Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementEasy
A network security administrator is configuring a Cisco Adaptive Security Appliance (ASA) firewall to allow internal users to access external web servers. The administrator wants to translate the internal private IP addresses to a single public IP address for outbound connections. Which NAT type should the administrator implement?
- AStatic NAT
- BPort Address Translation (PAT)
- CPolicy NAT
- DDynamic NAT
Show answer & explanationAnswer & explanation
Correct answer: B. Port Address Translation (PAT)
Port Address Translation (PAT), also known as NAT Overload, allows multiple private IP addresses to share a single public IP address by using different source port numbers. This is the most common form of NAT for outbound internet access.
Why the other options are wrong
- A. Static NAT maps a single private IP address to a single public IP address, which doesn't meet the requirement of translating multiple internal users to one public IP.
- C. Policy NAT applies NAT based on specific traffic criteria (e.g., source/destination IP, port), but it's a method of applying NAT, not a distinct NAT type for this specific translation need.
- D. Dynamic NAT maps multiple private IP addresses to a pool of public IP addresses, but it still uses a one-to-one mapping from the pool, not a single public IP for all.
Port Address Translation (PAT)
A form of Network Address Translation (NAT) that allows multiple private IP addresses to be mapped to a single public IP address by using different source port numbers for each connection.
- Also known as NAT Overload.
- Conserves public IP addresses.
- Commonly used for outbound internet access from internal networks.
Memory trick: NAT helps networks talk, like a language translator for IPs.