Professional Documents
Culture Documents
qxd
7/14/06
11:48 AM
Page 51
Lab 10
NAT Overload (PAT)
This CCNA Video Mentor (CVM) lab shows how to configure Network Address Translation (NAT),
specifically using the Port Address Translation (PAT) or overload feature. In particular, the objectives
of this lab are as follows:
Port numbers to support thousands of connections using a single Inside Global IP address
Configure NAT overload (PAT) using a single interface IP address for the Inside Global IP
address
Scenario
This lab contains two main steps, as follows:
Step 1.
Review the terms associated with the typical use of NAT and PAT with an Internet
connection and see NAT working in a router.
Step 1.
Initial Configurations
Example 10-1 shows the pertinent initial configuration of router R1 in the lab video. Note that this lab
begins with R1 having a valid NAT/PAT overload configuration, using the Inside Global IP address of
R1s S0/1/0 interface (100.1.1.2). As usual, the parts of the configurations not relevant to this lab have
been omitted.
Example 10-1
hostname R1
!
ip nat inside source list 3 interface serial 0/1/0 overload
!
interface FastEthernet 0/0
ip address 172.22.11.1 255.255.255.0
ip nat inside
!
1682_ch10.qxd
52
7/14/06
11:48 AM
Page 52
Example 10-1
continued
Ending Configurations
This lab video does not change the router configuration.
The
Internet
172.22.11.101
PC1
S0/1/0
Fa0/0
172.22.11.1
R1
100.1.1.2
S0/1/0
100.1.1.1
ISP-1
PC2
172.22.11.102
Private Network
172.22.0.0
Web Server
9.1.1.1
Because the video is organized into two separate steps, the reference materials have been organized into two separate sections.
1682_ch10.qxd
7/14/06
11:48 AM
Page 53
Step 1 Reference
Figure 10-2
Inside
My Network
Outside
The Rest of
the World
S0/1/0
R1
100.1.1.2
Figure 10-3
172.22.11.101
PC1
S0/1/0
Fa0/0
172.22.11.1
R1
100.1.1.2
PC2
S0/1/0
100.1.1.1
ISP-1
NAT Table
172.22.11.102
Private Network
172.22.0.0
Inside Local
Inside Global
172.22.11.101 : 3212
100.1.1.2 : 3212
172.22.11.102 : 3212
100.1.1.2 : 3213
First Connection
Dest. Source:
Dest. Port: Source Port:
9.1.1.1 172.22.11.101 80
3212
Dest. Source:
9.1.1.1 100.1.1.2
Second Connection
Dest. Source:
Dest. Port: Source Port:
9.1.1.1 172.22.11.102 80
3212
Dest. Source:
9.1.1.1 100.1.1.2
Web Server
9.1.1.1
The
Internet
53
1682_ch10.qxd
54
7/14/06
11:48 AM
Page 54
Figure 10-4
172.22.11.101
PC1
R1
Web Server
9.1.1.1
PC2
Source IP 172.22.11.102, Source Port 13109
172.22.11.102
Step 2 Reference
Figure 10-5
Inside
My Network
Outside
The Rest of
the World
Fa0/0
172.22.11.1
Interface Fa0/0
ip nat inside
Figure 10-6
S0/1/0
R1
100.1.1.2
Interface S0/1/0
ip nat outside
NAT Packets
Entering an
Inside Interface
Source Addresses
That Should Be
NATed
Do Overload
(PAT)