IntermediatePublished 2026-07-02
CCNA NAT3: Dynamic NAT with an Address Pool
Bundle lab
Configure dynamic one-to-one NAT using a public address pool on an IOS router between a private LAN and a simulated ISP. Two inside hosts draw from a two-address public pool on-demand. Validate that no translations exist before traffic, that each host receives a distinct global address after generating traffic, and that entries age out when idle.
Learning objectives
- Mark inside vs. outside interfaces correctly so translations occur only across the edge
- Build a dynamic NAT pool and bind it to an ACL that matches inside sources
- Verify on-demand translations with show ip nat translations/statistics
- Differentiate dynamic NAT pool behavior from PAT overload
- Troubleshoot translation failures due to ACL scope, interface role, or routing
Troubleshooting focus
- Inside/outside roles reversed so no translation occurs
- ACL 1 does not match the intended inside subnet (mask vs wildcard mismatch)
- Pool addresses not on or reachable from the outside segment
- Missing default route on the NAT router
- Testing from the outside expecting inbound initiation (dynamic NAT does not create inbound reachability)
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.