Courseiva
Network Services and SecurityhardTroubleshootingObjective-mapped

CCNA Network Services and Security Practice Question

Exhibit

R1# show running-config | section ip nat
ip nat inside source list 100 interface GigabitEthernet0/1
ip nat inside source static 192.168.1.10 203.0.113.5
access-list 100 permit ip 192.168.2.0 0.0.0.255 any
!
interface GigabitEthernet0/0
 ip address 192.168.1.1 255.255.255.0
 ip nat outside
!
interface GigabitEthernet0/1
 ip address 203.0.113.1 255.255.255.0
 ip nat inside
!

You are connected to R1. Configure PAT (NAT overload) so that hosts on the 192.168.1.0/24 inside network can reach the Internet through the outside interface GigabitEthernet0/1 using the IP address 203.0.113.1. Additionally, configure static NAT to map internal server 192.168.1.10 to public IP 203.0.113.5. The current configuration has several errors. Identify and correct them.

⚠ Common exam trap

Watch for three common NAT configuration errors: interface direction misassignment, missing 'overload' keyword for PAT, and incorrect ACL subnet matching. Always verify each component separately.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Correct the NAT interface directions: G0/0 as inside, G0/1 as outside. Add 'overload' to the PAT command. Change ACL 100 to permit 192.168.1.0 0.0.0.255.

The configuration had three issues: (1) Inside and outside interfaces were swapped — G0/0 (inside) was marked 'ip nat outside' and G0/1 (outside) was 'ip nat inside'. (2) The PAT command was missing the 'overload' keyword. (3) ACL 100 matched the wrong subnet (192.168.2.0 instead of 192.168.1.0). To fix: correct interface NAT directions, add 'overload', and update ACL to permit 192.168.1.0/24.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Correct the NAT interface directions: G0/0 as inside, G0/1 as outside. Add 'overload' to the PAT command. Change ACL 100 to permit 192.168.1.0 0.0.0.255.

    Why this is correct

    This is the correct configuration: G0/0 is the inside interface because it faces the internal 192.168.1.0/24 network, and G0/1 is the outside interface facing the Internet. Adding the overload keyword enables PAT so multiple internal hosts share the public address, and changing ACL 100 to permit 192.168.1.0/24 ensures that exactly the internal network is eligible for translation. These three corrections together produce a functional dynamic PAT configuration while preserving any static NAT for the server.

  • Change the NAT interface directions: G0/0 as outside, G0/1 as inside. Add 'overload' to the PAT command. Change ACL 100 to permit 192.168.1.0 0.0.0.255.

    Why it's wrong here

    This option correctly updates ACL 100 to match the internal 192.168.1.0/24 network and adds the overload keyword, but it reverses the NAT interface designations. On most enterprise routers G0/0 connects to the LAN and G0/1 connects to the ISP, so marking G0/0 as outside and G0/1 as inside causes the router to apply NAT in the wrong direction, and PAT never translates the LAN source addresses. As a result, inside hosts remain untranslated and the configuration is invalid despite the correct ACL change.

  • Correct the NAT interface directions: G0/0 as inside, G0/1 as outside. Add 'overload' to the PAT command. Keep ACL 100 as is because it already permits the correct subnet.

    Why it's wrong here

    This answer correctly fixes the NAT interface directions and adds overload, but it leaves ACL 100 permitting 192.168.2.0/24. Because the inside LAN is 192.168.1.0/24, packets from that subnet are not matched by the ACL, so the router will not translate them and PAT fails; the only traffic that could be translated would be from the wrong subnet. The ACL must be changed to permit the actual internal network, making this option incorrect even though the interface roles and overload are right.

  • Change the NAT interface directions: G0/0 as outside, G0/1 as inside. Add 'overload' to the PAT command. Change ACL 100 to permit 192.168.1.0 0.0.0.255.

    Why it's wrong here

    Although this answer identifies the need for the overload keyword and the correct ACL entry, the swapped inside/outside interface assignment is the critical failure: with G0/0 marked outside, the router treats the internal network as an external source and attempts to translate traffic arriving on the WAN side instead. This misassignment also prevents the NAT ACL from being matched against LAN-originated packets, so the corrected ACL never affects real traffic and PAT cannot operate. Thus, despite containing two accurate fixes, the reversed directions make the whole configuration unworkable.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Correct the NAT interface directions: G0/0 as inside, G0/1 as outside. Add 'overload' to the PAT command. Change ACL 100 to permit 192.168.1.0 0.0.0.255.Correct answer

Why this is correct

This is the correct configuration: G0/0 is the inside interface because it faces the internal 192.168.1.0/24 network, and G0/1 is the outside interface facing the Internet. Adding the overload keyword enables PAT so multiple internal hosts share the public address, and changing ACL 100 to permit 192.168.1.0/24 ensures that exactly the internal network is eligible for translation. These three corrections together produce a functional dynamic PAT configuration while preserving any static NAT for the server.

Change the NAT interface directions: G0/0 as outside, G0/1 as inside. Add 'overload' to the PAT command. Change ACL 100 to permit 192.168.1.0 0.0.0.255.Wrong answer — click to see why

Why this is wrong here

The specific factual error is that the inside and outside interfaces are swapped; G0/0 is the internal interface and must be 'ip nat inside'.

Why candidates choose this

Candidates might confuse which interface is inside/outside, especially if they misread the topology or think the external interface should be marked inside.

Correct the NAT interface directions: G0/0 as inside, G0/1 as outside. Add 'overload' to the PAT command. Keep ACL 100 as is because it already permits the correct subnet.Wrong answer — click to see why

Why this is wrong here

The specific factual error is that the ACL permits the wrong subnet (192.168.2.0 instead of 192.168.1.0).

Why candidates choose this

Candidates may overlook the ACL error if they assume the existing ACL is correct, or they may misread the subnet in the question.

Change the NAT interface directions: G0/0 as outside, G0/1 as inside. Add 'overload' to the PAT command. Change ACL 100 to permit 192.168.1.0 0.0.0.255.Wrong answer — click to see why

Why this is wrong here

The specific factual error is that both the interface directions are swapped and the ACL is changed, but the interface directions must be correct for NAT to work.

Why candidates choose this

Candidates might think that changing the ACL is the only fix and ignore the interface direction issue, or they may incorrectly assume that the outside interface should be marked inside.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.