hardMultiple Choice
350-401 Practice Question: Is configuring NAT on a Cisco router to allow…
A network engineer is configuring NAT on a Cisco router to allow internal hosts to access the internet. The engineer uses the command ip nat inside source static tcp 192.168.1.10 80 203.0.113.1 80. After testing, external users can access the internal web server using the public IP. However, internal hosts cannot access the web server using the public IP. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that static NAT entries automatically handle internal-to-public traffic, when in fact hairpinning must be explicitly configured to allow traffic from the inside network to be translated and reflected back to another inside host.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The router does not have NAT hairpinning enabled, so internal traffic to the public IP is not translated.
The issue is that NAT hairpinning (also known as NAT reflection or NAT loopback) is not enabled by default on Cisco IOS. When an internal host sends traffic to the public IP address (203.0.113.1), the router sees the destination as its own outside interface IP and forwards the packet out that interface without performing the static NAT translation. The packet never reaches the internal web server (192.168.1.10). To fix this, the engineer must enable hairpinning using the 'ip nat enable' command on the inside interface or configure a route-map to force the router to translate traffic sourced from the inside network destined to the public IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The router does not have NAT hairpinning enabled, so internal traffic to the public IP is not translated.
Why this is correct
Without NAT hairpinning, the router treats a packet from an inside host to the inside server's public IP as inside-to-inside traffic. By default, Cisco IOS applies NAT only to packets crossing a NAT boundary between inside and outside interfaces, so the destination translation is never consulted. Consequently, the public IP is not translated to the private server address and the packet fails. To enable this, you must explicitly configure hairpinning, for example with 'ip nat enable route-map' on the involved interfaces.
- ✗
The static NAT entry is missing the extendable keyword.
Why it's wrong here
The 'extendable' keyword is used when multiple static NAT entries share the same global IP address or when you need to support overlapping address pools across multiple outside interfaces. It does not alter the fundamental rule that NAT is applied only to traffic that traverses the inside-to-outside or outside-to-inside boundary. A missing 'extendable' keyword would only cause a configuration conflict if you tried to add a second static mapping for the same public IP; it is unrelated to the hairpinning failure, which occurs because the packet never leaves the inside zone.
- ✗
The internal hosts have a route to the public IP via the router's outside interface.
Why it's wrong here
Even if internal hosts have a route pointing to the router's outside interface for the public IP, the core problem remains that the router will not perform destination NAT on a packet that enters and exits the same NAT zone. The packet might be routed toward the outside interface, but the translation table is not examined because the packet did not cross an outside-to-inside boundary. Therefore, the existence of a route does not cause the public IP to be translated; the missing hairpinning configuration is still the sole reason the traffic fails.
- ✗
The access list used for NAT is blocking internal traffic.
Why it's wrong here
Static NAT entries are configured with 'ip nat inside source static' and are not associated with an access list; they are direct one-to-one address mappings. An ACL could only influence NAT if the configuration were dynamic ('ip nat inside source list') or route-map based. In this scenario, no ACL is evaluated for the static translation of the destination address, so it cannot be the cause of the failure. The lack of hairpinning is the only plausible explanation for internal traffic to the public IP not being translated.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.