Courseiva
hardMultiple ChoiceObjective-mapped

300-410 Practice Question: Router R1 is configured with ip nat inside source…

Router R1 is configured with ip nat inside source list 100 interface GigabitEthernet0/1 overload. Internal hosts can access the internet, but traffic to a specific external server at 203.0.113.100 is being translated to a different source IP than expected. Router R1 shows: show ip nat translations: Pro Inside global Inside local Outside local Outside global --- 10.1.1.1 192.168.1.1 203.0.113.100 203.0.113.100. The server logs show connections from 10.1.1.1 instead of 203.0.113.1. What is the root cause?

⚠ Common exam trap

Cisco often tests the misconception that the `interface` keyword in `ip nat inside source list` automatically uses a public IP, but the trap is that it simply uses whatever IP is configured on that interface, which could be private if misconfigured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The interface GigabitEthernet0/1 has a private IP address; configure a public IP or use a NAT pool.

The NAT configuration uses `ip nat inside source list 100 interface GigabitEthernet0/1 overload`, which translates inside local addresses to the IP address of the GigabitEthernet0/1 interface. If that interface has a private IP address (e.g., 10.1.1.1), then all translated traffic will appear to come from that private address, not a public one. The server logs confirm this by showing connections from 10.1.1.1 instead of a public IP like 203.0.113.1, indicating the interface lacks a public IP or a NAT pool with a routable address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The interface GigabitEthernet0/1 has a private IP address; configure a public IP or use a NAT pool.

    Why this is correct

    If the interface IP is private, NAT will use that private IP, causing the issue.

  • The access-list 100 is incorrectly matching traffic.

    Why it's wrong here

    The translation shows the correct inside local address, so ACL is working.

  • The server is responding to the wrong IP due to asymmetric routing.

    Why it's wrong here

    The server sees the source IP as 10.1.1.1, which is the translated address.

  • The NAT configuration is missing the 'overload' keyword.

    Why it's wrong here

    The configuration includes 'overload', and translations are occurring.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.