Skip to topic
    ← Back to course topics

    Network Address Translation (NAT) — AQA A-Level Computer Science

    Test yourself on Network Address Translation (NAT) with AQA A-Level practice questions.

    Start free

    7 days Premium · Then free forever · No card, no charge

    Your focus

    1. Explain the basic concept of NAT and why it is

    Network Address Translation (NAT) exam tips

    Quick Revision Summary (Key Takeaway)

    Network Address Translation (NAT) is a routing technique that modifies IP header address information while packets traverse a routing device, mapping private, non-routable IP addresses within a local area network to a single public IP address. This protocol mitigates IPv4 address exhaustion and enhances network security by concealing the internal network structure from external devices on the internet.

    Topic Overview

    Network Address Translation (NAT) is a networking method implemented on routers and firewalls that remaps an IP address space into another by modifying network address information in the IP header of packets while they are in transit. Developed primarily as a temporary mitigation strategy for the rapid depletion of the 32-bit IPv4 address pool, NAT has become a fundamental architectural component of modern enterprise and home networks.

    Understanding NAT is vital for A-Level Computer Science as it ties together core networking principles, including the TCP/IP stack, packet switching, private versus public addressing schemes, and transport layer port multiplexing. It provides students with practical insight into how data traverses local boundaries to interface with the global internet while maintaining network perimeter security.

    Key Concepts
    • →Public vs Private IP Addresses: Private IP addresses (specified by RFC 1918, such as 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16) are reserved for internal local networks and cannot be routed across the public internet.
    • →Port Address Translation (PAT): Also known as NAT overload, PAT maps multiple private IP addresses to a single public IP address by assigning unique transport layer port numbers to each session.
    • →Translation Table: An in-memory database managed by the NAT router that tracks the mappings between internal IP/port pairs and external public port allocations to ensure bidirectional packet delivery.
    • →Inbound Connection Restriction: External hosts cannot establish unsolicited connections to internal devices because no entry exists in the translation table until an internal device initiates communication.
    Examiner Tips
    • 💡Always differentiate between IP addresses (Network Layer) and Port numbers (Transport Layer) when explaining how the router distinguishes multiple internal devices using the same public IP.
    • 💡Use accurate terminology such as 'non-routable private IP', 'globally unique public IP', and 'NAT translation table' rather than vague colloquial phrases like 'it hides the computer'.
    Common Mistakes
    • Believing NAT is an encryption protocol: Students often assume NAT protects data confidentiality. NAT only modifies header routing information; packet payloads remain in plaintext unless encrypted by protocols like TLS/HTTPS or IPsec.
    • Assuming NAT is rendered obsolete by IPv6: While IPv6 eliminates the technical necessity for NAT by providing an astronomical address space (128-bit addresses), NAT is still widely encountered in dual-stack networks, legacy architectures, and specific policy routing scenarios.
    • Thinking all inbound packets are blocked: NAT does not block all incoming traffic; it allows inbound packets that correspond to an active session previously initiated by an internal host and recorded in the translation table.
    Revision Plan
    1. 1Day 1: Review IPv4 addressing, subnetting basics, and the distinction between RFC 1918 private address ranges and public routable addresses.
    2. 2Day 2: Diagram the lifecycle of an outbound and inbound packet passing through a NAT router, explicitly drawing the translation table.
    3. 3Day 3: Study Port Address Translation (PAT) and understand why port numbers are necessary when multiple clients access the same remote web server.
    4. 4Day 4: Compare NAT's security benefits against dedicated firewalls and examine the limitations NAT imposes on peer-to-peer protocols and hosting servers.
    5. 5Day 5: Complete past paper questions on routing, packet switching, and NAT from AQA A-Level Computer Science papers.
    Exam Question Types
    • 📋Diagrammatic trace questions: Completing a table showing source/destination IP and port transformations as a packet moves from a host, through a NAT router, to an external server.
    • 📋Short-answer definitions: Defining the difference between private and public IP addresses and explaining why private addresses cannot be routed over the internet.
    • 📋Evaluative structured questions (4 to 6 marks): Explaining why NAT was introduced and discussing its impact on network security and application compatibility.
    Command Word Expectations (AQA)
    Explain

    Requires students to clarify a topic by giving reasons or mechanisms. In NAT questions, you must provide the cause-and-effect chain (e.g., replacement of private IP with public IP, logging in a table, and re-mapping inbound packets).

    Describe

    Requires giving a detailed, factual account of a process or system without necessarily evaluating pros and cons. Detail the sequential path of a packet through the router.

    Discuss

    Requires an exploration of multiple viewpoints or technical trade-offs (e.g., the benefits of address preservation and privacy versus the drawbacks of broken end-to-end connectivity and performance overhead).

    How Students Lose Marks (Examiner Pitfalls)
    Pitfall: Confusing private and public IP address spaces and implying NAT changes packet payloads rather than IP headers and port numbers.
    ❌ Weak Answer (Loses Marks):NAT changes an IP address so that private networks can use the internet securely and protects the computer from viruses.
    Example improved answer:NAT translates private, non-routable IP addresses from a local network into a globally unique public IP address at the router. It modifies the source IP address and source port in the packet header before forwarding it across the internet, recording these mappings in a translation table so incoming response packets can be routed back to the correct internal client.
    Examiner Tip: Explicitly mention the translation table and how port numbers are used (Port Address Translation / NAPT) to differentiate between internal hosts sharing a single public IP.
    Pitfall: Stating that NAT completely encrypts internet traffic or serves as a full firewall replacement.
    ❌ Weak Answer (Loses Marks):NAT acts as a firewall because it hides your IP address, making the network completely immune to outside attacks and encrypting data packets.
    Example improved answer:NAT provides an inherent layer of security by hiding internal private IP addresses from external networks, meaning unsolicited inbound connections cannot be routed to internal hosts directly. However, it does not inspect packet payloads or encrypt data, so it is not a direct substitute for a stateful inspection firewall.
    Examiner Tip: Distinguish clearly between preventing direct unsolicited inbound access and actively filtering malware or inspecting packet data.
    Step-by-Step Worked Solutions

    Question: A host on a private local area network with the IP address 192.168.1.45 initiates an HTTP connection to a web server at 93.184.216.34 on port 80. The local host uses source port 49152. Describe the step-by-step role of the NAT-enabled router as the request leaves the network and the subsequent response is received.

    1. 1.Step 1: Identify outbound packet details: Source IP is 192.168.1.45, Source Port is 49152, Destination IP is 93.184.216.34, Destination Port is 80.
    2. 2.Step 2: Router interception and modification: The NAT router intercepts the outbound packet, replaces the private source IP (192.168.1.45) with its public IP address (e.g., 203.0.113.5), and assigns a unique public source port (e.g., 50001).
    3. 3.Step 3: Translation table entry: The router records this mapping (192.168.1.45:49152 <-> 203.0.113.5:50001) in its internal NAT translation table.
    4. 4.Step 4: Outbound transmission: The modified packet is transmitted across the internet to the destination web server.
    5. 5.Step 5: Response packet receipt: The web server responds with a packet directed to Destination IP 203.0.113.5 on Destination Port 50001.
    6. 6.Step 6: Inbound translation and routing: The NAT router looks up port 50001 in its translation table, identifies the corresponding private host (192.168.1.45:49152), replaces the destination address/port with these private details, and forwards the packet onto the LAN.
    Final Answer: The NAT router replaces the internal private IP and port with its public IP and an assigned port, records the mapping in a translation table, forwards the request, and reverses this translation upon receiving the external response to ensure delivery to the correct internal client.

    Question: Explain two reasons why Network Address Translation (NAT) was introduced and discuss one limitation associated with its use in modern networking. [6 marks]

    1. 1.Step 1: State the first reason (IPv4 address exhaustion): The 32-bit IPv4 address space provides only approximately 4.3 billion unique addresses, which is insufficient for global demand. NAT allows hundreds of devices on a private network to share a single public IPv4 address, significantly conserving available addresses.
    2. 2.Step 2: State the second reason (Network privacy and security): Private IP addresses (e.g., RFC 1918 ranges like 192.168.x.x) are non-routable on the public internet. By preventing direct inbound addressing of client machines, NAT stops unauthorized external devices from initiating direct connections to internal hosts.
    3. 3.Step 3: State the limitation (Breaks end-to-end connectivity / complicates peer-to-peer protocols): NAT violates the pure end-to-end principle of networking. Services that require external incoming connections (such as VoIP, peer-to-peer file sharing, and self-hosted multiplayer game servers) require complex traversal mechanisms (like STUN, UPnP, or manual port forwarding) because external hosts cannot initiate communication with a private IP.
    Final Answer: NAT was introduced to alleviate IPv4 address exhaustion by enabling address sharing, and to provide baseline security by masking internal private topologies. Its key drawback is breaking the end-to-end connectivity model, which complicates peer-to-peer communications and inbound server hosting without port forwarding.
    Active Recall Memory Test
    What primary problem was Network Address Translation designed to alleviate?
    Key Fact: The exhaustion of the 32-bit IPv4 public address space.
    Why can private IP addresses (e.g., 192.168.x.x) not be routed directly across the public internet?
    Key Fact: They are not globally unique and internet routers are programmed to drop packets containing RFC 1918 private destination addresses.
    How does Port Address Translation (PAT) allow hundreds of internal devices to use a single public IP address?
    Key Fact: It assigns a unique transport layer port number to each internal connection and records this association in a translation table.
    What technique must be configured on a NAT router to allow an external user to connect directly to an internal web server?
    Key Fact: Port forwarding (static NAT mapping of a specific external port to an internal IP address and port).
    Frequently Asked Questions
    What is the difference between static NAT, dynamic NAT, and PAT?
    Static NAT maps an individual private IP address to a single dedicated public IP address in an unchanging one-to-one relationship, commonly used for internal servers. Dynamic NAT maps a private IP address to an available public IP from a pre-allocated pool of public addresses on a first-come, first-served basis. Port Address Translation (PAT), or NAT Overload, is a many-to-one mapping technique that routes multiple private IP addresses through a single public IP by tracking unique source port numbers.
    Does NAT replace the need for a firewall?
    No, NAT does not replace a firewall. While NAT offers a baseline level of stealth by keeping internal IP addresses hidden and preventing unprompted external inbound connections, it does not analyze packet contents. A firewall performs stateful packet inspection, deep packet inspection, and rule-based traffic filtering to block malicious payloads and unauthorized protocols that NAT permits.
    Why do online multiplayer games sometimes report strict NAT type issues?
    Multiplayer games often utilize direct peer-to-peer (P2P) connections between players' consoles or PCs to reduce server latency. A 'Strict NAT' indicates that the player's router is blocking incoming unsolicited connection requests from other peers because there is no matching outbound session in the translation table. Resolving this typically requires enabling Universal Plug and Play (UPnP) or setting up manual port forwarding rules.
    Will IPv6 completely eliminate the need for NAT in the future?
    In theory, yes, because IPv6 provides roughly 3.4 x 10^38 unique addresses, eliminating the need to conserve IP space through translation. In a pure IPv6 implementation, every device can have a globally unique, end-to-end routable IP address protected by firewall rules. However, transitional mechanisms like NAT64 (translating IPv6 to IPv4) and specialized enterprise prefix translations will remain in use for the foreseeable future.
    How does a router know which port to assign during Port Address Translation?
    When an internal host sends an outbound packet, the router checks its translation table for an available port from its dynamic or ephemeral port range (typically 49152 to 65535). It allocates an unused port to that specific internal IP and socket pair, ensuring no two internal connections share the same external port number simultaneously.