IntermediatePublished 2026-07-02
PAT onto the Outside Interface (SOHO Edge)
Bundle lab
Implement and verify interface-based PAT (overload) on a single-edge SOHO router. Inside hosts on 192.168.10.0/24 share the router’s lone public IP (203.0.113.1) on its outside interface. Validate NAT translations, ACL matches, and simultaneous host access, and practice troubleshooting common misconfigurations (inside/outside role reversal, ACL selection errors).
Learning objectives
- Configure PAT directly on the WAN interface using ip nat inside source list <id> interface <wan> overload
- Correctly mark ip nat inside and ip nat outside on the appropriate interfaces
- Author a standard ACL that selects the inside source subnet for translation
- Validate NAT operations with show ip nat translations, show ip nat statistics, and ACL hit counts
- Test from inside endpoints to confirm both hosts share the same public IP with unique ports
- Troubleshoot failures caused by incorrect interface role marking or ACL mismatches
Troubleshooting focus
- NAT not creating translations because inside/outside roles are reversed
- ACL used for NAT source selection is empty/mismatched (no hits)
- Routing to the ISP works but return traffic appears broken due to missing/wrong NAT
- Outside-initiated traffic fails as expected (no static mappings) while inside-initiated flows succeed
- Mis-typed interface in the NAT rule (overload bound to the wrong interface)
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.