Source NAT and Destination NAT
Another common way to classify NAT is by looking at which part of the packet is being rewritten.
Type | What Changes | Common Use |
|---|---|---|
Source NAT (SNAT) | Source IP address, and often source port | Outbound traffic from private network to internet |
Destination NAT (DNAT) | Destination IP address, and sometimes destination port | Inbound traffic to internal services |
Source NAT
Source NAT is used when internal devices initiate outbound communication. The NAT device changes the source address of the packet before it leaves the network.
This is the normal internet access case in homes and offices. A private system sends traffic outward, and the NAT device replaces the private source IP with a public one.
In simple terms:
Inside host starts the communication
Source address gets translated
Replies are mapped back using the NAT table
Destination NAT
Destination NAT is used when incoming traffic from outside needs to be redirected to an internal host. The NAT device changes the destination address of the arriving packet so it reaches the correct private server.
This is commonly used when an organization wants to make an internal service reachable from outside without giving that internal host its own public IP.
In simple terms:
External host sends traffic toward a public address
NAT device rewrites the destination
Packet is delivered to the internal server
Source NAT and Destination NAT
Port Forwarding
Port forwarding is one of the most common practical uses of destination NAT. It allows traffic arriving on a specific public port to be redirected to a particular private IP address and port.
For example:
Public
203.0.113.5:80=> Private192.168.1.20:80Public
203.0.113.5:22=> Private192.168.1.30:22
This is useful when hosting services such as:
Web servers
SSH access
Game servers
Camera systems
Remote desktop services
Without port forwarding, outside users usually cannot directly start connections to private devices behind NAT.
Port forwarding is powerful, but it also increases exposure. Once a port is forwarded, the internal service behind it becomes reachable from outside and must be secured properly.
Be the first to add a comment.