A network engineer runs the following command to verify NAT translations: R1# show ip nat translations verbose Pro Inside global Inside local Outside local Outside global --- 10.2.2.2 10.1.1.1 192.168.1.1 192.168.1.1 create 00:00:15, use 00:00:05, flags: extended, timing-out What does the 'extended' flag indicate?
The 'extended' flag confirms the entry maps IP addresses plus TCP or UDP port numbers, which is the defining behaviour of Port Address Translation. This satisfies the scenario's requirement to identify why a single inside global address can multiplex many inside local hosts through distinct port identifiers.
Why this answer
The 'extended' flag in the output of 'show ip nat translations verbose' indicates that the NAT translation includes Layer 4 port information, which is characteristic of Port Address Translation (PAT) or NAT overload. This allows multiple internal hosts to share a single public IP address by using unique port numbers, as opposed to a simple one-to-one translation without port multiplexing.
How to eliminate wrong answers
Option A is wrong because the 'extended' flag specifically indicates that the translation includes port information for multiple sessions, not a single port only. Option C is wrong because the 'extended' flag does not imply static NAT; static NAT entries typically show the 'static' flag and do not time out, whereas this entry has a 'timing-out' flag indicating dynamic behavior. Option D is wrong because the 'extended' flag is unrelated to VPN tunnels; VPN-related translations would involve different flags or encapsulation contexts, not port-based NAT extensions.