Courseiva
mediumMultiple Choice

300-410 Practice Question: The problem with this NAT configuration?…

What is the problem with this NAT configuration?

interface GigabitEthernet0/0
 ip address 192.168.1.1 255.255.255.0
 ip nat inside

!

interface GigabitEthernet0/1
 ip address 203.0.113.1 255.255.255.0

!

ip nat inside source list 1 interface GigabitEthernet0/1 overload
access-list 1 permit 192.168.1.0 0.0.0.255

⚠ Common exam trap

Test-takers frequently assume that simply configuring the NAT statement and ACL is enough, overlooking the mandatory interface-level 'ip nat outside' command, which Cisco explicitly tests in the 300-410 exam to ensure understanding of NAT operation fundamentals.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The interface GigabitEthernet0/1 is missing the 'ip nat outside' command.

The configuration is missing the 'ip nat outside' command on interface GigabitEthernet0/1. For NAT to function, Cisco IOS requires that the inside interface be marked with 'ip nat inside' and the outside interface with 'ip nat outside'. Without this, the router does not know which interface is the external (outside) interface, and the NAT translation will not be applied to outgoing packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ACL is too permissive; it should only permit specific hosts.

    Why it's wrong here

    The ACL correctly scopes translation to the 192.168.1.0/24 subnet, so permitting that range is the intended source list, not a fault. A too-permissive ACL would be a genuine issue only where translation must be restricted to named hosts, which this scenario does not require.

  • ✓

    The interface GigabitEthernet0/1 is missing the 'ip nat outside' command.

    Why this is correct

    NAT translation requires both an inside and an outside interface designation. GigabitEthernet0/1 holds the global address in the overload statement but lacks 'ip nat outside', so translations cannot be built and the configuration is incomplete.

  • ✗

    The 'overload' keyword is unnecessary for this configuration.

    Why it's wrong here

    Overload is required here: it enables PAT so many inside hosts share the single GigabitEthernet0/1 address. Removing it would attempt one-to-one mapping and exhaust the pool. Overload is genuinely unnecessary only when a pool of public addresses provides sufficient one-to-one translations.

  • ✗

    The inside interface should be GigabitEthernet0/1.

    Why it's wrong here

    GigabitEthernet0/1 carries the public 203.0.113.1 address and is the NAT outside interface, so designating it inside would break translation. The inside designation belongs on the private-facing interface. Swapping would be correct only if addressing were reversed, which it is not.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.