IntermediatePublished 2026-07-02
NAT at the Internet Edge with Default Routing
Bundle lab
Build an Internet-edge NAT design that reaches beyond the ISP to a real external network. You will configure dynamic PAT (overload) from a private LAN to a public /29 using a NAT pool on the edge router, with the router’s default route already pointing to the ISP. Verify that an inside host can reach a public server across the ISP and that translations, counters, and default routing reflect the expected state.
Learning objectives
- Identify inside vs outside interfaces and why NAT only translates traffic crossing between them
- Configure dynamic PAT using a NAT pool with an ACL source selector
- Leverage an existing default route so routing works before translation
- Verify translations with show ip nat translations/statistics and ACL hit counts
- Test end-to-end reachability from an inside host to a true external network
Troubleshooting focus
- If pings from the inside fail, confirm inside/outside roles are correct on the edge router interfaces.
- Check that the NAT ACL matches the inside subnet exactly and isn’t shadowed by an unintended ACE.
- Make sure the public NAT pool lies within the connected outside /29 so the ISP can ARP and return traffic succeeds.
- Confirm the default route on the edge router points to the ISP next hop (not to itself).
- Validate that hosts have the right gateway and mask; the router should already forward before NAT.
- Observe NAT statistics; zero hits means translation is not being triggered by inside-to-outside flows.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.