What Is NAT (Network Address Translation)?

Related problems: Only a handful of public IP addresses for a whole office of devices; Remote access, VoIP or a hosted server breaks behind our firewall; Two networks we're joining after an acquisition use the same private address ranges; Not sure why an outside service sees all our users as one IP address

Network Address Translation (NAT) is a technique where a router or firewall rewrites the IP addresses in packets as they pass between two networks. Its most familiar use lets many devices on a private network, using private IPv4 addresses, share one or a few public IP addresses to reach the internet. NAT also lets organizations publish a server to the internet, join networks with overlapping address ranges, and hide internal addressing from the outside. It became standard because public IPv4 addresses are scarce.

At a glance

  • NAT rewrites source or destination IP addresses, and often ports, as packets cross a router or firewall.
  • Port Address Translation (PAT), a common form, lets many private devices share one public IPv4 address.
  • Static NAT maps one private address to one public address, often to publish a server or service.
  • NAT can complicate VoIP, VPNs and other protocols that embed addresses inside their traffic.
  • With IPv6’s large address space, NAT for address sharing is usually unnecessary.

What problem it solves

The IPv4 address space has about 4.3 billion addresses, far fewer than the devices now online. Private address ranges let organizations number their internal devices freely, but those addresses cannot be routed on the public internet. Without NAT, every laptop, phone and printer that needed internet access would need its own public address, which most organizations could not get.

NAT bridges the two. Inside, devices use private addresses. At the edge, the router or firewall translates them to the organization’s public addresses for outbound traffic and maps replies back. This lets an office of hundreds of devices browse the web and use cloud services through a single public address, and lets the organization change its internal numbering without involving its provider.

How it works

Outbound translation (PAT). When a device sends a packet to the internet, the network firewall or router replaces its private source address with a public one and assigns a unique source port. It records this mapping in a translation table. When the reply returns, it uses the table to send the packet back to the right device.

Static NAT and port forwarding. To make an internal server reachable from the internet, the firewall maps a public address, or a public address and port, to the server’s private address. This usually uses one of the organization’s static IP addresses.

Twice NAT and overlapping networks. When two networks use the same private ranges, such as after a merger or when connecting to a partner, NAT can translate both sides so they can communicate without immediate renumbering. This is a common interim fix in VPN designs.

Protocol side effects. Some protocols embed IP addresses or negotiate ports inside their traffic. SIP voice, some VPN types and certain gaming or peer-to-peer apps may need helper features, NAT traversal methods or devices such as a session border controller to work reliably. Logging is also affected: outside services see the public address, so tracing activity to a user needs the translation logs.

IPv4 and IPv6. NAT is mostly an IPv4 tool. IPv6 has enough space to give every device a globally unique IP address, so firewalls control access without translation, though some translation mechanisms help IPv6 and IPv4 networks interoperate.

To design firewall and NAT policy for your sites, see our Network Firewalls solution page.

When it matters for buyers

  • Deploying VoIP or UCaaS. Ask how the provider handles NAT traversal and whether firewall settings need changing.
  • Publishing services. Hosting a server, VPN endpoint or camera system from the office needs static addresses and NAT rules.
  • Mergers and acquisitions. Overlapping address ranges are common, and NAT is often the bridge until networks are renumbered.
  • Choosing an internet service. Some broadband, cellular and satellite services put customers behind carrier-grade NAT, which can block inbound access.
  • Security and audit. Keep translation logs long enough to trace an outside report back to an internal user.

Questions to ask vendors

  • Does this service give us public IPv4 addresses, or are we behind carrier-grade NAT?
  • How many static public addresses are included, and what do more cost?
  • How does your voice or VPN service handle NAT traversal, and what firewall settings do you need?
  • Do you support IPv6, so we can reduce our reliance on NAT over time?
  • Will the managed firewall log translations, and for how long are logs kept?
  • How would you handle overlapping private address ranges when connecting to our partners or acquired sites?

How it differs from carrier-grade NAT (CGNAT)

Ordinary NAT runs at the edge of your own network, usually on your firewall, and translates your private addresses to public addresses you control. Carrier-grade NAT runs inside the provider’s network and shares the provider’s public addresses among many customers. Behind CGNAT, your connection may not have its own public address at all, which can stop inbound access, port forwarding and some VPNs. Many connections behind CGNAT also use ordinary NAT on the customer’s router, so traffic is translated twice.

Frequently Asked Questions

Is NAT a security feature?
Not by itself. NAT commonly blocks unsolicited inbound connections as a side effect, because the router has no mapping for them, but it is not designed as a security control. A firewall with explicit rules is what should decide what traffic is allowed.
What is the difference between NAT and PAT?
Port Address Translation (PAT), also called NAT overload, is a common form of NAT that maps many private addresses to one public address by also changing port numbers. Most office routers and firewalls use PAT for outbound internet access. Other forms of NAT map addresses one to one without using ports.
Do we need NAT with IPv6?
Usually not. IPv6 has enough addresses for every device to have a globally unique one, so NAT is not needed for address sharing. Organizations rely on firewalls to control access instead. Some use IPv6 prefix translation for specific designs, but it is less common.
Why does VoIP have trouble with NAT?
Voice protocols such as SIP often carry IP addresses and ports inside the call signaling. If NAT changes the packet headers but not those embedded details, audio may fail to flow in one or both directions. Session border controllers, SIP-aware firewalls and provider NAT-traversal features are common fixes.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.