← All labs Lab 10 · Packet Tracer

NAT overload (PAT)

ACL, ip nat inside/outside and one public IP for the whole LAN

Level: Intermediate Time: 30 min Domain 4.0 IP Services

Scenario

The LAN uses private addresses (192.168.1.0/24) and the ISP doesn't know how to send traffic back to them: the PCs can't reach the Internet web server (198.51.100.10).

Configure PAT on R1 so the whole LAN goes out with the IP of its public interface (G0/1): a standard ACL 1 permitting the LAN, G0/0 as inside, G0/1 as outside and the translation with overload. Then ping from a PC and look at the translations with show ip nat translations.

Topology

PC1PC2SW1R1ISPSRV1Gi0/0Gi0/1Fa0Fa0/1Fa0Fa0/2Gi0/1Gi0/0Gi0/1Fa0

Devices and cabling

FromToCable
R1 Gi0/0SW1 Gi0/1Straight-through
PC1 Fa0SW1 Fa0/1Straight-through
PC2 Fa0SW1 Fa0/2Straight-through
R1 Gi0/1ISP Gi0/0Crossover
ISP Gi0/1SRV1 Fa0Crossover

If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.

Addressing

DeviceInterfaceAddressMaskDefault gateway
R1G0/0 (inside)192.168.1.1255.255.255.0—
R1G0/1 (outside)203.0.113.2255.255.255.252—
ISPG0/0203.0.113.1255.255.255.252—
ISPG0/1198.51.100.1255.255.255.0—
PC1NIC192.168.1.10255.255.255.0192.168.1.1
PC2NIC192.168.1.11255.255.255.0192.168.1.1
SRV1NIC198.51.100.10255.255.255.0198.51.100.1

Starting configuration

In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.

R1hostname R1 no ip domain-lookup interface g0/0 ip address 192.168.1.1 255.255.255.0 no shutdown interface g0/1 ip address 203.0.113.2 255.255.255.252 no shutdown ip route 0.0.0.0 0.0.0.0 203.0.113.1
ISPhostname ISP no ip domain-lookup interface g0/0 ip address 203.0.113.1 255.255.255.252 no shutdown interface g0/1 ip address 198.51.100.1 255.255.255.0 no shutdown
SW1hostname SW1 no ip domain-lookup

PCs and servers (Desktop › IP Configuration)

Tasks

What must end up working. In the app, each one ticks itself off as soon as you get it.

  1. ACL 1 permitting 192.168.1.0/24
  2. G0/0 as the inside interface
  3. G0/1 as the outside interface
  4. PAT using G0/1's IP
  5. PC1 and PC2 reach server 198.51.100.10
  6. Translations checked with show ip nat translations
In Packet Tracer
  • The ISP is another 2911 router and the server a Server-PT, which has the HTTP service on by default.
Hints
  • ACL 1 permitting 192.168.1.0/24: access-list 1 permit 192.168.1.0 0.0.0.255
  • G0/0 as the inside interface: interface g0/0 → ip nat inside
  • G0/1 as the outside interface: interface g0/1 → ip nat outside
  • PAT using G0/1's IP: ip nat inside source list 1 interface g0/1 overload
  • PC1 and PC2 reach server 198.51.100.10: From PC1: ping 198.51.100.10. Without NAT, the ISP has no route back to 192.168.1.0.
  • Translations checked with show ip nat translations: First ping from a PC, then show ip nat translations on R1

Step-by-step solution

Try it on your own first: you learn much more by typing the commands yourself.

Show the solution

1Define what gets translated R1

The standard ACL marks the inside addresses allowed to go out translated.

R1enable configure terminal access-list 1 permit 192.168.1.0 0.0.0.255

2Mark inside and outside R1

NAT only translates traffic that enters an inside interface and leaves through an outside one.

R1interface g0/0 ip nat inside interface g0/1 ip nat outside exit

3Enable PAT R1

overload lets the whole LAN share G0/1's IP, telling each connection apart by its port.

R1ip nat inside source list 1 interface g0/1 overload end

Verification

Without NAT, the ISP has no route back to 192.168.1.0/24 and the ping fails. With NAT, it replies.

PC1C:\>ping 198.51.100.10 Pinging 198.51.100.10 with 32 bytes of data: Reply from 198.51.100.10: bytes=32 time<1ms TTL=126 Reply from 198.51.100.10: bytes=32 time<1ms TTL=126 Reply from 198.51.100.10: bytes=32 time<1ms TTL=126 Reply from 198.51.100.10: bytes=32 time<1ms TTL=126 Ping statistics for 198.51.100.10: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms

Each echo shows up translated: inside, 192.168.1.10; outside, 203.0.113.2 with its own port.

R1R1#show ip nat translations Pro Inside global Inside local Outside local Outside global icmp 203.0.113.2:1 192.168.1.10:1 198.51.100.10:1 198.51.100.10:1 icmp 203.0.113.2:2 192.168.1.10:2 198.51.100.10:2 198.51.100.10:2 icmp 203.0.113.2:3 192.168.1.10:3 198.51.100.10:3 198.51.100.10:3 icmp 203.0.113.2:4 192.168.1.10:4 198.51.100.10:4 198.51.100.10:4 icmp 203.0.113.2:5 192.168.1.10:5 198.51.100.10:5 198.51.100.10:5 icmp 203.0.113.2:6 192.168.1.10:6 198.51.100.10:6 198.51.100.10:6 icmp 203.0.113.2:7 192.168.1.10:7 198.51.100.10:7 198.51.100.10:7 icmp 203.0.113.2:8 192.168.1.10:8 198.51.100.10:8 198.51.100.10:8

Common mistakes

Practice this lab on your phone

RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.

Get RoutingLab