Cisco CCNA (200-301)IP ServicesHard
A small office network uses a single Cisco router for internet access. Due to a recent ISP change, the public IP address provided is now 203.0.113.5. The internal network uses 192.168.1.0/24. The router's FastEthernet0/0 interface is connected to the ISP and FastEthernet0/1 to the internal LAN. Which configuration ensures that all internal hosts can access the internet using PAT, assuming an access-list named 'NAT_ACL' permits internal traffic?
- Ainterface FastEthernet0/0 ip nat outside interface FastEthernet0/1 ip nat inside ip nat inside source list NAT_ACL pool ISP_POOL overload
- Binterface FastEthernet0/0 ip nat inside interface FastEthernet0/1 ip nat outside ip nat inside source list NAT_ACL interface FastEthernet0/0 overload
- Cinterface FastEthernet0/0 ip nat inside interface FastEthernet0/1 ip nat outside ip nat outside source list NAT_ACL interface FastEthernet0/0 overload
- Dinterface FastEthernet0/0 ip nat outside interface FastEthernet0/1 ip nat inside ip nat inside source list NAT_ACL interface FastEthernet0/0 overload
Show answer & explanationAnswer & explanation
Correct answer: D. interface FastEthernet0/0 ip nat outside interface FastEthernet0/1 ip nat inside ip nat inside source list NAT_ACL interface FastEthernet0/0 overload
For PAT, the interface connected to the public network (ISP) must be `ip nat outside`, and the interface connected to the private network (LAN) must be `ip nat inside`. The `ip nat inside source list <ACL> interface <outside_interface> overload` command enables PAT, using the IP address of the outside interface as the global address.
Why the other options are wrong
- A. While the `ip nat outside`/`ip nat inside` interface configurations are correct, this command attempts to use a `pool` named `ISP_POOL`, which is not defined and unnecessary when using the `interface` keyword for PAT.
- B. This option incorrectly designates FastEthernet0/0 (ISP) as `ip nat inside` and FastEthernet0/1 (LAN) as `ip nat outside`.
- C. This option incorrectly designates FastEthernet0/0 (ISP) as `ip nat inside` and FastEthernet0/1 (LAN) as `ip nat outside`.
Cisco IOS PAT Configuration
Steps to configure Port Address Translation (NAT Overload) on a Cisco router for internet access.
- Define `ip nat inside` on the internal interface.
- Define `ip nat outside` on the external (ISP-facing) interface.
- Use `ip nat inside source list <ACL> interface <outside_interface> overload` for PAT.
- An Access Control List (ACL) defines which internal traffic to translate.
Memory trick: Inside is private, Outside is public, ACL lists what to overload on the outside interface.