IntermediatePublished 2026-07-18
CCNA Foundations: Dynamic NAT — Translate from an Address Pool
Archive lab
Deploy dynamic NAT on an enterprise edge so multiple inside clients share a pool of public IPs. You will configure an ACL to match inside sources, build a public NAT pool, bind the ACL to the pool, and correctly mark inside/outside interfaces. Validate from end hosts and confirm on-demand translations on the edge router.
Learning objectives
- Identify and mark correct inside and outside NAT interfaces
- Define a public address pool and bind it to an inside source list
- Verify dynamic NAT translation creation and aging using show commands
- Troubleshoot missing translations due to ACL or pool/netmask errors
- Confirm return routing exists toward the pool on the upstream router
Troubleshooting focus
- If pings fail from both hosts: Verify ip nat inside is on the LAN interface and ip nat outside is on the WAN. A reversal prevents translation.; Confirm the ACL actually matches the entire inside LAN as eligible sources.; Check the pool range and netmask (/29 → 255.255.255.248). A wrong mask breaks the ISP’s return route.; Ensure the edge default route to 203.0.113.1 exists and the ISP has a route to the 198.51.100.8/29 pool via 203.0.113.2.
- If only one host works at a time: Ensure you configured a pool with multiple IPs, not a single overload PAT; confirm multiple dynamic entries appear during concurrent pings.
- If
show ip nat translationsis empty: Generate traffic (ping from hosts) and recheck; NAT is on-demand.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.