Network Address Translation (NAT)

Rewriting of IP addresses in packet headers as traffic crosses a boundary device, so hosts on privately addressed networks can reach the internet through public addresses.

Network Address Translation rewrites the source or destination address in an IP header as a packet passes through a router or firewall, and reverses it on the return path. RFC 3022 describes the traditional form used at an organisation’s edge. It exists mainly because IPv4 addresses ran short. Hosts inside the network use private IP addresses, and the edge device maps them to public ones. Static NAT maps one internal address to one public address permanently; dynamic NAT assigns addresses from a pool.

The common variant maps many internal hosts to a single public address by translating ports as well, which is Port Address Translation (PAT). As a side effect, outsiders see only the public address, and unsolicited inbound traffic has no mapping to follow unless one has been configured. That is a by-product of address translation, not a filtering policy, so NAT does not replace a firewall. NAT also alters the header that some protocols protect, which is why IPsec in its AH form, whose integrity check covers the addresses, does not survive it.

Exam relevance: a scenario about conserving IPv4 addresses, or about hiding an internal addressing scheme from the internet, is likely to point to NAT. Candidates are expected to keep straight that NAT is an addressing mechanism with a security side effect, not a security control in its own right.