A small office with one public address
A small office has twenty computers, a printer and a web server. The ISP (Internet Service Provider, the company that sells the internet link) gives the office just one public address: 203.0.113.2. Yet every computer can browse the web at the same time. How?
Private and public addresses
A public address is unique on the whole internet. Only one device in the world uses it, so routers everywhere know where to send it. A private address is free for anyone to use inside their own network. RFC 1918 (the standard that set them aside) reserves three ranges:
| Private range | Prefix | Typical use |
|---|---|---|
10.0.0.0 – 10.255.255.255 | /8 | Large companies |
172.16.0.0 – 172.31.255.255 | /12 | Medium networks |
192.168.0.0 – 192.168.255.255 | /16 | Homes and small offices |
Thousands of homes use 192.168.10.11 at this moment. So internet routers refuse to route private addresses at all. If a packet left the office with a private source address, the reply would have no way to find its way back.
Why NAT was needed
IPv4 has about 4.3 billion addresses. That sounded like plenty in the 1980s, but today there are far more phones, laptops and smart devices than that. The regional registries that hand out addresses ran out of free IPv4 blocks years ago. The long-term fix is IPv6. The short-term fix, still used almost everywhere, is to give each site a few public addresses and use private addresses inside.
NAT (Network Address Translation) makes that work. A router at the edge of the network, the point where the office meets the ISP, rewrites the address in each packet:
- Going out: it swaps the private source address for a public one.
- Coming back: it swaps the public destination address back to the private one.
To do the second step, the router has to remember each swap. It keeps them in a translation table.
- 1. Inside, nothing changes. PC1 sends to 198.51.100.10 from its private address. The switch and R1's inside port see it as normal.
- 2. R1 translates and remembers. It changes the source to 203.0.113.2 and adds a row to its translation table: 192.168.10.11 ↔ 203.0.113.2.
- 3. The internet only sees the public address. The ISP can route it, and the server replies to 203.0.113.2.
- 4. R1 swaps it back. It looks up the table, changes the destination to 192.168.10.11 and sends the reply inside.
Why this works so well
- It saves addresses. One public address can serve hundreds of devices (the “PAT (NAT overload)” lesson shows how).
- Inside addresses can stay the same. If the office changes ISP, only R1's public side changes. No PC needs a new address.
- Only the edge router does the work. PCs don't know NAT is happening. The server on the internet doesn't either.
💡 In simple terms: NAT is like an office front desk. Every letter going out shows the office address, not the person's desk number. The front desk keeps a list of who sent what, so replies still reach the right desk.
NAT has costs too. The router must track every conversation, and devices on the internet can't start a connection to an inside device unless you set that up (the “Static NAT” lesson).
How to see it
At home, open What Is My IP on two devices on the same Wi-Fi. Both show the same public address, even though each has its own private address. That shared address is NAT at work.
On a Cisco router, the translation table shows each swap. This output is based on Cisco documentation, not run on a lab device.
R1#show ip nat translations Pro Inside global Inside local Outside local Outside global icmp 203.0.113.2:3 192.168.10.11:3 198.51.100.10:3 198.51.100.10:3 Total number of translations: 1
192.168.10.11, "inside local") is seen on the internet as 203.0.113.2 ("inside global"). The next lesson explains all four column names.Check yourself
Why can't a packet with source 192.168.10.11 be sent across the internet as it is?
Where does NAT usually happen?
What does the router use to send a reply back to the right inside device?