Network Implementation 20% Lesson 3 of 14

Lesson 2.1.3 — NAT and PAT for Address Translation

Avatar Of Asad IjazAsad Ijaz ·Sep 17, 2026 ·7 min read
21% through domain
Illustration Of Many Colored Dots Converging Through A Funnel Into One Bright Dot, Each Tagged With A Port Number

Domain 2.0 | Network Implementation — 20% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain the purpose of Network Address Translation (NAT) and why private networks rely on it
  • Distinguish static NAT, dynamic NAT, and PAT (NAT overload)
  • Identify the four NAT address types: inside local, inside global, outside local, and outside global
  • Explain how PAT uses port numbers to let many private hosts share a single public IP address
  • Recognize common NAT/PAT limitations and how they show up in troubleshooting

Key Terms

TermDefinition
NAT (Network Address Translation)The process of translating private IP addresses to public IP addresses (and back) as traffic crosses a network boundary
PAT (Port Address Translation)A form of NAT, also called NAT overload, that maps many private addresses to one public address by tracking unique source port numbers
Static NATA permanent, one-to-one mapping between a single private address and a single public address
Dynamic NATA one-to-one mapping drawn from a pool of public addresses, assigned on a first-come basis rather than fixed per host
Inside Local AddressA private address as seen on the inside (private) network
Inside Global AddressThe public address that an inside local address is translated to, as seen on the outside (public) network

Explanation

Why Address Translation Exists

Lesson 1.7.1 covered the private IPv4 ranges — 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 — and mentioned that these addresses aren’t routable on the public internet. That fact only matters because of NAT. Without address translation, a device using a private address would have no way to reach anything outside its own network, because internet routers simply discard packets sourced from or destined to private address space.

NAT solves this by translating a private address into a public one at the network boundary — typically a router or firewall sitting at the edge of the network — and translating the reply back on the way in. It’s the reason an entire household or an entire office building can share a single public IP address from an ISP, and it’s a big part of why IPv4 has survived as long as it has despite running out of new address blocks years ago.

Static NAT: One-to-One Mapping

Static NAT creates a permanent, fixed mapping between one private address and one public address. Every time that private host sends traffic out, it always gets translated to the same public address, and anyone on the internet wanting to reach that specific internal host always uses that same public address to get to it.

HQ-RTR(config)# ip nat inside source static 192.168.1.10 203.0.113.10

Static NAT is the right tool when something on the inside needs to be consistently reachable from the outside — a mail server or a web server, for example — because the mapping never changes.

Dynamic NAT: Pool-Based Translation

Dynamic NAT also creates one-to-one mappings, but instead of a fixed pairing, it draws from a pool of available public addresses and assigns them as needed. If a company owns a small block of public addresses but has more internal hosts than public addresses to permanently assign, dynamic NAT lets those hosts share the pool — whichever public address is free gets handed out next.

The catch: if every address in the pool is already in use, the next host requesting translation simply can’t get out until one frees up. Dynamic NAT scales only as far as the pool does, which is exactly the limitation that made PAT so much more popular in practice.

PAT (NAT Overload): Many-to-One via Port Numbers

PAT (Port Address Translation), also called NAT overload, is what almost every home router and small office network actually runs. Instead of needing one public address per internal host, PAT lets an entire network share a single public address by tracking connections using port numbers.

Here’s the mechanism: every outbound connection gets assigned a unique source port on the shared public address. The router keeps a translation table mapping each internal host’s private address and original source port to a specific public source port. When a reply comes back addressed to that public port, the router checks its table and forwards the reply to the correct internal host.

BR-RTR# show ip nat translations
Pro  Inside global          Inside local           Outside local          Outside global
tcp  203.0.113.5:51422      192.168.1.10:52011     93.184.216.34:443      93.184.216.34:443
tcp  203.0.113.5:51423      192.168.1.11:49882     93.184.216.34:443      93.184.216.34:443

Notice both internal hosts (192.168.1.10 and 192.168.1.11) are sharing the exact same public address (203.0.113.5) — the router tells them apart purely by which port each connection was assigned. This is the same port-number concept covered back in Lesson 1.4.1, just applied to distinguishing internal hosts instead of identifying a destination service.

Diagram Showing Two Internal Hosts Sharing One Public Ip Address, Distinguished By Unique Port Numbers Under Pat
How Pat Uses Unique Port Numbers To Let Multiple Hosts Share One Public Ip

How PAT Uses Unique Port Numbers To Let Multiple Hosts Share One Public IP

Because a single public address has roughly 65,000 usable ports available, PAT can support tens of thousands of simultaneous connections from a single public IP — which is exactly why it’s the default NAT mode on virtually every consumer router and most enterprise edge devices.

NAT Terminology: The Four Address Types

The exam likes to test precise NAT terminology, and it trips people up because the names all sound similar. There are four categories, and the “local vs. global” distinction always means “as seen from inside the private network” vs. “as seen from outside on the public internet”:

TermMeaning
Inside LocalThe private address of an inside host, as it appears on the inside network
Inside GlobalThe translated public address of that same inside host, as it appears to the outside world
Outside LocalThe address of an outside (internet) host, as it appears from the inside network’s perspective
Outside GlobalThe actual, real public address of that outside host

In the overwhelming majority of real deployments, outside local and outside global are identical — internet hosts almost never get translated themselves. It’s the inside local and inside global pairing that does virtually all the work in a typical NAT setup.

Diagram Showing Inside Local, Inside Global, Outside Local, And Outside Global Address Types Relative To The Nat Boundary
Where Each Of The Four Nat Address Types Sits Relative To The Private And Public Network

Where Each Of The Four NAT Address Types Sits Relative To The Private And Public Network

Where NAT Fits With Routing

NAT typically runs on the exact same edge router covered in the last two lessons. That router might be running OSPF or EIGRP internally to learn about all the private subnets in the organization, running BGP or a static default route to reach the internet, and performing PAT on every packet that crosses from the inside interface to the outside interface — three completely different jobs, running on one device, in sequence, for every single packet leaving the network.

That ordering matters conceptually: the router first has to know where to send a packet (routing), and separately has to decide what address to translate it to (NAT) as it crosses the inside-to-outside boundary. Getting the direction of translation backwards — translating on the wrong interface, or applying an inside NAT rule to outside-sourced traffic — is one of the most common real-world NAT misconfigurations.

Diagram Showing A Single Edge Router Performing Routing, Nat/Pat Translation, And Default Route Forwarding Together
How Routing And Nat/Pat Work Together On A Single Edge Router

How Routing And NAT/PAT Work Together On A Single Edge Router

Limitations of NAT

NAT solves the address-exhaustion problem, but it isn’t free of downsides:

  • Breaks end-to-end connectivity assumptions. Some protocols embed IP addresses inside their payload (not just the packet header), and NAT doesn’t know to rewrite those — this is part of why certain VoIP and VPN protocols need special NAT-aware handling.
  • Complicates inbound connections. An outside host generally can’t initiate a connection to an inside host unless a static NAT mapping or port forward rule specifically allows it, since there’s no existing translation table entry for unsolicited inbound traffic.
  • Adds a layer of state the router must track. Every active PAT translation consumes a small amount of router memory; a router under a denial-of-service style connection flood can exhaust its translation table.

None of this is a reason to avoid NAT — it remains essential in nearly every IPv4 network — but it’s exactly why IPv6, with its enormous address space, was designed without requiring NAT at all, even though NAT-like techniques do still show up in some IPv6 deployments for other reasons.

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • A show ip nat translations table where multiple inside local addresses map to one inside global address, distinguished only by port number, is PAT/NAT overload in action.
  • A single, unchanging private-to-public address pairing is static NAT — typically applied to a server that needs to be consistently reachable from outside.
  • Outside local and outside global addresses being identical in a translation table is the normal case, not an error.
  • An inbound connection from the internet failing to reach an internal host, with no static NAT or port forward configured, is expected NAT behavior, not a bug.

Common Exam Traps

  • NAT and PAT are not the same thing at the same scale. Static and dynamic NAT are one-to-one; PAT is many-to-one via port numbers. Don’t treat “NAT” as always meaning “one public IP for the whole network” — that specific behavior is PAT.
  • “Local” always means the private-network perspective; “global” always means the public-network perspective. Applying this consistently resolves most inside/outside local/global confusion.
  • Outside local and outside global are usually identical. The exam sometimes tests whether you know this pairing is the exception to “translation happens on both sides.”
  • PAT relies on port numbers, not IP addresses, to distinguish hosts sharing one public address. Confusing this with dynamic NAT (which still assigns distinct IP addresses from a pool) is a frequent mistake.
  • Unsolicited inbound connections don’t work through PAT without an explicit rule. This is expected behavior, not a misconfiguration, unless a specific service needs to be reachable from outside.

Lesson 2.1.3 Practice Quiz — NAT and PAT for Address Translation

17 questions covering static NAT, dynamic NAT, PAT/NAT overload, the four NAT address types, and NAT troubleshooting.

N10-009 · Domain 2.1
Question 1Plain
What is the primary purpose of NAT?
NAT translates non-routable private addresses to routable public addresses (and back) as traffic crosses the network boundary, allowing private networks to reach the internet.
Question 2Plain
Which NAT type creates a permanent, fixed one-to-one mapping between a single private address and a single public address?
Static NAT creates a permanent, unchanging one-to-one mapping — ideal for hosts like servers that need to be consistently reachable at the same public address.
Question 3Plain
What does PAT use to distinguish multiple internal hosts sharing a single public IP address?
PAT (NAT overload) assigns each outbound connection a unique source port on the shared public address, using the port to tell hosts apart.
Question 4Choose Two
Which two statements about PAT are correct? (Choose two.)
PAT is many-to-one, using unique port numbers to distinguish hosts sharing the single public address — that's exactly what lets it avoid needing one public address per host.
Question 5Choose Two
Which two statements about dynamic NAT are correct? (Choose two.)
Dynamic NAT is pool-based and one-to-one — a host gets a distinct public IP from the pool, not a shared one distinguished by port. It's limited by pool size, and port-based distinction is PAT's job, not dynamic NAT's.
Question 6Choose Two
Which two NAT address types are typically identical in a standard deployment? (Choose two.)
Outside local and outside global are usually identical, since internet hosts are almost never themselves translated. Inside local and inside global, by contrast, are normally different — that's the pairing doing the actual translation work.
Question 7Scenario
A company runs an internal mail server that must always be reachable from the internet at the exact same public IP address. Which NAT type fits this need?
A server that must always be reachable at a fixed, unchanging public address needs a permanent one-to-one mapping — static NAT.
Question 8Scenario
A small office owns a block of 10 public IP addresses but has 40 internal hosts, only some of which are active at any given time. Each active host should get its own distinct public IP, drawn from the block as needed. Which NAT type fits this need?
Dynamic NAT draws one-to-one mappings from a pool of public addresses, assigning them to active hosts as needed — exactly this scenario.
Question 9Scenario
A home router has a single public IP assigned by the ISP but needs to let a laptop, a phone, and a smart TV all browse the internet simultaneously. Which NAT type makes this possible?
PAT (NAT overload) is exactly what lets many devices share one public IP simultaneously, distinguished by port number — the default mode on virtually every home router.
Question 10Scenario
An external host on the internet attempts to initiate a connection to an internal server, but no static NAT mapping or port forward has been configured for that server. What happens?
Without an existing translation table entry or an explicit static mapping/port forward, there's no way for the router to know which internal host an unsolicited inbound connection is meant for — this is expected behavior, not a bug.
Question 11Scenario
An administrator configures a NAT rule but mistakenly applies the "inside" designation to the router's outside-facing (internet) interface instead of the internal interface. What is the most likely result?
NAT relies entirely on correct inside/outside interface designation to know which direction to translate traffic. Misapplying it is one of the most common real-world NAT misconfigurations.
Question 12Exhibit
Based on this translation table, what NAT type is in use?
Pro Inside global Inside local Outside local Outside global tcp 203.0.113.5:51422 192.168.1.10:52011 93.184.216.34:443 93.184.216.34:443 tcp 203.0.113.5:51423 192.168.1.11:49882 93.184.216.34:443 93.184.216.34:443
Both 192.168.1.10 and 192.168.1.11 are translated to the same inside global address (203.0.113.5), distinguished only by their assigned ports (51422 vs. 51423) — this is PAT.
Question 13Exhibit
Which NAT type does this configuration line represent?
HQ-RTR(config)# ip nat inside source static 192.168.1.10 203.0.113.10
The keyword "static" plus a single fixed private-to-public address pairing identifies this as a static NAT configuration.
Question 14Exhibit
Based on this configuration, what NAT behavior should the administrator expect?
HQ-RTR(config)# ip nat pool PUBLIC-POOL 203.0.113.20 203.0.113.29 netmask 255.255.255.0 HQ-RTR(config)# ip nat inside source list 10 pool PUBLIC-POOL
This is a dynamic NAT pool spanning 10 addresses (.20 through .29). Up to 10 hosts get their own distinct public address at a time; an 11th host must wait until one frees up.
Question 15Exhibit
In this translation table entry, what does the fact that Outside Local and Outside Global are identical indicate?
Pro Inside global Inside local Outside local Outside global tcp 203.0.113.5:51422 192.168.1.10:52011 93.184.216.34:443 93.184.216.34:443
Outside local and outside global being identical is the normal case — internet-side hosts are almost never translated themselves, so both columns show the same real public address.
Question 16Exhibit
A router's log shows the following message. What is the most likely cause?
%NAT-3-POOL_EXHAUSTED: All addresses in pool PUBLIC-POOL are in use. New translation request from 192.168.1.55 denied.
This log message is specific to dynamic NAT: every address in the pool is currently assigned, so a new host requesting translation is denied until one frees up — exactly the scaling limitation dynamic NAT has that PAT avoids.
Question 17Exhibit
Given this translation table entry, which value is the actual mechanism the router uses to route a returning reply packet to the correct internal host?
Pro Inside global Inside local tcp 203.0.113.5:51422 192.168.1.10:52011
A reply arrives addressed to 203.0.113.5 on port 51422. The router looks up that specific port in its translation table to determine the reply belongs to 192.168.1.10, and forwards it accordingly — this port-based lookup is the core PAT mechanism.
📝

Summary

NAT translates private, non-routable IP addresses to public addresses at the network boundary, allowing private networks to reach the internet.

Static NAT creates a permanent one-to-one mapping; dynamic NAT draws one-to-one mappings from a pool; PAT (NAT overload) lets many hosts share one public address using unique port numbers.

The four NAT address types are inside local, inside global, outside local, and outside global — "local" is the private-side view, "global" is the public-side view.

PAT is the default mode on almost all consumer and small-office routers because a single public address can support tens of thousands of simultaneous port-based translations.

NAT and routing typically run on the same edge device but perform distinct jobs: routing decides where a packet goes, NAT decides what address it wears when it gets there.

NAT's limitations — broken end-to-end addressing assumptions, blocked unsolicited inbound connections, and translation table state — are part of why IPv6 was designed without requiring it.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.