Lab: a branch edge — NAT overload and an inbound ACL
Thirty hosts, one public address, and a filter on the way back in. The commonest router in the world.
This is the shape of almost every small-office router: an inside network, a single public address, NAT overload, and an access list facing the internet.
Do this
- Mark the inside and outside interfaces.
- Write an ACL matching the inside network — with a wildcard mask.
- Add the
ip nat inside source list ... overloadstatement. - Ping out from a PC and read
show ip nat translations. - Then write an inbound ACL on the outside interface that permits only
R1(config)# ip nat inside source list 1 interface Gi0/1 overload
R1(config)# ip access-list extended FROM-INTERNET
R1(config-ext-nacl)# permit tcp any host 203.0.113.5 eq 443
R1(config-ext-nacl)# permit tcp any any established
The point
Two separate ideas that look like one. NAT decides which address the packet leaves with; the ACL decides whether it is allowed at all. They are applied at different moments, and the order matters when you start publishing services inbound.
Look at the translation table while traffic is flowing: every row has the same global address and a different port. The port is the key. That is why unsolicited inbound traffic has nowhere to go — there is no row for it.
Try breaking it
- Remove
ip nat outsideand watch the translation table stay empty while - Write the ACL with a subnet mask instead of a wildcard and see what matches.
- Put the
permit ... establishedline above the specific permit and read the
Join the discussion
Replies, likes and bookmarks live in the community half, which needs a free account. This lab opens in the browser — no install, no plugin.
Open this in the communityEverything publishedHow this works