ZNetLab › Published › Question

NAT is configured but show ip nat translations is empty

QuestionRouting@admin1 min read

NAT is configured but show ip nat translations is empty

Branch router, one inside network, one internet link. Hosts cannot reach anything outside. Configuration:

access-list 1 permit 192.168.1.0 0.0.0.255
ip nat inside source list 1 interface GigabitEthernet0/1 overload
!
interface GigabitEthernet0/0
 ip address 192.168.1.1 255.255.255.0
 ip nat inside
!
interface GigabitEthernet0/1
 ip address 203.0.113.5 255.255.255.252

show ip nat translations is empty. The default route is there and the router itself can ping 8.8.8.8.

natpatccnatroubleshooting

1 answer

@admin · 2026-10-09

ip nat outside is missing from GigabitEthernet0/1.

NAT only translates traffic that crosses from an interface marked inside to one marked outside. With only the inside marked, there is no boundary, so no translation is ever created — and because nothing fails loudly, everything in the configuration looks correct. It is the single most common reason show ip nat translations comes back empty.

R1(config)# interface GigabitEthernet0/1
R1(config-if)# ip nat outside

The router itself being able to ping out is the clue that it is not a routing problem: traffic the router originates leaves with the interface's own address and needs no translation at all.

Worth noting for later: the ACL is right as written. It is a wildcard mask — 0.0.0.255, not 255.255.255.0 — which is the other thing that produces exactly this symptom.

Can you answer this?

Replies, likes and bookmarks live in the community half, which needs a free account. Writing here is free too, and everything is reviewed before it is published.

Open this in the communityEverything publishedHow this works