NAT for IPv4 Flashcards
7 cards from real Cisco CCNA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 NAT for IPv4 flashcards as text
A company wants external internet users to reach an internal web server at 10.0.0.5 via the public IP 198.51.100.10. Which NAT type should be used?
Answer: Static NAT
Static NAT creates a permanent one-to-one mapping between a private IP and a public IP, allowing inbound connections to reach internal servers predictably.
What happens to the NAT translation table entry when an idle TCP session times out?
Answer: The entry is removed after the NAT timeout expires
Cisco IOS removes idle dynamic NAT/PAT entries after a configurable timeout (default 24 hours for TCP, 5 minutes for UDP) to reclaim table space.
Which IOS command defines a NAT pool named MYPOOL with addresses 198.51.100.1 through 198.51.100.10 and a /28 mask?
Answer: ip nat pool MYPOOL 198.51.100.1 198.51.100.10 netmask 255.255.255.240
The correct syntax is 'ip nat pool [name] [start-ip] [end-ip] netmask [mask]' — prefix-length is an alternative but 'netmask' is the traditional keyword.
Which Cisco IOS command links an access list to a NAT pool for dynamic translation?
Answer: ip nat inside source list 10 pool MYPOOL
'ip nat inside source list [acl] pool [pool-name]' ties ACL-matched inside source addresses to the specified pool for dynamic NAT.
NAT is often criticized for which networking principle violation?
Answer: It violates end-to-end connectivity by modifying IP headers in transit
NAT violates the end-to-end principle of IP networking because it modifies source/destination addresses in packet headers, breaking transparency between endpoints.
A router uses 'ip nat inside source static tcp 10.1.1.5 80 198.51.100.1 80'. What does this accomplish?
Answer: Forwards external TCP port 80 traffic destined for 198.51.100.1 to internal host 10.1.1.5:80
This static NAT command maps external IP 198.51.100.1 port 80 to internal host 10.1.1.5 port 80, enabling port forwarding for an internal web server.
Which issue arises when two branch offices with overlapping private address ranges connect via a hub site using NAT?
Answer: Routing becomes ambiguous because the same IP range exists on multiple segments
Overlapping private address spaces cause routing ambiguity; a packet destined for 192.168.1.10 could belong to either branch, requiring Twice NAT or VPN with address translation to resolve.