IntermediatePublished 2026-07-19
CCNA Foundations: PAT (NAT Overload) — Many Hosts, One IP
Archive lab
CCNA exam domain: IP Services
Deploy Port Address Translation (NAT overload) on an enterprise edge so two inside clients share a single public IPv4 address to reach an external HTTP service on an ISP router. You will designate inside/outside, build the NAT selection ACL, configure the overload rule, and verify simultaneous flows and translations from the end hosts.
Learning objectives
- Configure inside and outside interfaces for NAT on a Cisco IOS edge router
- Author a standard ACL that selects the inside subnet for PAT
- Apply ip nat inside source list <acl> interface <wan> overload using the WAN's public IP
- Verify simultaneous connections from multiple inside hosts to an outside server
- Interpret show ip nat translations and statistics outputs to confirm port multiplexing
Troubleshooting focus
- If hosts cannot reach 203.0.113.1, verify the default route on the edge points at 203.0.113.1 and that the WAN interface is up/up.
- If pings work but HTTP fails, confirm the ISP router's HTTP server is running and reachable (ip http server enabled) and that the NAT ACL actually matches 10.10.10.0/24.
- If show ip nat translations is empty during traffic, check that ip nat inside is on the LAN-facing interface and ip nat outside is on the WAN-facing interface (not reversed).
- If only one host is translated, ensure both clients have the correct default gateway (10.10.10.1) and are in VLAN 10 on the switch access ports.
- For intermittent success, confirm there is no overlapping or wrong subnet mask on the LAN or transit /30; mismatched masks can ARP or route incorrectly.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.