Courseiva
hardMultiple ChoiceObjective-mapped

300-410 Practice Question: Router R1 is configured with ip nat inside source…

Router R1 is configured with ip nat inside source list 100 interface GigabitEthernet0/1 overload. Internal host 192.168.1.10 can access the internet, but when it tries to connect to an internal server at 10.1.1.10 via its public IP 203.0.113.10, the connection fails. Router R1 shows: show ip nat translations: Pro Inside global Inside local Outside local Outside global --- 203.0.113.10 10.1.1.10 --- ---. The host's traffic is being NATed to 203.0.113.1, but the server's response is sent to 203.0.113.1. What is the root cause?

⚠ Common exam trap

Cisco often tests the misconception that NAT hairpinning is automatically handled by dynamic PAT, when in fact it requires explicit static NAT configuration and a route to the public IP to force the router to perform the necessary translations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable NAT hairpinning by configuring ip nat inside source static tcp 10.1.1.10 80 203.0.113.10 80 and ensuring the router has a route to the public IP.

The root cause is that NAT hairpinning (also known as NAT reflection or NAT loopback) is not enabled. When an internal host (192.168.1.10) tries to reach an internal server (10.1.1.10) using the server's public IP (203.0.113.10), the router performs NAT for the host's traffic, translating its source to 203.0.113.1. The server's response is sent to 203.0.113.1 (the router's outside interface), but without hairpinning, the router does not know to forward this response back to the internal host because it expects the traffic to come from the outside. Option A corrects this by adding a static NAT for the server (mapping 10.1.1.10:80 to 203.0.113.10:80) and ensuring the router has a route to the public IP, which enables the router to perform the necessary NAT translation and forward the response back to the internal host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable NAT hairpinning by configuring ip nat inside source static tcp 10.1.1.10 80 203.0.113.10 80 and ensuring the router has a route to the public IP.

    Why this is correct

    Hairpinning allows the router to forward traffic from inside to inside via the public IP.

  • Configure the host to use the private IP of the server instead of the public IP.

    Why it's wrong here

    This is a workaround, not a fix for the NAT issue.

  • Add a static route on the router for 203.0.113.10 pointing to the server.

    Why it's wrong here

    This does not address the NAT hairpinning problem.

  • Use ip nat outside source list 100 interface GigabitEthernet0/1 overload.

    Why it's wrong here

    This would translate outside addresses, not solve hairpinning.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.