Port Address Translation (PAT)
A form of NAT in which many internal hosts share one public IP address, distinguished by translating each session's source port as well as its address.
Port Address Translation extends Network Address Translation so that a whole network of hosts using private IP addresses can reach the internet through a single public address. When an internal host opens a connection, the edge device rewrites the source address to the public one and, where needed, assigns a new source port, recording the pairing in a translation table. Replies arriving at that public address and port are matched against the table and sent back to the right internal host. RFC 3022 calls this Network Address Port Translation; it is also known as NAT overload.
Because the table only holds entries for sessions opened from inside, unsolicited inbound connections have nowhere to go and are dropped unless a port is forwarded deliberately. That is sometimes mistaken for a firewall, but no policy lies behind it. PAT also rewrites headers that some protocols depend on: IPsec needs NAT traversal, which wraps its traffic in UDP, and protocols that carry addresses inside their payload, such as SIP, need helper functions to work through it.
Exam relevance: a scenario in which many internal hosts share one public address is likely to point to PAT rather than static or dynamic NAT. Candidates are expected to see that it hides internal addresses but is not an access control.