Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A network administrator is configuring a Cisco ASA firewall to allow internal users to access external web servers. The internal network uses private IP addresses (10.0.0.0/8), and the ASA has a single public IP address for outbound internet access. The administrator wants to configure NAT so that multiple internal hosts can share this single public IP address for their outbound connections. Which type of NAT should the administrator configure?

  1. AIdentity NAT
  2. BPort Address Translation (PAT)
  3. CStatic NAT
  4. DDynamic NAT
Show answer & explanation

Correct answer: B. Port Address Translation (PAT)

Port Address Translation (PAT), also known as NAT Overload, allows multiple private IP addresses to share a single public IP address by using different source port numbers for each conversation. This is the most common form of NAT used for outbound internet access from an internal network with a limited number of public IP addresses.

Why the other options are wrong

  • A. Identity NAT (or NAT 0) means no translation occurs; it's used when traffic between two networks doesn't need NAT.
  • C. Static NAT provides a one-to-one mapping between a private IP and a public IP, which would only allow one internal host per public IP.
  • D. Dynamic NAT provides a one-to-one mapping from a pool of private IPs to a pool of public IPs; it doesn't allow multiple private IPs to share a single public IP.

Port Address Translation (PAT)

A form of Network Address Translation (NAT) that maps multiple private IP addresses to a single public IP address by using distinct port numbers for each translation.

  • Also known as NAT Overload
  • Conserves public IP addresses
  • Commonly used for home and small office internet access

Memory trick: PAT shares the public door with many keys.

More Network Security questions