Implement Network Address Translation and Port Address Translation

Practice Labs Module
Time
38 minutes
Difficulty
Intermediate

The "Implement Network Address Translation and Port Address Translation" module provides you with the instructions and Cisco hardware to develop your hands on skills in the following topics: Translating inside source addresses, Overloading inside source addresses.

Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
or

Already have an account? Sign In »

Overview

Introduction

The Implement Network Address Translation and Port Address Translation module provides you with the instructions and Cisco hardware to develop your hands on skills in the following topics:

  • Translating inside source addresses
  • Overloading inside source addresses

Exercise 1 - Translating Inside Source Addresses

In this exercise you will learn how to configure and verify network address translation, translating inside hosts (on the 192.168.16.0/24 subnet) such that they get a new source IP address as they pass out of router NYEDGE1.

In this example we will use 2 different source hosts NYCORE1 and NYCORE2 to use different translation methods so that they get new IP addresses on the 172.14.0.0/24 subnet to enable communication to devices on this subnet.

NYEDGE1 is configured as the default gateway for NYCORE1, NYCORE2 and PLABCSCO01, it has interfaces in the 192.168.16.0/24 subnet and 172.14.0.0/24 subnet (see diagram below), NYEDGE2 on the other hand only has an interface configured on the 172.14.0.0/24 subnet, it has no routing configured so it is unaware of the 192.168.16.0/24 subnet at all.

This makes it a prime candidate to test our NAT configuration, we will translate PLABCSCO01 such that it gets a 172.14.0.x address and NYEDGE2 is able to communicate to it.

There is also another device (actually 2) that you do not have access to that can be used as test remote devices. These also don’t have any configuration to understand the 192.168.16.0/24 subnet so they too are good test candidates.

Exercise 2 - Overloading Inside Source Addresses

In this exercise you will configure PAT such that PLABCSCO01 can browse to the website www.practice-labs.com, this is hosted on a shared infrastructure server which is only accessible if you configure NAT correctly.

Learning Partner
Comprehensive Learning

See the full benefits of our immersive learning experience with interactive courses and guided career paths.