Courseiva
hardMultiple Choice

350-401 Practice Question: Is troubleshooting a NAT issue where an internal…

A network engineer is troubleshooting a NAT issue where an internal host cannot establish an SSH session to a remote server on the internet. The engineer checks the NAT translations on the border router and sees that the translation for the host's source IP is present. However, the SSH session times out. The engineer also notices that the remote server's IP is not in the NAT translation table. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that a successful source NAT translation guarantees bidirectional traffic flow, but the trap here is that candidates overlook the requirement for symmetric routing in stateful NAT operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The router is performing NAT only for the source IP, but the return traffic is taking a different path that does not go through the NAT router.

The presence of a source NAT translation for the internal host indicates that the router is correctly translating the outbound SSH traffic. However, the absence of the remote server's IP in the NAT translation table suggests that the return traffic from the server is not reaching the NAT router. This typically occurs when the return path takes a different route through the network, bypassing the router that performed the NAT, so the router never sees the reply packets and cannot create the necessary reverse translation entry. As a result, the SSH session times out because the host receives no response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The router is performing NAT only for the source IP, but the return traffic is taking a different path that does not go through the NAT router.

    Why this is correct

    Correct because if the return traffic does not pass through the same NAT router, the router will not create an inbound translation entry, and the packet will not be translated back to the private IP.

  • ✗

    The SSH server is blocking connections from the public IP address.

    Why it's wrong here

    If the SSH server were blocking the public IP, the client would receive a TCP RST or connection refused during handshake, or at most a silent drop at the server's transport layer, not a timeout that occurs after the router has successfully forwarded the translated packet. The observed timeout indicates the client's SYN is translated and sent, but the SYN-ACK never returns, which is characteristic of asymmetric routing where the server's reply traverses a different router without a NAT entry. A server-side ACL would not prevent the router from creating an outbound translation entry either, so the root cause is the missing reverse path, not a policy blocking the public address.

  • ✗

    The NAT overload is causing port conflicts for SSH.

    Why it's wrong here

    NAT overload (PAT) multiplexes many private addresses onto one public IP by allocating a unique source port for each session, leaving the destination port (22 for SSH) unchanged. A port conflict would only occur if two sessions attempted the exact same four-tuple, but PAT's purpose is to avoid that by dynamically assigning distinct source ports, so collisions are effectively prevented. Even in a rare port-allocation hiccup, only one particular flow would be dropped, not all SSH attempts would hang; additionally, the observed timeout is a classic sign of a missing reverse translation, not a problem with creating the outbound translation entry.

  • ✗

    The access list used for NAT is denying the SSH traffic.

    Why it's wrong here

    If the NAT ACL denied SSH, the router would not create a translation entry, so the packets would be forwarded with their original private source IP or dropped based on the ACL's action. That would cause a different symptom: either the server cannot reply to the private IP, or the client times out immediately without any translation occurring. Because the problem states the router is performing NAT for the source IP, the ACL must be permitting SSH and a translation entry is created; the real issue is that the return packets take a different path and bypass the NAT router entirely. Therefore, an ACL denial is inconsistent with the described behavior of a valid outbound translation but no inbound reply.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.