Courseiva
hardMultiple Choice

How to Interpret NAT Translation Table with PAT and Static

A network engineer runs the following command on Router R5:

R5# show ip nat translations

Pro Inside global Inside local Outside local Outside global udp 192.0.2.20:1234 10.0.0.20:1234 203.0.113.1:53 203.0.113.1:53 tcp 192.0.2.20:5678 10.0.0.20:5678 198.51.100.1:80 198.51.100.1:80

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the distinction between static NAT and PAT by showing multiple translations from the same inside local address with different ports, leading candidates to mistakenly think static NAT is involved when the key clue is the port multiplexing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The router is performing Port Address Translation (PAT) for multiple sessions from the same internal host.

The output shows two different translations (UDP and TCP) for the same inside local address 10.0.0.20, both using the same inside global address 192.0.2.20 but with different port numbers (1234 and 5678). This is characteristic of Port Address Translation (PAT), also known as NAT overload, where a single public IP address is shared among multiple sessions from the same internal host by multiplexing on the transport layer port. Option B correctly identifies this behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The router is configured with static NAT for two internal hosts.

    Why it's wrong here

    Static NAT is configured with a one-to-one inside local-to-inside global binding that never changes and does not inspect or translate Layer 4 ports. The displayed translation entries show the same inside global address being reused for multiple sessions from 10.0.0.20, with each session distinguished by a different source port, which is impossible under static NAT. Static entries would also remain in the table even when idle, whereas these entries appear to be dynamic and port-based.

  • ✓

    The router is performing Port Address Translation (PAT) for multiple sessions from the same internal host.

    Why this is correct

    The translation table shows two entries both sourced from inside local 10.0.0.20, and both are assigned the same inside global address 192.0.2.20. The differentiator between the sessions is the source port, which is the defining behavior of Port Address Translation (PAT) / NAT overload. PAT lets one internal host sustain multiple concurrent TCP or UDP flows through a single public IP by rewriting each packet's source port along with the IP address, which matches the entries given in the question.

  • ✗

    The router is performing destination NAT.

    Why it's wrong here

    Destination NAT, often called port forwarding or NAT for inbound traffic, changes the destination IP address in packets from an outside global address to an inside local or outside local address. In this output, the outside local and outside global columns are the same for both entries, so no destination rewriting is occurring; the translation is happening on the source side of the sessions. A destination NAT entry would show a different outside local address in the table for those same outside global addresses.

  • ✗

    The inside local address 10.0.0.20 is using two different global addresses.

    Why it's wrong here

    The statement claims 10.0.0.20 is being mapped to two different global addresses, but both translation entries use the same inside global IP 192.0.2.20. The reason there are two lines is that PAT creates one translation entry per session, and these two sessions are differentiated solely by their source ports, not by the inside global address. Misreading this as two global addresses is a common trap; the address is identical, only the port is different.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

OSI Model Reference

LayerNamePDUKey Protocols / Devices
7ApplicationDataHTTP, HTTPS, DNS, SMTP, FTP, SSH
6PresentationDataTLS / SSL, JPEG, ASCII encoding
5SessionDataNetBIOS, RPC, SIP
4TransportSegment / DatagramTCP, UDP
3NetworkPacketIP, ICMP, OSPF — Routers
2Data LinkFrameEthernet, Wi-Fi, PPP — Switches, Bridges
1PhysicalBitsCables, NICs, Hubs, Repeaters

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.