NAT for IPv4 Flashcards
7 cards from real Cisco CCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 NAT for IPv4 flashcards as text
Which statement about NAT and IPv6 is most accurate from a CCNA perspective?
Answer: IPv6 was designed with sufficient address space to eliminate the need for NAT
IPv6's 128-bit address space provides enough unique addresses for every device globally, removing the address-conservation motivation that drove widespread IPv4 NAT adoption.
A 'show ip nat translations' output shows entries with 'Pro' as '---'. What type of traffic do these entries represent?
Answer: Non-TCP/UDP traffic such as GRE or other IP protocols
The '---' protocol field in NAT translation entries indicates non-TCP/UDP traffic (such as GRE tunnels or other IP protocols) that PAT cannot differentiate by port.
What is the purpose of the 'ip nat translation timeout' command?
Answer: Adjusts how long idle dynamic NAT entries are kept before removal
'ip nat translation timeout [seconds]' configures the idle timeout for dynamic NAT translations before the router removes them from the table.
Which feature allows a Cisco router to apply NAT based on the destination address rather than the source address?
Answer: ip nat inside destination
'ip nat inside destination' translates the destination IP of packets arriving on the inside interface, commonly used for load-balancing to multiple internal servers.
An administrator notices that after configuring NAT, internal users cannot reach the internet. The ACL for NAT is 'permit 192.168.10.0 0.0.0.255'. Users are on 192.168.20.0/24. What is the problem?
Answer: The ACL does not match the users' subnet, so their traffic is not being translated
The ACL only permits 192.168.10.0/24; users on 192.168.20.0/24 don't match, so their source addresses are never translated and packets are dropped or sent untranslated.
Which of the following is a valid benefit of using NAT in an enterprise network?
Answer: NAT enables conservation of public IPv4 addresses by sharing them among many private hosts
NAT's primary benefit is IPv4 address conservation, allowing thousands of private hosts to share a small number of public IP addresses for internet access.
A 'debug ip nat' output shows: 'NAT*: s=10.0.0.1->203.0.113.5, d=8.8.8.8'. What does the '->' indicate?
Answer: The source address is being translated from private to public
The '->' arrow in NAT debug output shows the original address on the left being translated to the address on the right; here the source 10.0.0.1 becomes 203.0.113.5.