Schedule DemoStart Free Trial

Unified Observability Platform for Modern IT Operations

Summarize with AI what Motadata does:

ObserveOps

  • Network Observability
  • Network Configuration & Compliance Management
  • Hybrid Infrastructure Monitoring
  • Log Monitoring
  • Application Performance Monitoring
  • Real User Monitoring

ServiceOps

  • Service Management
  • IT Asset & Configuration Management
  • Patch & Deployment Management
  • Agentic AI & Orchestration
  • MSP Edition

By Use Cases

  • Data Centre Monitoring
  • Docker Monitoring
  • Enterprise Service Management
  • IT Service Desk
  • ITSM MSP
  • Enterprise Network Monitoring

By Technologies

  • AWS Monitoring
  • Azure Monitoring
  • Kubernetes Monitoring
  • DevOps Observability
  • REST API Monitoring
  • Storage Monitoring

Resources

  • Getting Started
  • Documentation
  • Integrations
  • IT Glossary
  • Whitepapers
  • Ebooks & Guides
  • Product Brochures
  • Success Stories
  • Comparison
  • Features

Community

  • Blog
  • Press Releases
  • Events
  • Webinar
  • Become a Partner

Company

  • Company
  • Careers
  • Contact Us
  • Customer Support

Get in Touch

  • Request Demo
  • sales@motadata.com
  • support@motadata.com
© 2026 Mindarray Systems Limited. All rights reserved.
Privacy PolicyTerms of Service
Back to IT Glossary
IT Resources

Network Address Translation (NAT)

What Is Network Address Translation (NAT)?

Network address translation (NAT) is a method routers and firewalls use to rewrite the IP addresses in data packets as traffic moves between a private network and the public internet. Internal devices carry addresses the internet can't route to.

When one of those devices opens an outbound connection, NAT substitutes a public address for the private one. It also logs the swap, which is how replies find their way back to the machine that asked for them.

A home Wi-Fi router shows this in action. A laptop, two phones and a smart TV may all be online at once, yet every website on the other end sees a single public address, which belongs to the router.

Home routers use NAT, as do branch routers, enterprise firewalls and cloud gateways, so in practice it turns up at almost any point where private addressing meets the public internet.

IPv4, the 32-bit addressing scheme much of the internet still depends on, ran short of public addresses a long time back. NAT is a big part of why it has kept functioning since.

How Does NAT Work?

NAT does most of its work at the edge of the network. It rewrites packet headers, the addressing information carried in front of the data, and tracks every conversation in a translation table.

Take an outbound connection, which moves through four steps:

  1. Say a laptop requests a page from an external server; its packet leaves with the laptop's private address in the source field.

  1. At the router or firewall, that private address comes out and a public one goes in, often with a new source port attached.

  1. Before forwarding anything, the router records the pairing in its NAT table, which is simply a short-lived list matching private addresses to public ones.

  1. Replies arrive addressed to the public side. The router finds the matching entry, puts the original private address back and delivers the packet internally.

Idle entries expire after a while. And because private ranges are planned with subnetting, identical internal addresses can repeat across separate networks without conflict.

What Are the Types of NAT?

NAT comes in three main types. The difference lies in how many internal devices end up sharing each public address.

Type

How addresses map

Typical use

Static NAT

One private address to one fixed public address

Servers that must stay reachable from outside, such as web or mail servers

Dynamic NAT

Private addresses to a temporary public address drawn from a pool

Networks with a block of public addresses and a limited number of hosts needing outside access

PAT (NAT overload)

Many private addresses to one public address, told apart by port number

Home routers, branch offices and most enterprise internet access

PAT keeps many private addresses apart behind one public address by using port numbers, values that identify a specific application session on a device. It runs on most home routers and in branch offices, and on a large share of enterprise internet links too.

Two related terms often come up alongside these types:

  • Carrier-grade NAT (CGNAT): A further layer of translation that internet providers operate on their own equipment.

  • Port forwarding: A fixed rule directing inbound traffic on a chosen port to one specific internal device.

What Are Inside and Outside Addresses in NAT?

NAT describes a packet before and after translation using four address labels:

  • Inside local: The private address assigned to an internal device.

  • Inside global: The public address that device shows externally.

  • Outside global: The address of the remote host on the far side.

  • Outside local: How that same host is seen from inside the network, which usually turns out to be identical to the outside global address.

Why Is NAT Important?

NAT is important mainly because of scale. A large private network can get online with only a handful of public IPv4 addresses shared across all its devices.

  • Address conservation: Sharing addresses this way has slowed IPv4 exhaustion considerably.

  • Reduced exposure: Internal addresses stay hidden from outside view, and any unsolicited inbound packet without a matching table entry is dropped. Hiding an address doesn't inspect traffic, however, so access control lists and firewall inspection still need to do that work.

  • Addressing flexibility: An organization can switch internet providers or public ranges and leave its internal addressing untouched.

What Are the Limitations of NAT?

Most limitations of NAT trace back to one thing. It changes addresses that some applications expect to stay fixed from end to end.

  • Broken inbound reachability: External hosts can't open a session with an internal device unless a static mapping or port forward is in place.

  • Protocol friction: Voice over IP, certain video conferencing tools and IPsec VPNs embed addresses inside the payload itself. They depend on NAT traversal, a group of techniques that help traffic survive translation.

  • Harder traceability: Logs beyond the boundary capture only the public address, so tying activity to a specific host means consulting translation records, which slows root cause analysis.

  • Table exhaustion: Each session uses a table entry and a port. Under heavy load the table can fill up, at which point new connections fail.

What Is the Difference Between NAT, DHCP, and DNS?

NAT, DHCP and DNS all deal with IP addresses, yet they answer different questions.

  • DHCP (Dynamic Host Configuration Protocol): Gives a device a private address when it joins a network.

  • DNS (Domain Name System): Handles lookups, turning a name like a website address into the IP address a device connects to.

  • NAT: Comes in last, translating private addresses into public ones as traffic leaves.

Home routers typically run all three network protocols in one box, so the lines between them blur easily.

What Does NAT Type Mean in Gaming?

For gamers, NAT type is a measure of how readily a console or PC accepts connections that other players initiate through the router. Most consoles grade it on a scale:

  • Type 1 (open): Connections come through freely.

  • Type 2 (moderate): Some connections are limited.

  • Type 3 (strict): The router turns away most inbound connections nobody requested, so matchmaking may fail and voice chat can drop.

A few settings usually improve a strict rating:

  • UPnP (Universal Plug and Play): Lets devices ask the router for their own port forwards, and switching it on generally lifts the rating.

  • Manual port forwarding: Achieves the same result with fixed rules.

  • Removing double NAT: Double NAT, where a provider's modem and a second router both translate the same traffic, is a common cause of a strict rating. Putting one of the two devices into bridge mode usually clears it.

NAT itself should remain on. Without it, devices using private addresses lose internet access.

Is NAT Still Used with IPv6?

IPv6 was designed to end the address shortage behind NAT, yet NAT remains in wide use.

Each IPv6 address runs to 128 bits. A space that large lets every device hold a globally unique address. Conservation stops being a reason to translate, and hosts can reach each other directly again.

Moving to IPv6 has been a slow process, though:

  • Dual-stack networks: In most enterprises, IPv4 and IPv6 share the same infrastructure, and NAT still carries the IPv4 traffic.

  • Provider networks: Carrier-grade NAT stays in service at many internet providers for subscribers who only get IPv4.

Translation has also taken new forms within IPv6:

  • NAT64: Helps IPv6-only devices reach services that exist solely on IPv4, typically with DNS64 alongside it to generate IPv6 addresses for names that only have IPv4 records.

  • NPTv6 (network prefix translation): Changes only the network prefix, the leading part of an address that identifies the network, which lets an organization move to a new provider and keep its internal host addresses as they are.

Security design changes with it. On IPv6 networks, stateful firewall rules block unsolicited inbound traffic, a job NAT often handled indirectly under IPv4.

How Does NAT Affect Network Observability?

NAT affects network observability because a host's address changes as its traffic crosses the translation boundary. Flow records captured outside show the public address. Inside, device logs show the private one.

An investigation therefore has to join both views before the responsible host becomes clear. Observability platforms close this gap in a few ways:

  • Translation logs: Collected over syslog from routers and firewalls.

  • Device polling: Routers and firewalls are polled through SNMP for table utilization and active session counts.

  • Address mapping: Event correlation maps public addresses back to the internal devices behind them.

Tracking table and port usage over time gives warning of exhaustion before users run into dropped connections. Keeping every mapping in one place also gives investigators a direct path to the affected host.

Explore More IT Terms

Browse our comprehensive IT glossary to learn more about technology terminology.

Back to IT GlossaryContact Us
Table of Contents