NAT and PAT: How Private Networks Reach the Internet

Difficulty: Intermediate

Question

What is NAT? How does PAT let hundreds of devices share a single public IP, and what are the drawbacks of NAT?

Answer

Imagine an office building with 500 employees and one landline number. Employees can call out, and the receptionist notes who called whom, so when a reply comes back she forwards it to the right desk. That receptionist is NAT, Network Address Translation. It sits on the boundary router and rewrites IP headers so that many private addresses can share few public ones.

There are three flavours. Static NAT maps one private IP to one fixed public IP, and is used for servers that must be reachable from outside. Dynamic NAT maps private IPs to a pool of public IPs on a first come first served basis. PAT, Port Address Translation, also called NAT overload or NAPT, maps many private IPs to a single public IP by also rewriting the source port. PAT is what your home router does and what 99 percent of people mean when they say NAT.

Here is the mechanism step by step. Your laptop at 192.168.1.10 opens a connection from source port 51000 to 142.250.190.14 port 443. The router rewrites the source to its public IP 49.36.10.5 with a fresh port, say 62001, and stores a row in its translation table: 192.168.1.10:51000 maps to 49.36.10.5:62001. When the reply arrives at 49.36.10.5:62001, the router looks up the table, rewrites the destination back to 192.168.1.10:51000, and forwards it. Another laptop using the same source port 51000 would simply be given a different external port, which is why the port number is the key that multiplexes many hosts onto one IP. The router also recomputes IP and TCP checksums after rewriting.

The important consequence is that NAT is naturally outbound-only. An unsolicited inbound packet finds no table entry and is dropped. That gives an accidental security benefit, but it is not a real firewall. To host a server behind NAT you need port forwarding (a static mapping of external port 8080 to internal 192.168.1.20:80).

Drawbacks are what interviewers really want. NAT breaks the end-to-end principle: two devices behind different NATs cannot directly connect, which hurts peer-to-peer apps, VoIP and online gaming, and forces techniques such as STUN, TURN and ICE (used by WebRTC) and hole punching. Protocols that embed IP addresses in payloads, like FTP active mode and SIP, need an ALG to fix the payload. The router must keep state, costs memory and CPU, and has a port limit of about 65000 per public IP. Logging is harder because many users share one IP. And carrier-grade NAT, used by mobile ISPs, puts an ISP-level NAT in front of your home NAT, which is why some Indian mobile connections cannot host anything.

Connect this to IPv6: with 128-bit addresses, every device can have a public address and NAT is not needed for scarcity. A neat closing edge case: NAT entries time out, typically after a few minutes for UDP and a few hours for established TCP, which is why long idle connections through NAT sometimes die silently and applications add keepalive packets.

Code examples

A NAT translation table

Inside local        Inside global         Destination
192.168.1.10:51000  49.36.10.5:62001     142.250.190.14:443
192.168.1.11:51000  49.36.10.5:62002     142.250.190.14:443
192.168.1.12:40222  49.36.10.5:62003     104.16.85.20:443

$ sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

The iptables MASQUERADE rule is how a Linux box does PAT. Two hosts used source port 51000 but got distinct external ports.

Key points

Concepts covered

NAT, PAT, Private IP, Port Translation, Translation Table