Computer Networks · Module 5 — Network Layer
NAT
Aisha's 192.168.1.42 is private. No router on the internet knows where that is, and millions of other devices have the same address.
Sign in to track your score
Forty laptops in the hostel are all browsing at once. The internet sees exactly one address:
103.21.58.7. Replies still reach the right laptop every time.
Why & what
Why NAT exists. Aisha's 192.168.1.42 is private. No router on the internet knows where that is, and millions of other devices have the same address.
So a packet leaving the hostel with that source address could never be replied to. Something must swap it for an address the internet can actually reach.
What NAT is. NAT (Network Address Translation) is the router rewriting addresses in packet headers as they pass through.
The version used everywhere is PAT (Port Address Translation), often called NAT overload. It swaps the address and the port, which is what lets many devices share one public address.
Why the port matters. If the router only swapped addresses, two laptops browsing the same site would produce identical packets, and replies would be impossible to sort. By giving each conversation a different outside port number, the router creates a unique label for every conversation.
How it works
- Aisha's laptop sends a packet: source 192.168.1.42:51520, destination 203.0.113.10:443.
- The router picks an unused outside port, say 40001, and writes a row in its NAT table: inside 192.168.1.42:51520 maps to outside 103.21.58.7:40001.
- It rewrites the source to 103.21.58.7:40001 and sends the packet on. The destination is untouched.
- The reply comes back addressed to 103.21.58.7:40001.
- The router looks up 40001 in its table, rewrites the destination back to 192.168.1.42:51520, and delivers it inside.

Common confusion
Students think NAT is a firewall. Actually, NAT is an address translator that happens to block unsolicited incoming traffic as a side effect.
Nothing from outside can reach 192.168.1.42 directly, because there is no NAT table row until Aisha sends something first. That looks protective, and it does help. But NAT does not inspect traffic, does not block anything Aisha herself requested, and does not stop a malicious download. A firewall makes decisions about what to allow. NAT just rewrites headers and keeps a table.
Interview angle
Asked as: "What is NAT and why is it needed?" and the follow-up "how do replies find the right device?": which is where the port matters.
Model answer:
NAT is the translation of private addresses to a public address at the router. It exists because IPv4 addresses ran out, so devices inside a network use reusable private addresses and share one public address on the way out. The common form is PAT, or NAT overload. When a packet leaves, the router replaces the private source address and port with its own public address and a unique port, and records the mapping in a NAT table. When the reply arrives, it matches the port against the table and rewrites the destination back to the original private address. The port number is what keeps hundreds of simultaneous conversations apart on one public IP. NAT also hides internal addresses, but it is not a firewall: it does not inspect or filter traffic.
- 1.
What does the router rewrite when Aisha's packet leaves?
- 2.
How does the router know which laptop a reply belongs to?
- 3.
NAT exists mainly because
- 4.
Which statement is correct?