Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementEasy

A network security administrator is configuring a Cisco Adaptive Security Appliance (ASA) firewall to allow internal users to access external web servers. The administrator wants to translate the internal private IP addresses to a single public IP address for outbound connections. Which NAT type should the administrator implement?

  1. AStatic NAT
  2. BPort Address Translation (PAT)
  3. CPolicy NAT
  4. DDynamic NAT
Show answer & explanation

Correct answer: B. Port Address Translation (PAT)

Port Address Translation (PAT), also known as NAT Overload, allows multiple private IP addresses to share a single public IP address by using different source port numbers. This is the most common form of NAT for outbound internet access.

Why the other options are wrong

  • A. Static NAT maps a single private IP address to a single public IP address, which doesn't meet the requirement of translating multiple internal users to one public IP.
  • C. Policy NAT applies NAT based on specific traffic criteria (e.g., source/destination IP, port), but it's a method of applying NAT, not a distinct NAT type for this specific translation need.
  • D. Dynamic NAT maps multiple private IP addresses to a pool of public IP addresses, but it still uses a one-to-one mapping from the pool, not a single public IP for all.

Port Address Translation (PAT)

A form of Network Address Translation (NAT) that allows multiple private IP addresses to be mapped to a single public IP address by using different source port numbers for each connection.

  • Also known as NAT Overload.
  • Conserves public IP addresses.
  • Commonly used for outbound internet access from internal networks.

Memory trick: NAT helps networks talk, like a language translator for IPs.

More Visibility and Enforcement questions