hardMultiple Choice
CCNP Practice Question: Is configuring NAT overload (PAT) on a Cisco…
A network engineer is configuring NAT overload (PAT) on a Cisco router to allow multiple internal hosts to share a single public IP address. The engineer uses the command ip nat inside source list 1 interface GigabitEthernet0/0 overload. After testing, internal hosts can access the internet, but some applications fail intermittently. The engineer suspects a NAT issue. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that NAT overload failures are due to missing interface configurations or ACL issues, when in fact the real problem is port exhaustion from too many concurrent sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The NAT translation table is filling up due to a large number of concurrent sessions, causing new translations to be denied.
NAT overload (PAT) uses a single public IP address and tracks sessions via port numbers. With many internal hosts, the router can exhaust its available port numbers (typically 65,535 per public IP), causing new translations to be denied. This leads to intermittent application failures as some sessions cannot be translated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The access list 1 is too permissive and includes the public IP address of the router.
Why it's wrong here
While a permissive ACL may match more inside hosts than intended, including the router's own public IP in access list 1 does not directly exhaust the NAT translation table. PAT only translates traffic sourced from inside local addresses that enters the inside interface, so packets sourced from the outside/public IP would rarely traverse that path. Even if it did, this would be a constant misconfiguration causing consistent behavior, not sporadic translation failures tied to session volume.
- ✓
The NAT translation table is filling up due to a large number of concurrent sessions, causing new translations to be denied.
Why this is correct
With Port Address Translation (PAT), a single public IP can support at most about 65,000 simultaneous translations because each session must use a unique source port (1–65535, minus reserved). When the router's NAT table reaches this limit, it drops new connection attempts, denying translations for additional inside hosts. As existing sessions age out or are cleared, the table frees ports, allowing new connections to succeed, which matches the intermittent failure pattern described. High concurrent sessions—common with web browsing, streaming, or file transfers—can easily fill the table.
- ✗
The router is not configured with ip nat inside on the internal interface.
Why it's wrong here
The 'ip nat inside' command marks the interface where inside local addresses are sourced before translation. If it were missing from the internal interface, no traffic arriving on that interface would be translated at all — every inside host would fail to reach the Internet, not just intermittently. With PAT, a missing 'ip nat inside' would also produce a persistent, total outage rather than a table-filling condition. Thus, this configuration error cannot explain sporadic connectivity.
- ✗
The overload keyword is misspelled or not supported on this IOS version.
Why it's wrong here
The 'overload' keyword is a standard, widely supported IOS parameter that enables PAT; if it were misspelled, the router would reject the command with a syntax error during configuration, not silently malfunction. An unsupported keyword on an older IOS version would similarly cause a configuration rejection, not allow the NAT rule to install and then behave unpredictably. Consequently, the session-dependent failures described are not consistent with a keyword that was never accepted by the router.
Visual reference
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.