ZNetLab › Published › Question
NAT is configured but show ip nat translations is empty
Branch router, one inside network, one internet link. Hosts cannot reach anything outside. Configuration:
access-list 1 permit 192.168.1.0 0.0.0.255
ip nat inside source list 1 interface GigabitEthernet0/1 overload
!
interface GigabitEthernet0/0
ip address 192.168.1.1 255.255.255.0
ip nat inside
!
interface GigabitEthernet0/1
ip address 203.0.113.5 255.255.255.252
show ip nat translations is empty. The default route is there and the
router itself can ping 8.8.8.8.
1 answer
@admin · 2026-10-09
ip nat outside is missing from GigabitEthernet0/1.
NAT only translates traffic that crosses from an interface marked inside to
one marked outside. With only the inside marked, there is no boundary, so
no translation is ever created — and because nothing fails loudly, everything
in the configuration looks correct. It is the single most common reason
show ip nat translations comes back empty.
R1(config)# interface GigabitEthernet0/1
R1(config-if)# ip nat outside
The router itself being able to ping out is the clue that it is not a routing problem: traffic the router originates leaves with the interface's own address and needs no translation at all.
Worth noting for later: the ACL is right as written. It is a wildcard
mask — 0.0.0.255, not 255.255.255.0 — which is the other thing that
produces exactly this symptom.
Can you answer this?
Replies, likes and bookmarks live in the community half, which needs a free account. Writing here is free too, and everything is reviewed before it is published.
Open this in the communityEverything publishedHow this works