NAT and PAT explained: inside, outside and overload
Short answer
NAT (Network Address Translation) rewrites the private source address of a packet leaving the network into a public one, and reverses the change for the reply. PAT (port address translation, or NAT overload) goes further: it maps many inside hosts to one public address by giving each conversation its own source port.
Network Address Translation rewrites private source addresses into public ones at the network edge. This lesson explains inside and outside, the three kinds of NAT, how PAT lets a whole office share one public address, and how to read the translation table.
Open this labWhy NAT exists
The private ranges — 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 — can be reused by every organisation, which is exactly why the public internet will not route them. A packet that leaves with a private source address cannot get a reply. NAT at the edge router swaps that source for a public address the internet can answer.
The three kinds
| Type | Mapping | Typical use |
|---|---|---|
| Static NAT | One private address ↔ one public address, permanently | A server inside that must be reachable from outside |
| Dynamic NAT | Private addresses ↔ a pool of public addresses, first come first served | Rare today; needs as many public addresses as concurrent hosts |
| PAT (overload) | Many private addresses ↔ one public address, told apart by port | Almost every office and home router |
Configure PAT on the edge router
Mark which interfaces face the inside and which faces the outside, say which inside addresses may be translated (an access list), and translate them to the outside interface's address with overload:
Edge(config)# interface Gi0/0
Edge(config-if)# ip nat inside
Edge(config-if)# exit
Edge(config)# interface Se0/0/0
Edge(config-if)# ip nat outside
Edge(config-if)# exit
Edge(config)# access-list 1 permit 192.168.10.0 0.0.0.255
Edge(config)# ip nat inside source list 1 interface Se0/0/0 overloadReading the translation table
show ip nat translations lists each active translation: the inside local address (the host's real private address and port), the inside global address it was translated to (the public address and port), and the outside address it is talking to. With PAT you will see the same inside global address repeated with different ports — one per conversation.
Common questions
- What is the difference between NAT and PAT?
- NAT maps addresses one to one (or from a pool). PAT maps many inside addresses to a single public address and tells the conversations apart by source port.
- What do ip nat inside and ip nat outside do?
- They mark which side of the router each interface is on, so the router knows which direction to translate. A missing or swapped marking is the most common NAT mistake.
- Why can't my private network reach the internet without NAT?
- Private ranges are not routed on the public internet, so replies to a private source address have nowhere to go.
- What does overload mean in a NAT command?
- It turns on port address translation, letting many inside hosts share the one public address.
Practice this in the lab
Reading helps. Wiring it up yourself and breaking it makes it stick.
Open the lab