the right device.

What NAT is

NAT (Network Address Translation) is a job done by a router at the edge of a network: it rewrites the IP addresses in packets as they pass through. The most common use is to swap the private address of an inside device for the router's own public address on the way out, and to swap it back on the way in.

PAT (Port Address Translation) goes one step further: it also rewrites the port numbers. That lets hundreds of devices share a single public address at once. Cisco calls this NAT overload; home routers just call it NAT.

Why it exists

The full story is in Why NAT exists. In short:

  • IPv4 ran out. There are only about 4.3 billion IPv4 addresses, far fewer than the devices that want to be online.
  • Private addresses fill the gap. Inside a home or company, devices use RFC 1918 ranges such as 192.168.1.0/24. Everyone can reuse them, because they never appear on the internet.
  • But private addresses can't be routed on the internet. Thousands of homes use 192.168.1.10 right now, so a reply sent to that address would have nowhere to go. Internet routers drop such packets.
  • NAT is the bridge. It lets private devices talk to the internet using a small number of public addresses: often just one.

Where NAT happens

NAT happens on the device that sits between the private network and the internet: the home router, or the office's edge router or firewall. That device is also the default gateway for the inside devices, so every packet for the internet passes through it anyway. It has two sides:

SideFacesAddress in this example
Inside (LAN)Your own devices192.168.1.1 (private)
Outside (WAN)The internet provider203.0.113.5 (public, given by the ISP)
public sideLaptop192.168.1.10PC192.168.1.11Home routerin .1 · out 203.0.113.5InternetWeb server198.51.100.20
  1. 1. Inside: the laptop sends from its private address. Nothing has changed yet.
  2. 2. At the edge: the router swaps the private source for its public address 203.0.113.5 and writes the swap in its translation table.
  3. 3. Outside: the internet only ever sees the router's public address.
  4. 4. Return: the reply comes back to 203.0.113.5. The router looks up the table and swaps the destination back to 192.168.1.10.
  5. 5. Shared: both devices browse at once, both appearing as 203.0.113.5. Ports keep them apart (PAT).

The important parts

Inside and outside interfaces

The router must know which side is private and which is public, so it knows which direction to translate.

Translation table

The router's memory of every active swap: which inside address and port belongs to which public address and port. Replies are matched against it.

Public address (or pool)

The address the inside devices appear as. Home routers use the one address the ISP gives the WAN port.

Timeouts

Entries are deleted after a period of no traffic (seconds for DNS, minutes or hours for TCP). Otherwise the table would fill up.

There are three classic kinds of NAT:

Static NAT

One to one, permanent

One private address is always swapped for the same public address. Used so a server inside can be reached from outside.

Dynamic NAT

One to one, from a pool

Inside devices borrow a public address from a pool while they need it. If the pool runs out, the next device must wait.

PAT (NAT overload)

Many to one, using ports

Every inside device shares one public address. Port numbers keep the conversations apart. This is what nearly every home and office uses.

Source NAT, step by step

Start with the simplest case: one laptop opens a website. Changing the source address of outgoing traffic is called source NAT. The laptop is 192.168.1.10, the router's public address is 203.0.113.5, and the web server is 198.51.100.20 on HTTPS port 443.

  1. The laptop builds a packet from 192.168.1.10 (port 50001, an ephemeral port) to 198.51.100.20 port 443. The server is on another network, so the laptop sends the frame to its default gateway's MAC address.
  2. The router receives it on the inside interface and decides to send it out of the outside interface toward the ISP.
  3. The router translates. It replaces the source address 192.168.1.10 with 203.0.113.5, and fixes the IP and TCP checksums so the packet is still valid.
  4. The router remembers. It adds an entry to its translation table: inside 192.168.1.10:50001 ↔ outside 203.0.113.5:50001, talking to 198.51.100.20:443.
  5. The packet crosses the internet with a public source address, so every router can route the reply.
  6. The server replies to 203.0.113.5. It has no idea a private address was ever involved.
Leaving the laptop
On the home LAN
Source IP
192.168.1.10
Source port
50001
Destination IP
198.51.100.20
Destination port
443
Leaving the router
On the internet
Source IP
203.0.113.5 (rewritten)
Source port
50001
Destination IP
198.51.100.20
Destination port
443

Highlighted fields were rewritten by the router.

Outbound: source NAT replaces only the private source address. The destination is untouched.

The translation table

After that first packet, the router's table holds one row:

ProtocolInside (private)Outside (public)Remote server
TCP192.168.1.10:50001203.0.113.5:50001198.51.100.20:443

💡 Cisco uses special names for these columns: inside local (the private address), inside global (the public address it becomes), and outside local / outside global for the remote server. You don't need these names to understand NAT; they are explained in the CCNA-track lesson Inside local, inside global and friends.

PAT: many devices, one public address

With plain one-to-one NAT, two inside devices would need two public addresses. Most homes only have one. PAT solves this by using the source port as well. Each conversation gets its own public port number, and the router uses that number to tell the conversations apart.

Now the laptop and the PC both open the same website. By chance, both picked source port 50001:

  1. The laptop's packet arrives first. Public port 50001 is free, so the router keeps it: 192.168.1.10:50001 → 203.0.113.5:50001.
  2. The PC's packet arrives from 192.168.1.11:50001. Public port 50001 toward that server is already taken, so the router changes the source port too, for example to 50002: 192.168.1.11:50001 → 203.0.113.5:50002.
  3. Both packets leave with the same public source address, but with different source ports.
  4. When replies arrive, the destination port (50001 or 50002) tells the router which inside device each one belongs to.
PC's packet, inside
On the home LAN
Source IP
192.168.1.11
Source port
50001
Destination IP
198.51.100.20
Destination port
443
PC's packet, outside
On the internet
Source IP
203.0.113.5 (rewritten)
Source port
50002 (rewritten)
Destination IP
198.51.100.20
Destination port
443

Highlighted fields were rewritten by the router.

PAT: the source port is changed too when it would clash with a conversation already in the table.
ProtocolInside (private)Outside (public)Remote server
TCP192.168.1.10:50001203.0.113.5:50001198.51.100.20:443
TCP192.168.1.11:50001203.0.113.5:50002198.51.100.20:443
UDP192.168.1.11:61000203.0.113.5:61000198.51.100.53:53 (DNS)

Every row is unique on the outside, so every reply can be matched to exactly one inside device. A single public address has about 65,000 ports for TCP and as many again for UDP, which is plenty for a home or small office. ICMP messages such as ping have no ports, so PAT uses the ICMP query identifier in the same way.

💡 In simple terms: PAT is like a company with one phone number and many extensions. Callers outside only ever see the main number; the extension (the port) decides whose desk the call reaches.

The return path

Replies are where the translation table earns its keep. When a packet arrives on the outside interface, the router:

  1. Reads the destination address and port: 203.0.113.5:50002.
  2. Looks for a table entry that matches (and that came from this remote server).
  3. Finds 192.168.1.11:50001 and rewrites the destination address and port to those values.
  4. Forwards the packet onto the LAN, using ARP to find the PC's MAC address.
Reply on the internet
Arriving at the router
Source IP
198.51.100.20
Source port
443
Destination IP
203.0.113.5
Destination port
50002
Reply on the LAN
Delivered to the PC
Source IP
198.51.100.20
Source port
443
Destination IP
192.168.1.11 (rewritten)
Destination port
50001 (rewritten)

Highlighted fields were rewritten by the router.

Inbound: the router undoes the swap, this time on the destination fields.
Step 1 of 4 · SYN
PAT on the edge · one public address
PC
192.168.1.11
Home router
203.0.113.5
Web server
198.51.100.20
The start of a TCP connection through PAT. Every later packet of this connection uses the same table entry.

Why unsolicited inbound traffic fails

Now imagine a computer on the internet sends a packet to 203.0.113.5 port 3389 without anyone inside asking for it. The router looks in its table and finds nothing for port 3389. It has no idea which inside device, if any, should receive it, so it drops the packet.

Laptop192.168.1.10PC192.168.1.11Home routerin .1 · out 203.0.113.5InternetUnknown host192.0.2.99
  1. 1. Unsolicited: a packet arrives for 203.0.113.5 port 3389. Nobody inside started this conversation.
  2. 2. Dropped: no translation table entry matches, so the router cannot know which device it is for. The packet goes nowhere.

This is why people say NAT "hides" inside devices. It is a useful side effect, but it is not a security feature you should rely on by itself: the real protection comes from the firewall that runs on the same router. It is also why running a game server or a camera that must be reached from outside needs extra setup.

Destination NAT and port forwarding

Sometimes you want outside devices to reach something inside, such as a web server or a home security camera. The fix is a permanent rule that changes the destination address of incoming traffic. This is destination NAT; on a home router it is called port forwarding.

Example rule: "send anything arriving on TCP port 443 of my public address to 192.168.1.50 port 443".

Arriving from the internet
Outside interface
Source IP
192.0.2.99
Source port
53122
Destination IP
203.0.113.5
Destination port
443
Forwarded inside
To the home server
Source IP
192.0.2.99
Source port
53122
Destination IP
192.168.1.50 (rewritten)
Destination port
443

Highlighted fields were rewritten by the router.

Port forwarding: a fixed rule rewrites the destination, so a connection started outside can reach one inside server.
  • The inside server needs a fixed address (a static IP or a DHCP reservation). If its address changes, the rule points at nothing.
  • One public port can be forwarded to only one inside device. Two web servers can't both have port 443 on one public address.
  • Anything you forward is exposed to the whole internet. Forward only what you must, and keep that device patched.

CGNAT: NAT at the ISP

IPv4 addresses are now so scarce that many internet providers, especially mobile networks, don't give each customer a public address at all. Instead they run carrier-grade NAT (CGNAT): one big PAT device in the ISP's network shared by many customers. Your home router's WAN side gets an address from the shared range 100.64.0.0/10 (set aside for this purpose by RFC 6598), and the ISP translates again on the way to the internet.

Laptop192.168.1.10Home routerWAN 100.64.12.34ISP CGNAT203.0.113.200Web server198.51.100.20
  1. 1. First NAT: the home router swaps the private address for its WAN address 100.64.12.34.
  2. 2. Second NAT: the ISP's CGNAT device swaps that for a real public address, shared with many other customers.
  3. 3. Outside: the website sees 203.0.113.200, not your router's WAN address.

You can spot CGNAT yourself: if your router's WAN address starts with 100.64 to 100.127, or it doesn't match what What Is My IP shows, you are behind CGNAT. The big downside: port forwarding on your own router can't work, because the ISP's NAT drops the unsolicited traffic before it ever reaches you.

A real-world example

Open What Is My IP on your laptop and on your phone while both are on your home Wi-Fi. Both show the same public address. Then check each device's own address (ipconfig on Windows, Settings → Wi-Fi on a phone): each has a different private 192.168.x.x address. The difference between the two is NAT at work.

Example output from a Windows PC, written for this lesson
C:\> ipconfig
Wireless LAN adapter Wi-Fi:

   Connection-specific DNS Suffix  . : home
   IPv4 Address. . . . . . . . . . . : 192.168.1.10
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.1
The laptop only knows its private address. The public address (here 203.0.113.5) exists only on the router, so you have to ask an outside service to see it.

What happens when NAT fails

SymptomLikely cause
Outbound browsing works, but nobody outside can reach your server or gameNormal NAT behaviour: no port forward, wrong inside address in the rule, or CGNAT at the ISP
Port forward set up, but still unreachableThe inside device's address changed, its own firewall blocks the port, or you are behind CGNAT
New connections fail on a busy network, old ones keep workingThe translation table or the pool of public ports is full
Long idle connections (SSH, games) drop after a whileThe NAT entry timed out because no traffic passed; the next packet has no matching entry
Some apps (voice calls, old FTP) connect but audio or data failsThe app writes IP addresses inside its data, which NAT doesn't rewrite unless the router has a helper for that app
Nothing reaches the internet, but the LAN worksThe router has no public address from the ISP, or NAT is not enabled on the outside interface

Troubleshooting NAT

  1. Check the inside first. Can the device reach its default gateway? If not, NAT isn't the problem yet (see IP and gateway problems).
  2. Compare addresses. Your device's private address (ipconfig / ip addr), the router's WAN address (on its status page) and your public address (What Is My IP). Three different values in three ranges tell you a lot.
  3. Look for double NAT. A traceroute whose first two hops are both private or 100.64.x.x addresses shows two NAT layers.
  4. For port forwarding, test from outside. Testing from inside your own network often fails even when the rule works. Use the Port Checker tool.
Example output from a Windows PC, written for this lesson
C:\> tracert -d 198.51.100.20
Tracing route to 198.51.100.20 over a maximum of 30 hops

  1     2 ms     1 ms     1 ms  192.168.1.1
  2     9 ms     8 ms     9 ms  100.64.0.1
  3    12 ms    11 ms    12 ms  203.0.113.1
  4    14 ms    13 ms    14 ms  198.51.100.20

Trace complete.
Hop 1 is the home router. Hop 2 is in the 100.64.0.0/10 shared range, a strong hint that the ISP runs CGNAT. Read more about this output in Traceroute.

Common mistakes

  • Thinking NAT is a firewall. It blocks unsolicited inbound traffic as a side effect, but it doesn't inspect or filter anything on purpose.
  • Mixing up the directions. Outgoing traffic gets its source rewritten; replies get their destination rewritten. Port forwarding rewrites the destination of traffic started outside.
  • Forwarding to a device that uses DHCP without a reservation. After a reboot it may get a new address and the rule breaks.
  • Assuming your public IP belongs only to you. With CGNAT, many customers share it.
  • Expecting the PC to know its public address. Only the router (or the ISP) knows it.
✅ Key takeaways
  • NAT rewrites IP addresses at the network edge, usually private source → public on the way out.
  • PAT also rewrites ports, so many inside devices share one public address.
  • The translation table remembers every swap so replies can be swapped back.
  • Traffic from outside with no matching entry is dropped, unless a port forward (destination NAT) rule exists.
  • CGNAT adds a second NAT at the ISP and stops port forwarding from working.

Check yourself

Predict · scenario 1

A laptop at 192.168.1.10 sends a packet to a web server through a PAT router whose public address is 203.0.113.5. What source address does the web server see?

Predict · scenario 2

Two inside PCs both use source port 50001 to talk to the same server. How does the PAT router keep them apart?

Predict · scenario 3

A friend on the internet tries to connect to your public address on port 25565 to join your game server. You have no port forwarding set up. What happens?

Predict · scenario 4

Your router's WAN address is 100.72.18.4 and port forwarding doesn't work even though the rule is correct. Why?

Going further (CCNA)

This lesson explains how NAT behaves. Configuring it on Cisco routers is CCNA material, covered in the NAT configuration lessons: Inside local, inside global and friends, Static NAT, Dynamic NAT, PAT (NAT overload) and Verifying and troubleshooting NAT.

Next, see NAT as one step in a full journey in What happens when you open a website?, and compare it with the job of a firewall.

FAQ

What is the difference between NAT and PAT?
Basic NAT swaps one IP address for another, one to one. PAT (Port Address Translation, also called NAT overload) also changes port numbers, so many inside devices can share a single public IP address at the same time. When people say "NAT" about a home router, they almost always mean PAT.
Is NAT a firewall?
Not really, although it has a similar side effect. Because the router only knows where to send replies to conversations started from inside, unsolicited traffic from the internet is dropped. But NAT was built to save addresses, not to enforce security rules. Real protection comes from a firewall, which is usually built into the same router.
How many devices can share one public IP with PAT?
In theory, a public address has about 65,000 port numbers per transport protocol, and each connection uses one. In practice a home or small office never gets close. Large networks and ISPs using CGNAT do have to plan for it, and give each customer a block of ports.
Does IPv6 need NAT?
Normally not. IPv6 has so many addresses that every device can have its own public, globally unique address. Security comes from a firewall that blocks unsolicited inbound traffic, which gives the same protection people associate with NAT, without rewriting addresses.