Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A network administrator is configuring Network Address Translation (NAT) on a Cisco router. The internal network uses private IP addresses (10.0.0.0/8) and needs to access the internet. The router has a single public IP address (203.0.113.10) assigned to its internet-facing interface. Which type of NAT is most appropriate for allowing multiple internal hosts to share this single public IP address for outbound internet access?

  1. ANAT64
  2. BStatic NAT
  3. CNAT Overload (PAT)
  4. DDynamic NAT
Show answer & explanation

Correct answer: C. NAT Overload (PAT)

NAT Overload, also known as Port Address Translation (PAT), allows multiple internal private IP addresses to share a single public IP address for external communication by using different source port numbers. This is the most common and appropriate method for giving an entire internal network internet access via one public IP. Static NAT maps one-to-one. Dynamic NAT uses a pool of public IPs. NAT64 translates IPv6 to IPv4.

Why the other options are wrong

  • A. NAT64 is a mechanism for translating IPv6 packets to IPv4 packets and vice versa, which is not relevant to this scenario.
  • B. Static NAT maps a single private IP to a single public IP, which is not suitable for multiple internal hosts sharing one public IP.
  • D. Dynamic NAT uses a pool of public IP addresses to map to private IPs, but the scenario specifies only a single public IP.

NAT Overload (PAT)

NAT Overload, also known as Port Address Translation (PAT), is a type of NAT that allows multiple internal private IP addresses to share a single public IP address by mapping different source port numbers to distinguish traffic flows.

  • Many-to-one mapping (many private IPs to one public IP).
  • Uses source port numbers for differentiation.
  • Most common for home and small business internet access.

Memory trick: NAT is like a translator; how many people are talking to how many public faces?

More Network Security questions