ZNetLab › Published › Article

NAT overload: one address, a table, and how the reply finds its way home

ArticleRouting@admin2 min read

NAT overload: one address, a table, and how the reply finds its way home

PAT is not address translation with extra steps — it is a table keyed on the port, and knowing that explains every "works outbound, fails inbound" ticket.

A branch has thirty hosts on 192.168.1.0/24 and one public address. NAT overload — PAT — lets all thirty use it, and the thing that makes it work is not the address at all. It is the port.

What the router writes down

When an inside host opens a connection, the router rewrites the source address to its own public one and rewrites the source port to one it has not used. Then it records the four-tuple:

R1# show ip nat translations
Pro Inside global       Inside local       Outside local     Outside global
tcp 203.0.113.5:1034    192.168.1.10:49152 93.184.216.34:80  93.184.216.34:80
tcp 203.0.113.5:1035    192.168.1.11:52311 93.184.216.34:80  93.184.216.34:80

Two hosts, one public address, two different ports. The reply comes back to 203.0.113.5:1034, the router looks up that port, and only then does it know which inside host asked. The port is the key. The address carries no information at all — every row has the same one.

Which is why inbound does not work

Nothing outside has ever sent anything, so there is no row, so there is nothing to look up and the packet is dropped. That is not a bug or an ACL; it is the mechanism. If you want inbound, you have to write the row yourself:

R1(config)# ip nat inside source static tcp 192.168.1.20 80 203.0.113.5 80

The three lines that are always the problem

R1(config)# access-list 1 permit 192.168.1.0 0.0.0.255
R1(config)# ip nat inside source list 1 interface GigabitEthernet0/1 overload
R1(config)# interface GigabitEthernet0/0
R1(config-if)# ip nat inside
R1(config)# interface GigabitEthernet0/1
R1(config-if)# ip nat outside

Four things have to be true and people usually get three:

Miss the last one and show ip nat translations is empty while everything looks configured. The branch NAT lab in the simulator ships with exactly that missing, so you can see what the symptom looks like before you ever see it on a real box.

natpatccnasecurity

Join the discussion

Replies, likes and bookmarks live in the community half, which needs a free account. Writing here is free too, and everything is reviewed before it is published.

Open this in the communityEverything publishedHow this works