Skip to main content

IPv4 guide

What Are the 4 Types of NAT? Static, Dynamic, PAT, and DNAT

What are the four types of NAT?

A practical four-item answer is static NAT, dynamic NAT, Port Address Translation (PAT or NAPT), and destination NAT (DNAT or port forwarding). This list is useful for learning, but it is not a single universal standards taxonomy. Static and dynamic describe how a mapping is allocated; PAT describes translation that also uses transport ports; SNAT and DNAT describe whether a rule rewrites the source or destination.

Those dimensions can overlap. A fixed one-to-one mapping can use source translation for outbound packets and destination translation for return or inbound packets. SNAT means source NAT; it is not an abbreviation for static NAT.

NAT types at a glance

Four common NAT labels and how their mappings differ
TypeWhat changesMapping behaviorTypical use
Static NATUsually one address on each sideA fixed one-to-one binding configured in advanceGive a host or service a stable translated address
Dynamic NATUsually one address on each sideA binding is selected from a pool while neededLet a limited number of inside hosts use a public address pool
PAT / NAPT / NAT overloadAddress and TCP or UDP portMany sessions share one or a few external addresses, separated by port and protocol stateOutbound Internet access for many private devices
DNAT / port forwardingDestination address and sometimes destination portA rule or state entry directs traffic to another endpointPublish a selected internal service through a reachable external address

Product interfaces often use different labels. Read the actual match conditions, translated fields, direction, state behavior, and firewall policy instead of assuming that two vendors mean the same thing by “NAT type.”

1. Static NAT: a fixed one-to-one mapping

Static NAT keeps a configured address binding rather than borrowing an address only for one session. For example, a gateway could associate private address 10.0.0.10 with documentation address 198.51.100.10. Outbound packets may have their source rewritten to the external address, while traffic returning to that mapping is translated back toward the internal address.

A static mapping does not by itself prove that inbound traffic is allowed. Routing, firewall or ACL policy, service listeners, upstream filtering, and return-path symmetry still determine whether a connection works.

2. Dynamic NAT: temporary mappings from a pool

Dynamic NAT chooses an available address from a configured pool when a mapping is needed and releases it according to the implementation's state and timeout rules. A host might use one external address for a period and a different address later.

This conserves pool addresses when not every internal host communicates externally at the same time, but the pool still limits concurrent address bindings. Dynamic NAT is not the same as PAT: address-only dynamic NAT normally consumes one external address per active binding, while PAT can distinguish many sessions with ports.

3. PAT or NAPT: many sessions share an address

Port Address Translation, also called Network Address Port Translation or NAT overload, translates transport identifiers as well as addresses. A flow from 10.0.0.21:51514 could leave as 203.0.113.5:41001; another flow can share 203.0.113.5 with a different translated port. The gateway keeps state so replies return to the correct private endpoint.

PAT is common for home, enterprise, and provider egress, but it has finite port and state capacity. Idle timeouts, endpoint-dependent mappings, application payloads, inbound requirements, and logging all affect behavior. At provider scale, preserve the public address, port, protocol, timestamp, and time zone needed to correlate a subscriber session. See the CGNAT guide for the extra carrier-scale boundary.

4. DNAT and port forwarding: translate the destination

Destination NAT changes the destination address, and sometimes the destination port, before forwarding a packet. A rule could send traffic for 203.0.113.10:443 to 10.0.0.50:8443. Port forwarding is a common DNAT use, although a DNAT rule can translate an address without changing the port.

DNAT publishes a translation path; it is not a complete exposure policy. Verify who may connect, which interface and protocol match, whether the firewall permits the flow, whether the service is listening, and whether replies follow a compatible path.

SNAT vs static NAT: the terms are not interchangeable

Source NAT and static NAT describe different NAT dimensions
TermWhat it describesExample
SNATThe source address or source port is rewritten for a packet or flowPrivate client traffic leaves with a public source address
DNATThe destination address or destination port is rewrittenTraffic to a public service address is directed to an internal server
Static NATThe mapping is fixed rather than selected dynamicallyOne internal address has one configured external address
Dynamic NATThe mapping is created from a pool or policy when neededAn active host temporarily receives an external address binding

A static one-to-one deployment may therefore perform SNAT in one packet direction and DNAT in the other. Always separate which field is rewritten from how the mapping is allocated.

Other NAT forms you may encounter

  • Twice NAT or bidirectional translation: may rewrite both source and destination information or coordinate mappings for sessions initiated from either realm. Vendor meanings vary, so inspect the rule.
  • Carrier-grade NAT (CGNAT): applies address and port sharing in a provider network. It adds a provider translation boundary and makes port-aware, time-aligned logs important for attribution and support.
  • NAT64: translates between IPv6 clients and IPv4 servers under a defined IPv6-to-IPv4 algorithm and state model. It is not simply another private-IPv4-to-public-IPv4 mapping.
  • Hairpin NAT or NAT loopback: lets an internal client reach a translated service through its external address when the gateway supports and permits that path.

These names describe deployment scope, protocol family, or packet behavior. They do not extend one official numbered list of NAT types.

Which NAT type should you choose?

Start with the traffic requirement, then choose translation and policy
RequirementLikely starting pointVerify separately
Many private clients need outbound accessPAT/NAPT on an approved egress address or poolPort capacity, timeouts, DNS, logs, firewall and failover
One endpoint needs a stable translated addressA static one-to-one mappingRoutes, policy, service exposure and return-path symmetry
A selected internal service must accept inbound trafficDNAT or port forwarding with an explicit firewall ruleLeast privilege, TLS, service health, logs and upstream filtering
A provider must share public IPv4 across customersCGNAT with address-and-port translationScale, port policy, lawful log requirements, IPv6 and customer support
IPv6-only clients must reach IPv4 servicesNAT64 with the required DNS and routing designApplication compatibility, address synthesis, observability and fallback

If the need is only routing between networks, NAT may be unnecessary. Begin with the traffic path, address realms, route ownership, firewall policy, and application requirements. The broader Network Address Translation guide explains the packet path and limitations.

NAT troubleshooting checklist

  1. Record the original source and destination IPs, ports, protocol, interface, timestamp, and intended direction.
  2. Identify the rule that should match and the exact post-translation address and port tuple.
  3. Verify routes and neighbor reachability before and after the translation boundary.
  4. Check firewall or ACL decisions separately from the NAT rule.
  5. Inspect translation state, pool or port exhaustion, timeouts, and asymmetric return paths.
  6. Test DNS answers, application-embedded addresses, hairpin behavior, IPv4 and IPv6 independently.
  7. Confirm that logs preserve enough address, port, protocol, time, and rule context to trace the flow.

The IP address troubleshooting guide provides a wider symptom-to-check sequence, and the IPv4 knowledge base covers routing, registry, reputation, and DNS operations.

NAT types FAQ

What are the four types of NAT?

A useful learning list is static NAT, dynamic NAT, PAT/NAPT, and DNAT or port forwarding. It is not a universal standards list: static and dynamic describe mapping allocation, PAT adds port translation, and SNAT or DNAT describe the field being rewritten.

Is SNAT the same as static NAT?

No. SNAT means source NAT: the source address or port is rewritten. Static NAT means the mapping is fixed. A static mapping may perform source translation in one direction and destination translation in the other.

What is the difference between NAT and PAT?

NAT is the wider family of address translation. PAT or NAPT also translates TCP or UDP ports, allowing many sessions to share one or a few external addresses while the gateway tracks each flow.

Is port forwarding a type of DNAT?

Usually, yes. Port forwarding changes the destination address, destination port, or both so traffic reaches a selected internal service. Firewall policy and routing still determine whether the service is reachable.

Does NAT protect a network?

NAT changes addressing and may make unsolicited inbound flows harder without a mapping, but it is not a security policy. Use a firewall or ACL, least-privilege rules, patching, authentication, monitoring, and application controls.

Is NAT required for IPv6?

No. IPv6 networks commonly route global addresses without address translation. NAT64 is a specific translation mechanism for IPv6 clients reaching IPv4 servers; it is not a general requirement for IPv6 security.

Primary standards

NAT and public IPv4 planning

NAT can change how many endpoints share an address, but it does not create routable IPv4 capacity or prove authority to use a prefix. For public IPv4, define the required address or prefix size, inbound and outbound paths, origin ASN, routing handoff, RPKI and IRR responsibility, DNS, logging, reputation, abuse handling, failover, renewal, and return plan. If the need is time-bound, compare those controls in the managed IPv4 leasing workflow after the network design is clear.