ZNetLab › Published › Lab

Lab: a branch edge — NAT overload and an inbound ACL

LabSecurity@admin1 min read

Lab: a branch edge — NAT overload and an inbound ACL

Thirty hosts, one public address, and a filter on the way back in. The commonest router in the world.

This is the shape of almost every small-office router: an inside network, a single public address, NAT overload, and an access list facing the internet.

Do this

R1(config)# ip nat inside source list 1 interface Gi0/1 overload
R1(config)# ip access-list extended FROM-INTERNET
R1(config-ext-nacl)# permit tcp any host 203.0.113.5 eq 443
R1(config-ext-nacl)# permit tcp any any established

The point

Two separate ideas that look like one. NAT decides which address the packet leaves with; the ACL decides whether it is allowed at all. They are applied at different moments, and the order matters when you start publishing services inbound.

Look at the translation table while traffic is flowing: every row has the same global address and a different port. The port is the key. That is why unsolicited inbound traffic has nowhere to go — there is no row for it.

Try breaking it

nataclsecurityccnalab

Join the discussion

Replies, likes and bookmarks live in the community half, which needs a free account. This lab opens in the browser — no install, no plugin.

Open this in the communityEverything publishedHow this works