CCNA NAT and PAT

NAT is how private networks talk to the public internet — and the CCNA 200-301 exam probes both the vocabulary and the configuration. This CCNA NAT and PAT guide covers NAT terminology and the order of operations, then static NAT, dynamic NAT and PAT configuration. Test your understanding afterwards with our free CCNA mock test.

NAT Terminology and Order of Operations

NAT vocabulary is the price of admission — the exam defines scenarios in these exact terms. Inside local: the private address as the host knows it (e.g. 192.168.1.10). Inside global: the public address representing it on the internet (what the world sees). Outside local / outside global mirror the concept for the far end (usually identical, differing only with destination NAT). A simple mnemonic: local = as seen on the local network, global = as seen on the internet.

The three flavours: static NAT is a permanent 1:1 mapping (great for publishing an internal server); dynamic NAT maps inside addresses to a pool of public addresses on demand; PAT (overload) maps many inside addresses to one public address, distinguished by port numbers — this is the normal home/SOHO setup and the exam's default assumption when it says "NAT".

Order of operations decides which address routing sees, and the exam tests it. Inside-to-outside: routing happens first, then NAT — the router picks the exit interface using the inside local address, then translates. Outside-to-inside: NAT happens first, then routing — the destination is translated back before the routing decision. Get the direction wrong and you'll misdiagnose every NAT troubleshooting question. Mark interfaces with ip nat inside and ip nat outside — swapping them is the classic config error.

Key exam points

  • Inside local = private as the host knows it; inside global = public as the internet sees it.
  • Static = 1:1 permanent; dynamic = pool; PAT/overload = many-to-one via ports (the SOHO norm).
  • Inside→outside: routing first, then NAT. Outside→inside: NAT first, then routing.
  • Mark interfaces correctly: ip nat inside on the LAN side, ip nat outside toward the internet.

Configuring Static NAT, Dynamic NAT and PAT

Static NAT is one line: ip nat inside source static 192.168.1.10 203.0.113.5 — read it as "inside source 192.168.1.10 always appears as 203.0.113.5". Use it to publish internal servers (web, mail) to the internet, and pair it with an ACL permitting the traffic. Verify with show ip nat translations and show ip nat statistics.

Dynamic NAT needs an ACL to select inside hosts and a pool of public addresses:
ip nat pool PUBLIC 203.0.113.10 203.0.113.20 netmask 255.255.255.0
access-list 1 permit 192.168.1.0 0.0.0.255
ip nat inside source list 1 pool PUBLIC
PAT adds one word — overload: ip nat inside source list 1 interface g0/1 overload translates everyone to the interface's own public address. Overload is what makes one public IP serve a whole LAN, and it's the configuration the exam reaches for most.

Troubleshooting PAT follows the checklist: are inside/outside marked correctly? Does the ACL match the inside hosts (a wrong wildcard mask selects nobody)? Is the pool/interface address correct? show ip nat translations shows live mappings — an empty table with traffic flowing means the ACL or interface marking is wrong. For port forwarding to an internal server through PAT, use ip nat inside source static tcp 192.168.1.10 80 203.0.113.5 80.

Key exam points

  • Static: ip nat inside source static <inside> <outside> — for publishing servers.
  • Dynamic: ACL + ip nat pool + ip nat inside source list 1 pool <name>.
  • PAT: add overload — ip nat inside source list 1 interface <int> overload.
  • Empty translation table = check interface marking and the ACL's wildcard mask.

Related CCNA study guides

Frequently asked questions

What are the key CCNA exam points for NAT Terminology and Order of Operations?

For the CCNA 200-301 exam, remember: Inside local = private as the host knows it; inside global = public as the internet sees it. Static = 1:1 permanent; dynamic = pool; PAT/overload = many-to-one via ports (the SOHO norm). Inside→outside: routing first, then NAT. Outside→inside: NAT first, then routing. Mark interfaces correctly: ip nat inside on the LAN side, ip nat outside toward the internet.

What are the key CCNA exam points for Configuring Static NAT, Dynamic NAT and PAT?

For the CCNA 200-301 exam, remember: Static: ip nat inside source static <inside> <outside> — for publishing servers. Dynamic: ACL + ip nat pool + ip nat inside source list 1 pool <name>. PAT: add overload — ip nat inside source list 1 interface <int> overload. Empty translation table = check interface marking and the ACL's wildcard mask.

Which key detail about NAT Terminology and Order of Operations should you memorise for the CCNA 200-301 exam?

Static = 1:1 permanent; dynamic = pool; PAT/overload = many-to-one via ports (the SOHO norm).

Which key detail about Configuring Static NAT, Dynamic NAT and PAT should you memorise for the CCNA 200-301 exam?

Dynamic: ACL + ip nat pool + ip nat inside source list 1 pool <name>.

What is a common CCNA exam trap involving NAT Terminology and Order of Operations?

Inside→outside: routing first, then NAT. Outside→inside: NAT first, then routing.