NAT
Network Address Translation
- Pronunciation
- NAT
In short
NAT is a technique in which a router rewrites the IP addresses in passing packets, letting many devices on a private network share one public IP address.
What is NAT?
NAT, or Network Address Translation, is a method routers use to change the IP addresses, and often the port numbers, in packets as they pass between two networks. Its most common job is letting every device on a home or office network, each with a private address such as 192.168.1.20, reach the internet through a single public IP address. Without NAT, the world would have run out of IPv4 addresses much sooner.
When a device sends a request to the internet, the router replaces the packet's private source address and port with its own public address and a port it chooses, and it records that mapping in a translation table. When the reply comes back to that public port, the router looks up the table, rewrites the destination back to the device's private address, and forwards the packet inside. This many-to-one form is technically called port address translation (PAT), or masquerading on Linux, but most people simply call it NAT.
An analogy is an office receptionist with one public phone number: every outgoing call shows the main number, and the receptionist remembers who called whom, so replies reach the right desk. NAT runs in almost every home router, in mobile carrier networks, where one public address may be shared by many customers (carrier-grade NAT), and in the cloud, where a NAT gateway lets servers in a private subnet download updates without being reachable from the internet.
NAT is often mistaken for a firewall. Because unsolicited incoming traffic has no matching entry in the translation table, NAT does block it as a side effect, but it isn't a security feature and doesn't filter traffic by rules. NAT also makes incoming connections harder, which is why hosting a server behind a home router requires port forwarding and why peer-to-peer apps and video calls use NAT traversal techniques. IPv6 has enough addresses for every device, so it largely removes the need for NAT.
Key takeaways
- NAT rewrites IP addresses, and usually ports, as packets cross a router.
- It lets many devices with private addresses share one public IPv4 address.
- The router keeps a translation table so replies reach the right internal device.
- Incoming connections need port forwarding, because NAT has no mapping for them by default.
- NAT hides internal addresses but is not a replacement for a firewall.
Example
# 1. Allow the kernel to forward packets between network interfaces
sudo sysctl -w net.ipv4.ip_forward=1
# 2. Rewrite outgoing packets from the private network to this machine's public IP
sudo iptables -t nat -A POSTROUTING -s 10.0.0.0/24 -o eth0 -j MASQUERADE
# 3. Port forwarding: send incoming traffic on port 8080 to an internal web server
sudo iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 8080 -j DNAT --to-destination 10.0.0.5:80
# List the NAT rules
sudo iptables -t nat -L -n -vReaders ask
Is NAT a firewall?
No. NAT blocks unsolicited incoming connections as a side effect, because the router has no mapping for them, but it doesn't inspect traffic or filter it by rules. You still need a real firewall for security.
What is port forwarding?
Port forwarding is a fixed NAT rule that sends incoming traffic on a specific public port to a chosen device and port inside the private network. It is how you make a server behind a home router reachable from the internet.
Does IPv6 use NAT?
Usually not. IPv6 has enough addresses to give every device a public one, so NAT isn't needed to save addresses, and a firewall is used instead to block unwanted incoming traffic.
See also
- IP AddressNetworking, p. 10An IP address is a numeric label assigned to each device on a network so that data can be routed to it, much like a postal address for a house.
- SubnetNetworking, p. 29A subnet is a smaller network carved out of a larger one by splitting its range of IP addresses, which keeps traffic organized, contained, and easier to secure.
- FirewallNetworking, p. 8A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.
- PortNetworking, p. 22A port is a number from 0 to 65535 that identifies a specific program or service on a device, so traffic reaching an IP address gets to the right application.
- PacketNetworking, p. 20A packet is a small, formatted unit of data sent across a network, made of a header with addressing information and a payload that carries the actual data.
- DHCPNetworking, p. 6DHCP is a network protocol that automatically gives devices an IP address and other settings, such as the router and DNS server, when they join a network.
Spotted a mistake or something missing on this page?Suggest an edit