mediumMultiple Choice
300-410 Practice Question: An engineer configures NAT on a router with 'ip…
An engineer configures NAT on a router with 'ip nat inside source list 1 interface GigabitEthernet0/0 overload'. The inside hosts are 10.0.0.0/24, and the outside interface is 203.0.113.1. Traffic works for most hosts, but one host at 10.0.0.50 cannot access the internet. 'Show ip nat translations' shows no entry for this host. 'Show access-lists' shows ACL 1 permits 10.0.0.0 0.0.0.255. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that a missing NAT translation automatically implies a NAT configuration or ACL issue, when in fact the root cause is often a host-side misconfiguration that prevents traffic from reaching the router in the first place.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The host has a misconfigured subnet mask or default gateway.
The host at 10.0.0.50 is within the ACL 1 permitted range, yet no NAT translation appears, indicating the traffic never reaches the NAT process. A misconfigured subnet mask or default gateway on the host would cause its packets to be sent to the wrong next-hop or be dropped locally, preventing the router from seeing the traffic and creating a translation. Since 'show ip nat translations' shows no entry, the issue is upstream of NAT, pointing to a host-side configuration problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The host's IP address is statically assigned and conflicts with another device.
Why it's wrong here
An IP address conflict causes intermittent ARP disruptions and potential packet loss, but the host still believes it has networking capability and will transmit frames toward its configured default gateway. If the router were receiving those frames, the NAT process would at least attempt a translation (and possibly fail due to duplicate MAC issues). Since no translation is ever attempted, the root cause cannot be an IP conflict; the traffic is not arriving at the router at all.
- ✓
The host has a misconfigured subnet mask or default gateway.
Why this is correct
The correct answer. If the host's subnet mask is incorrect, it may compute that the router's inside interface is not on the same subnet, and therefore not use it as the next hop; instead, it will ARP for the destination IP directly. Alternatively, if the default gateway is misconfigured (or missing), all out-of-subnet traffic is sent to the wrong device or dropped locally. In either case, the packets never reach the router's inside interface, so the router's NAT process never sees the traffic and creates no translation entry.
- ✗
The NAT pool is exhausted.
Why it's wrong here
NAT pool exhaustion is a global condition affecting every host that needs address translation, not a single host. The scenario explicitly states that other hosts work, which proves that the pool still has available addresses or port-block resources. Furthermore, with an exhausted pool, the router would still receive the packets and attempt to translate them, only to drop them when no address is available; this would generate NAT failure logs and would be visible in `show ip nat statistics`.
- ✗
The router's inside interface is administratively down.
Why it's wrong here
If the router's inside interface were administratively down, the router would not forward any traffic from that entire subnet—meaning no hosts on that segment would have NAT translations. Since other hosts are functioning and have working translations, the interface must be up and operational. The failure is host-specific, pointing to a Layer 3 addressing issue at the host itself rather than a router interface state.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.