7.2 Network Address Translation: Static NAT, Dynamic NAT, and PAT/Overload
Key Takeaways
Cisco NAT terminology describes addresses from four perspectives: Inside Local (private host IP), Inside Global (public IP representing inside host), Outside Local (external IP viewed internally), and Outside Global (registered public destination IP).
Static NAT creates an immutable, bidirectional 1:1 address binding between an Inside Local and Inside Global address, permitting inbound session initiation for DMZ public services.
Dynamic NAT maps private inside hosts to an available pool of public IP addresses on demand; translations preserve port numbers but fail once the available pool is depleted.
Port Address Translation (PAT / NAT Overload) multiplexes tens of thousands of concurrent client sessions onto a single public IP address by tracking unique Layer 4 TCP and UDP port numbers.
IPsec Encapsulating Security Payload (ESP) lacks Layer 4 port numbers, preventing PAT multiplexing; NAT Traversal (NAT-T / RFC 3948) resolves this by encapsulating ESP inside UDP port 4500.
Network Address Translation: Static NAT, Dynamic NAT, and PAT/Overload
Network Address Translation (NAT), defined in RFC 2663, was introduced as an interim mechanism to slow IPv4 address exhaustion by enabling private IP networks (governed by RFC 1918) to communicate across the public Internet. Today, NAT remains an essential architectural component in enterprise edge routing, demilitarized zone (DMZ) security design, multi-tenant cloud segmentation, and business-to-business extranet integrations where overlapping address spaces collide.
Cisco NAT Address Terminology
Understanding NAT requires analyzing packets from two perspectives: the location of the host (Inside vs. Outside) and the perspective of the network viewing the address (Local vs. Global).
+------------------------------------+ +------------------------------------+
| INSIDE NETWORK (Private) | | OUTSIDE NETWORK (Public) |
| Inside Local Inside Global | ROUTER | Outside Local Outside Global |
| [10.10.1.50] --> [198.51.100.25] |==[NAT]==>| [203.0.113.10] <-- [203.0.113.10] |
+------------------------------------+ +------------------------------------+
The Four NAT Address Classifications
- Inside Local (IL): The IP address assigned to an internal host residing on the private enterprise network. This address is typically drawn from RFC 1918 private space (
10.0.0.0/8,172.16.0.0/12, or192.168.0.0/16) and is non-routable across the public Internet. - Inside Global (IG): The globally routable, public IPv4 address that represents the internal host to the external world. The NAT router translates the Inside Local source address into the Inside Global address on outbound transit.
- Outside Local (OL): The IP address of an external host as it appears to internal endpoints on the inside network. In standard NAT deployments, the Outside Local address is identical to the Outside Global address. However, in advanced scenarios involving outside NAT or overlapping subnets, the router rewrites the external destination IP to an internal local address.
- Outside Global (OG): The globally routable public IPv4 address assigned by the service provider or registered owner to the destination host on the outside network.
NAT Address Type Matrix
| Address Category | Physical Location | Network Perspective | Packet Direction & Header Modification | Concrete Enterprise Example |
|---|---|---|---|---|
| Inside Local (IL) | Inside Enterprise | Viewed from Inside | Source IP on outbound packet before translation | 10.10.1.50 (Internal Web App Server) |
| Inside Global (IG) | Inside Enterprise | Viewed from Outside | Source IP on outbound packet after translation | 198.51.100.25 (Public NAT Address) |
| Outside Local (OL) | Outside Internet | Viewed from Inside | Destination IP on outbound packet before translation | 203.0.113.10 (Cloud SaaS Endpoint) |
| Outside Global (OG) | Outside Internet | Viewed from Outside | Destination IP on outbound packet after translation | 203.0.113.10 (Public Destination Server) |
Packet Header Transformation Walkthrough
Consider an internal host (10.10.1.50) transmitting an HTTP request to an external web server (203.0.113.10):
- Outbound Ingress (LAN to WAN):
- Original packet received on the inside interface:
Source: 10.10.1.50:51234Destination: 203.0.113.10:80. - NAT lookup occurs. The router translates the Source IP from Inside Local (
10.10.1.50) to Inside Global (198.51.100.25). - Egress packet transmitted out the outside interface:
Source: 198.51.100.25:51234Destination: 203.0.113.10:80.
- Original packet received on the inside interface:
- Inbound Return (WAN to LAN):
- Return packet received on the outside interface:
Source: 203.0.113.10:80Destination: 198.51.100.25:51234. - NAT state lookup matches the active session. The router translates the Destination IP from Inside Global (
198.51.100.25) back to Inside Local (10.10.1.50). - Egress packet delivered to the inside host:
Source: 203.0.113.10:80Destination: 10.10.1.50:51234.
- Return packet received on the outside interface:
The Three Flavors of NAT
NAT ARCHITECTURES
|
+---------------------------+---------------------------+
| |
STATIC NAT DYNAMIC NAT
(1:1 Fixed Mapping) |
Inbound & Outbound Initiation +----------+----------+
Ideal for DMZ Public Servers | |
DYNAMIC POOL PAT / OVERLOAD
(1:1 Dynamic Lease) (M:1 Port Multiplexing)
No Port Rewriting 65,000+ Flows per IP
Pool Depletion Risk Outbound Initiation
1. Static NAT (One-to-One Permanent Translation)
Static NAT configures a fixed, persistent mapping between an Inside Local address and an Inside Global address. The relationship is permanent and bidirectional: outside clients can initiate incoming sessions directly to the Inside Global address, which the router translates to the server's private Inside Local IP. Static NAT is standard for hosting enterprise DMZ services (such as HTTPS portals, SMTP relays, or external DNS servers).
2. Dynamic NAT (Many-to-Many Dynamic Allocation)
Dynamic NAT defines a pool of public Inside Global addresses. When an internal client initiates an outbound connection, the router dynamically assigns an unused IP from the pool. Key characteristics include:
- Translations are temporary and stateful, expiring after inactivity.
- Transport Layer port numbers are not modified; the client retains its original Layer 4 source port.
- Pool Depletion: If the pool contains ten public IPs, only ten internal hosts can establish external sessions concurrently. The eleventh host is dropped until an existing translation expires or is manually cleared.
3. Port Address Translation (PAT / NAT Overload)
PAT multiplexes thousands of private internal IP addresses onto a single public IP (or a small pool) by modifying both the Layer 3 source IP and the Layer 4 TCP/UDP source port. PAT tracks flows using a stateful 5-tuple: (Protocol, Source IP, Source Port, Destination IP, Destination Port).
- Port Multiplexing Capacity: Because TCP and UDP headers allocate 16 bits for port numbers, a single public IP theoretically supports up to 65,536 concurrent connections per protocol. In practice, Cisco routers allocate ports from three pools: 0–511, 512–1023, and 1024–65535. If multiple inside hosts transmit from the same source port (e.g., port 1024), PAT preserves the source port for the first host and re-marks subsequent hosts to unused ports in the same range.
Comparison of NAT Implementations
| Feature / Metric | Static NAT | Dynamic NAT | Port Address Translation (PAT / Overload) |
|---|---|---|---|
| Mapping Ratio | 1 Inside Local : 1 Inside Global | 1 Inside Local : 1 Inside Global (dynamic) | Many Inside Local : 1 Inside Global |
| Layer 4 Port Translation | No (Preserves original port) | No (Preserves original port) | Yes (Rewrites source port when needed) |
| Session Initiation | Bidirectional (Inbound and Outbound) | Outbound only (Inbound requires existing state) | Outbound only (Inbound requires port forwarding) |
| Public IP Scalability | Low (Requires 1 public IP per host) | Low (Requires public IP per concurrent host) | High (~65,000 concurrent sessions per IP) |
| Primary Use Case | Public DMZ web/mail/API servers | Rare legacy integrations without port changes | Standard enterprise campus Internet access |
Cisco IOS-XE Configuration and Implementation
NAT configuration on Cisco IOS-XE requires three distinct steps: defining boundary interfaces, selecting traffic via an Access Control List (ACL), and applying the translation rule.
! Step 1: Designate interface roles
interface GigabitEthernet0/0/0
description Internal Corporate LAN
ip nat inside
!
interface GigabitEthernet0/0/1
description Primary ISP Uplink
ip nat outside
!
! Step 2: Define traffic matching access list
ip access-list standard ACL_CORP_INTERNAL
permit 10.10.0.0 0.0.255.255
!
! Step 3a: Static NAT Configuration (DMZ Server)
ip nat inside source static 10.10.50.10 198.51.100.50 extendable
!
! Step 3b: Dynamic NAT Pool Configuration
ip nat pool POOL_PUBLIC 198.51.100.10 198.51.100.20 netmask 255.255.255.224
ip nat inside source list ACL_CORP_INTERNAL pool POOL_PUBLIC
!
! Step 3c: PAT / Overload on Egress Interface (Standard Enterprise Model)
ip nat inside source list ACL_CORP_INTERNAL interface GigabitEthernet0/0/1 overload
The extendable keyword in static NAT allows the network engineer to configure multiple translations referencing the same global IP (such as port forwarding different TCP ports to distinct internal servers) or apply the same rule across multiple VRF instances.
Operational Behavior, Timeouts, and Troubleshooting
Cisco IOS-XE maintains active translation sessions in the NAT table. These sessions are aged out according to configurable timers:
- TCP Session Timeout: Defaults to 86,400 seconds (24 hours) for fully established connections.
- TCP FIN / RST Timeout: Defaults to 60 seconds after observing TCP termination flags, freeing memory quickly.
- UDP Timeout: Defaults to 300 seconds (5 minutes) because UDP lacks connection-teardown signaling.
- ICMP Timeout: Defaults to 60 seconds, aging out ping translations rapidly.
Verifying NAT Operations
Router# show ip nat translations
Pro Inside global Inside local Outside local Outside global
tcp 198.51.100.1:1024 10.10.1.50:1024 203.0.113.10:443 203.0.113.10:443
tcp 198.51.100.1:1025 10.10.1.51:1024 203.0.113.10:443 203.0.113.10:443
--- 198.51.100.50 10.10.50.10 --- ---
Router# show ip nat statistics
Total active translations: 3 (1 static, 2 dynamic; 2 extended)
Outside interfaces:
GigabitEthernet0/0/1
Inside interfaces:
GigabitEthernet0/0/0
Hits: 1482932 Misses: 24
Expired translations: 1482905
Dynamic mappings:
-- Inside Source
[Id: 1] access-list ACL_CORP_INTERNAL interface GigabitEthernet0/0/1 ref count 2
In show ip nat statistics, Hits indicate packets matched against existing translations, while Misses indicate packets requiring a new entry in the translation table. A high miss rate accompanied by dropped packets indicates pool depletion under Dynamic NAT.
To clear dynamic entries without disrupting static mappings:
Router# clear ip nat translation *
Router# clear ip nat translation inside 10.10.1.50 198.51.100.1
NAT and IPsec Interaction: NAT Traversal (NAT-T / RFC 3948)
Deploying IPsec Virtual Private Networks (VPNs) across intermediate NAT routers introduces two major technical obstacles:
- Authentication Header (AH / IP Protocol 51) Incompatibility: AH calculates an Integrity Check Value (ICV) across immutable fields of the IP packet, including the source and destination IP addresses. When an intermediate router performs NAT, it rewrites the IP address, causing the receiving IPsec peer to recalculate a mismatched ICV and drop the packet. AH is fundamentally incompatible with NAT.
- Encapsulating Security Payload (ESP / IP Protocol 50) PAT Incompatibility: Standard ESP encrypts the transport-layer payload and operates directly over IP (protocol 50) without a TCP or UDP header. Because standard ESP lacks Layer 4 port fields, a PAT router cannot multiplex multiple outbound ESP tunnels over a single public IP address.
The NAT-T Solution
NAT Traversal (NAT-T), standardized in RFC 3948, resolves this conflict seamlessly:
[Standard ESP Packet - Fails PAT]
+-----------+-----------+-------------------------+
| IP Header | ESP (50) | Encrypted Payload + Auth|
+-----------+-----------+-------------------------+
[NAT-T Encapsulated Packet - Traverses PAT]
+-----------+------------+-----------+-------------------------+
| IP Header | UDP 4500 | ESP (50) | Encrypted Payload + Auth|
+-----------+------------+-----------+-------------------------+
- NAT Discovery: During Internet Key Exchange (IKE) Phase 1 negotiation over UDP port 500, peers transmit MD5/SHA hashes of their source and destination IP addresses. If the receiver calculates a different hash, it detects the presence of a NAT device along the transit path.
- Port Floating to UDP 4500: Once NAT is detected, both peers dynamically shift communication from UDP port 500 to UDP port 4500.
- UDP Encapsulation: The router encapsulates outbound ESP packets inside a standard UDP header with source and destination ports set to 4500. Intermediate PAT routers can now modify the outer UDP port numbers without corrupting the inner encrypted ESP packet.
- NAT-T Keepalives: Because intermediate PAT routers age out UDP translation entries after 300 seconds of inactivity, IPsec peers transmit lightweight UDP 4500 keepalive packets (typically every 20 seconds) to maintain active NAT state.
A network administrator inspects an outbound packet leaving an enterprise gateway. The private client workstation has IP 10.20.4.15 and is connecting to a cloud web server at 198.51.100.5. The gateway translates the client IP to public address 203.0.113.88. According to Cisco NAT terminology, which label correctly identifies the address 203.0.113.88?
Inside Local
Outside Local
Inside Global
Outside Global
An engineer configures Dynamic NAT using a pool of six public IPv4 addresses without overload. What occurs when seven internal workstations attempt to establish simultaneous outbound Internet connections?
The first six workstations establish connections; the seventh workstation's traffic is dropped until an active translation expires
The router automatically switches to Port Address Translation (PAT) to multiplex all seven workstations across the pool
The router broadcasts an ARP probe to acquire an additional dynamic IP address from the upstream ISP
All seven workstations share the first IP in the pool using round-robin queuing scheduling
Why does standard IPsec Encapsulating Security Payload (ESP) fail to traverse an intermediate Port Address Translation (PAT) router, and how does NAT Traversal (NAT-T) resolve this issue?
ESP packets are rejected because PAT routers enforce mandatory TCP handshakes; NAT-T converts the IPsec tunnel into a TLS connection over port 443
ESP modifies the IP TTL field, which violates NAT RFC 2663 rules; NAT-T resets the TTL to 255 across every intermediate hop
ESP encrypts the entire Layer 3 IP header; NAT-T strips encryption from the outer header to allow IP address modification
ESP operates directly over IP protocol 50 without Layer 4 port headers; NAT-T encapsulates ESP packets inside a UDP header using port 4500
Sections you finish are checked off in the contents.