Blog

Networking articles

What Is NAT and How Does It Work?

What is NAT? How network address translation rewrites addresses, the main types from PAT to CGNAT, cloud NAT gateways, and what NAT can and cannot protect.

4 min read Networking

Twenty laptops, a few phones and a printer in your office all reach the internet, yet the outside world sees them as one IP address. The technology doing that sleight of hand is NAT, Network Address Translation. If you have ever wondered what is NAT and why it keeps appearing in router settings, VPN guides and cloud network diagrams, this article explains how it works and the variations you are likely to meet.

The basic idea

NAT is a function in a router or firewall that rewrites the IP addresses (and often the port numbers) in packets as they pass through. Its most common job is translating between private addresses used inside a network, such as 192.168.1.20, and a public address that is valid on the internet, such as 203.0.113.45. It was introduced as a stop-gap to stretch the limited supply of IPv4 addresses, and became a permanent fixture of almost every network.

How NAT works, packet by packet

Suppose a laptop at 192.168.1.20 loads a web page from a server at 198.51.100.7:

  1. The laptop sends a packet from 192.168.1.20:51334 (its address and a temporary source port) to 198.51.100.7:443.
  2. The router replaces the source with its own public address and a port it chooses, say 203.0.113.45:40001, and records the mapping in its translation table.
  3. The web server replies to 203.0.113.45:40001. It has no idea the laptop exists.
  4. The router looks up port 40001 in its table, rewrites the destination back to 192.168.1.20:51334, and delivers the reply.

The translation table might look like this at any given moment:

Inside address:portPublic address:portDestination
192.168.1.20:51334203.0.113.45:40001198.51.100.7:443
192.168.1.31:62010203.0.113.45:40002198.51.100.7:443
192.168.1.20:51340203.0.113.45:40003192.0.2.10:993

Because the router distinguishes conversations by port, thousands of connections from many devices can share one public address. Entries expire after a period of inactivity, which is why very long idle connections sometimes drop and why some applications send "keep-alive" messages.

Types of NAT

PAT / NAT overload / masquerading

What the example above describes is technically Port Address Translation (PAT), also called NAT overload, or masquerading in Linux terminology. Many private addresses share one public address, separated by port numbers. When people say "NAT" in everyday conversation, this is almost always what they mean. On a Linux server acting as a router, it can be enabled with a rule like:

sudo iptables -t nat -A POSTROUTING -s 10.0.0.0/24 -o eth0 -j MASQUERADE

(IP forwarding must also be enabled, and newer systems may use nftables rather than iptables.)

Static NAT (one-to-one)

One private address is permanently mapped to one public address, in both directions. This is used when an internal server needs its own public identity. Cloud "elastic" or "static" public IPs attached to a virtual machine are often implemented this way: the VM itself only knows its private address, and the provider's network translates.

Destination NAT and port forwarding

Ordinary PAT handles connections that start inside. For connections that start outside, the router needs a destination NAT rule saying which internal device should receive them. In home and office routers, this is the "port forwarding" setting.

Carrier-grade NAT (CGNAT)

Internet providers short of IPv4 addresses apply NAT themselves, so many customers share one public address. Your router gets an address from the shared range 100.64.0.0/10 (or another private range), then NATs again. This "double NAT" makes inbound connections impossible without help from the provider. A quick sign of CGNAT: the WAN address on your router differs from what What Is My IP reports.

NAT64

Translates between IPv6 and IPv4, letting IPv6-only devices (common on some mobile networks) reach IPv4-only services. It usually works alongside DNS64, which synthesizes IPv6 addresses for IPv4-only names.

NAT in the cloud

Cloud networks use NAT heavily. A typical design places application and database servers in private subnets with no public addresses. They still need outbound internet access for software updates and API calls, so traffic goes through a managed NAT gateway in a public subnet. The servers can reach out; nothing on the internet can reach in. Note that managed NAT gateways are usually billed by the hour and by data processed, which can become noticeable with heavy outbound traffic, so it is worth reviewing in any cloud architecture.

When designing private ranges for these networks, a subnet calculator helps avoid overlaps with your office or VPN ranges.

What NAT does and does not do for security

NAT has a useful side effect: unsolicited inbound connections have no matching table entry, so they are dropped. That hides internal devices from casual scanning. But NAT is not a firewall and should not be relied on as one:

  • It does nothing about malicious traffic on connections your devices start themselves, such as malware calling home or a user visiting a harmful site.
  • Port forwards, UPnP and DMZ settings deliberately punch holes through it.
  • IPv6 networks usually do not use NAT at all; devices have globally routable addresses, and a proper stateful firewall does the protecting.

Use an explicit firewall policy regardless of NAT.

Common problems NAT causes

  • Inbound access: hosting services or remote access requires port forwarding or a VPN.
  • VPN and VoIP quirks: some protocols embed IP addresses inside the data. Features like IPsec NAT traversal (UDP 4500) and SIP helpers exist to work around this, sometimes imperfectly.
  • Shared reputation: under CGNAT, another customer's abuse can get a shared public address blocked or flooded with CAPTCHAs.
  • Logging: an external log shows only the public IP; you need router logs to map it back to an internal device.

Key takeaways

  • NAT rewrites addresses so many private devices can share a public IP, tracking each conversation in a translation table.
  • Everyday "NAT" is really PAT; static NAT, destination NAT, CGNAT and NAT64 are variations.
  • Cloud NAT gateways give private servers outbound access without exposing them.
  • NAT hides devices but is not a firewall; always configure explicit filtering.

Need help with this?

Netifi helps businesses around the world with Networking. Tell us what you are working on.