NAT and PAT questions cover static NAT (one-to-one), dynamic NAT (pool-based), and PAT/overload (many-to-one using port numbers). The CCNA asks you to read NAT table output, fix misconfigured NAT, and match the right NAT type to a scenario.
Start Scenario PracticeWhat is the purpose of the 'ip nat inside source list' command in Cisco IOS?
Explanation: The 'ip nat inside source list' command is used to define which traffic (identified by an access list) should be translated and to specify the translation method, such as dynamic NAT, PAT, or static NAT. It links the ACL that matches the source IP addresses to a NAT pool or interface, enabling the router to perform the translation for outbound traffic.
Which component in Cisco SD-WAN is responsible for orchestrating the overlay network, including authentication and NAT traversal?
Explanation: The vBond orchestrator is responsible for the initial authentication of all SD-WAN components (vSmart, vManage, vEdge/cEdge) into the overlay network. It also performs NAT traversal by discovering and distributing the public IP addresses and port numbers of vEdge routers behind NAT, enabling secure DTLS/TLS connections between them. Without vBond, new devices cannot securely join the fabric or establish control-plane connectivity.
A network engineer is configuring a Cisco router to provide internet access to a small office using a single public IP address assigned by the ISP. The engineer wants to allow internal hosts to initiate connections to the internet, but also needs to make a web server on the internal network reachable from the internet. The engineer configures a standard access list for NAT and an ip nat inside source list command. However, external users cannot reach the internal web server. What is the most likely cause?
Explanation: The scenario describes a need for both dynamic PAT (for internal hosts to reach the internet) and static NAT (to make the internal web server reachable from the internet). The 'ip nat inside source list' command alone performs dynamic NAT/PAT, translating multiple inside addresses to the single public IP. To allow inbound connections to the web server, a static one-to-one mapping is required using the 'ip nat inside source static tcp' command, which creates a permanent translation entry. Without this static command, the router has no way to know which inside host should receive incoming traffic destined for the public IP on port 80.
A network engineer issues the following command on Router R6: R6# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 192.168.1.100 10.0.0.10 --- --- --- 192.168.1.101 10.0.0.11 --- --- udp 192.168.1.100:1234 10.0.0.10:1234 203.0.113.5:53 203.0.113.5:53 tcp 192.168.1.101:80 10.0.0.11:80 198.51.100.2:443 198.51.100.2:443 Based on this output, what is true about the NAT translations?
Explanation: The output shows two static-like entries (the first two lines with no protocol or port) and two dynamic entries with PAT (the UDP and TCP lines). The first translation for 10.0.0.10 to 192.168.1.100 has no protocol or port information, indicating it is a dynamic NAT entry without PAT (port address translation), because PAT would show specific ports. Option B correctly identifies this translation as dynamic NAT without PAT.
Which type of NAT translates multiple inside addresses to a single outside address using different port numbers?
Explanation: Port Address Translation (PAT) is a form of dynamic NAT that maps multiple private IP addresses to a single public IP address by differentiating traffic based on Layer 4 port numbers. This allows many internal hosts to share one outside address, conserving public IPv4 addresses. PAT is commonly used on home routers and enterprise edge devices to enable internet access for numerous devices with a single public IP.
+8 more scenario questions available
Practice all NAT and PAT Configuration ScenariosNAT and PAT questions cover static NAT (one-to-one), dynamic NAT (pool-based), and PAT/overload (many-to-one using port numbers). The CCNA asks you to read NAT table output, fix misconfigured NAT, and match the right NAT type to a scenario. These appear throughout the 350-401 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-401. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-401 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full NAT and PAT Configuration Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →