mediumMultiple Choice
300-410 Practice Question: The problem with this NAT configuration?…
What is the problem with this NAT configuration?
interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside
!
interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0
!
ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255
⚠ Common exam trap
Test-takers frequently assume that simply configuring the NAT statement and ACL is enough, overlooking the mandatory interface-level 'ip nat outside' command, which Cisco explicitly tests in the 300-410 exam to ensure understanding of NAT operation fundamentals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The interface GigabitEthernet0/1 is missing the 'ip nat outside' command.
The configuration is missing the 'ip nat outside' command on interface GigabitEthernet0/1. For NAT to function, Cisco IOS requires that the inside interface be marked with 'ip nat inside' and the outside interface with 'ip nat outside'. Without this, the router does not know which interface is the external (outside) interface, and the NAT translation will not be applied to outgoing packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The ACL is too permissive; it should only permit specific hosts.
Why it's wrong here
The ACL correctly scopes translation to the 192.168.1.0/24 subnet, so permitting that range is the intended source list, not a fault. A too-permissive ACL would be a genuine issue only where translation must be restricted to named hosts, which this scenario does not require.
- ✓
The interface GigabitEthernet0/1 is missing the 'ip nat outside' command.
Why this is correct
NAT translation requires both an inside and an outside interface designation. GigabitEthernet0/1 holds the global address in the overload statement but lacks 'ip nat outside', so translations cannot be built and the configuration is incomplete.
- ✗
The 'overload' keyword is unnecessary for this configuration.
Why it's wrong here
Overload is required here: it enables PAT so many inside hosts share the single GigabitEthernet0/1 address. Removing it would attempt one-to-one mapping and exhaust the pool. Overload is genuinely unnecessary only when a pool of public addresses provides sufficient one-to-one translations.
- ✗
The inside interface should be GigabitEthernet0/1.
Why it's wrong here
GigabitEthernet0/1 carries the public 203.0.113.1 address and is the NAT outside interface, so designating it inside would break translation. The inside designation belongs on the private-facing interface. Swapping would be correct only if addressing were reversed, which it is not.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.