NAT and PAT questions cover static NAT (one-to-one), dynamic NAT (pool-based), and PAT/overload (many-to-one using port numbers). The CCNA asks you to read NAT table output, fix misconfigured NAT, and match the right NAT type to a scenario.
Start Scenario PracticeConsider the following partial configuration on a Cisco IOS-XE router: interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0 ip nat outside ! ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255 What is the effect of this configuration?
Explanation: The configuration uses an ACL (access-list 1) to match traffic from the 192.168.1.0/24 subnet, and the 'ip nat inside source list 1 interface GigabitEthernet0/1 overload' command translates all matching source IP addresses to the single IP address 203.0.113.1 (the outside interface IP) using Port Address Translation (PAT). This is a classic dynamic NAT overload configuration, where multiple internal hosts share one public IP by multiplexing on source ports.
Which THREE statements about NAT and PAT behavior in Cisco IOS are true? (Choose THREE.)
Explanation: PAT (Port Address Translation) extends NAT by using unique source port numbers to multiplex multiple inside hosts over a single public IP address. This allows many internal devices to share one external IP, with the router tracking each session by the combination of inside global IP and port.
Given this partial configuration: ip nat pool MYPOOL 203.0.113.10 203.0.113.20 netmask 255.255.255.0 ip nat inside source list 1 pool MYPOOL access-list 1 permit 192.168.1.0 0.0.0.255 What is the effect?
Explanation: The configuration uses a standard ACL to match inside hosts (192.168.1.0/24) and dynamically assigns them a unique address from the pool 203.0.113.10–203.0.113.20. Because no 'overload' keyword is present, PAT is not enabled; each translation consumes a pool address, and once all 11 addresses are used, new translations fail until an existing translation times out or is cleared.
A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 192.0.2.10 10.0.0.10 --- --- R1# show ip nat statistics Total active translations: 1 (0 static, 1 dynamic; 0 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 0 Misses: 0 CEF Translated packets: 0, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source [Id] ip nat pool POOL1 192.0.2.10 192.0.2.20 netmask 255.255.255.240 refcount 1 map-id 1 [Id] ip nat inside source list ACL1 pool POOL1 refcount 1 Based on this output, what is the problem?
Explanation: The output shows a single dynamic NAT translation with zero hits and zero misses, meaning no traffic has attempted to traverse the NAT process. This indicates the translation entry exists (likely from a previous or idle session) but no packets have matched the access list or triggered translation since the counters were cleared. The problem is that the NAT configuration is in place but not actively translating any traffic.
What is the problem with this NAT configuration? interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0 ! ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255
Explanation: The configuration is missing the 'ip nat outside' command on interface GigabitEthernet0/1. For NAT to function, Cisco IOS requires that the inside interface be marked with 'ip nat inside' and the outside interface with 'ip nat outside'. Without this, the router does not know which interface is the external (outside) interface, and the NAT translation will not be applied to outgoing packets.
+8 more scenario questions available
Practice all NAT and PAT Configuration ScenariosNAT and PAT questions cover static NAT (one-to-one), dynamic NAT (pool-based), and PAT/overload (many-to-one using port numbers). The CCNA asks you to read NAT table output, fix misconfigured NAT, and match the right NAT type to a scenario. These appear throughout the 300-410 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 300-410. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 300-410 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full NAT and PAT Configuration Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →