In NAT, how does 1:1 NAT differ from single-port and port-range forwarding, and how can two internal hosts both serve public port 443?
answer
- whole address vs one port
- outbound source differs too
- inbound key: address, protocol, port
- one triple, one internal host
basics
~20 s1:1 NAT gives a host a whole public address, all ports, both directions; port forwarding maps one port or range of a shared address. A public address and port reach one host, so a second server needs another port, address or proxy.
solid answer
~40 s1:1 NAT, which RFC 2663 calls static address assignment, binds a whole public address to one private address: every protocol and port is translated inbound, and the host's own outbound traffic leaves with that address. Port forwarding is one static NAPT entry, one public address, protocol and port to one internal endpoint, on an address the router shares with everyone else; a port range is the same for a block of ports. A NAT selects an inbound mapping by destination address, protocol and port, and nothing in a SYN to `203.0.113.7:443` says which internal host was meant, so that triple leads to one host. For a second server on 443 you use another external port, a second public address, one reverse proxy that routes by TLS server name or `Host` header, or IPv6.
go deeper
Recall that 1:1 NAT gives a host a whole public address while port forwarding opens one port on a shared one.
Explain the inbound lookup key, why one public address, protocol and port can lead to only one host, and how outbound traffic differs under 1:1 NAT.
Choose among another port, another address, a reverse proxy and IPv6 for a second service, and state what each costs clients and operations.
Treat public addresses and exposed ports as a budget: decide when a shared proxy front beats per-host addresses for many services.
## Three ways to let traffic in All three are **static** entries in a NAT's table, written by an administrator, that let unsolicited inbound traffic reach an internal host. They differ in what the entry is keyed on and how much of the public address it consumes. - **1:1 NAT** binds a whole public address to one private address. RFC 2663 calls this *static address assignment*: a one-to-one mapping between a private and an external address for the lifetime of NAT operation. Traditional NAT (RFC 3022) notes that a local address statically mapped to a global one allows access to that host from outside via a fixed public address. Every protocol and every port is translated, in both directions. - **Port forwarding** is a single static NAPT entry: one external address, protocol and port to one internal address and port. The public address stays shared; its other ports still belong to the router and to other mappings. - **Port-range forwarding** is the same thing for a contiguous block of ports, for an application that genuinely uses many, such as a game server's port block or a media server's RTP ports. Each external port in the range still maps to exactly one internal port; implementations usually keep the numbers the same. ## Side by side | | 1:1 NAT | Port forwarding | Port-range forwarding | "DMZ host" | |---|---|---|---|---| | Public addresses used | one per internal host | shares one | shares one | shares one | | Ports covered | all, every protocol | one, one protocol | a block, one protocol | all not otherwise mapped | | Host's outbound source | its own public address | the shared address | the shared address | the shared address | | Typical use | a server needing its own IP | one service | a multi-port application | a device that needs everything | The last column is an implementation feature of single-address routers: all unsolicited inbound traffic that matches no other entry goes to one chosen host. The Port Control Protocol (RFC 6887) quotes the name: a `MAP` request with protocol and internal port both zero asks for all incoming traffic for all protocols, "commonly called a 'DMZ host'". Inbound it resembles 1:1 NAT, but the host does not own the address, and its outbound traffic is still port-translated with everyone else's. ## Why 1:1 NAT changes the outbound side too With 1:1 NAT the internal host's own outbound connections leave with its dedicated public address. In the Basic NAT model only the address is rewritten and the port is left alone. That matters to anything that checks source addresses: a partner allowlisting you sees one stable address per host. With port forwarding, the server's outbound traffic shares the router's address with every other device, and the NAT may choose its source port. ## Two hosts that both want public 443 A NAT selects an inbound mapping by the packet's **destination address, protocol and destination port**. Nothing in a TCP SYN for `203.0.113.7:443` says which internal host the client meant, so on one public address, TCP 443 can lead to **one** internal host. Implementations typically refuse a second rule for the same external port. The working options: 1. **Use a different external port** for the second host, as in `203.0.113.7:8443 -> 192.168.1.11:443`. Cheap, but clients must put the port in the URL. 2. **Use a second public address**, either as 1:1 NAT for `192.168.1.11` or as a forward on that address. Both hosts stay on 443, at the cost of an address. 3. **Forward 443 to one reverse proxy** that terminates or inspects TLS and routes by the server name the client asked for (SNI) or by the HTTP `Host` header. This multiplexes above the transport layer; the NAT itself cannot do it. 4. **Use IPv6**, where each host has its own global address and the router only has to permit the inbound connection, not translate it. TCP 443 and UDP 443 are separate mappings, so they could in principle lead to different hosts, but a service that offers both normally wants them on the same one. ## Choosing between them - Pick **port forwarding** when one or a few services must be reachable and public addresses are scarce, which is the common case. - Pick a **range** only when the application really uses that block; every port in it is open to every source. - Pick **1:1 NAT** when a host needs its own address for inbound and outbound alike and you hold enough public addresses. - Treat a **DMZ host** as an exposure: it hands every unmapped port of the public address to one device.
- Why can't a NAT tell two internal web servers apart by the incoming client's address?It could filter on source, but a public service does not know its clients in advance, so a forward is keyed on what every client shares: the destination address, protocol and port. Any rule that split clients by source would send some of them to the wrong server. Telling services apart needs information the client chooses, such as the TLS server name, which only an application-layer proxy reads.
- When would you use a DMZ-host setting instead of individual forwards?Rarely: when one device needs unpredictable inbound ports and no mapping protocol is available. It sends every unsolicited packet for unmapped ports to that device, so the device faces the internet almost as if it held the address itself, while its outbound traffic is still shared and port-translated. Explicit forwards, or a dedicated address with filtering, expose far less.
saying these in an interview costs you the question
- 1:1 NAT and a single port forward differ only in how many ports they open.
- Two hosts can share public TCP 443 if both forwards are configured.
- A NAT can route different HTTPS sites by hostname without a proxy.
- A port-range rule may spread its ports across several internal hosts by itself.
- A DMZ-host setting gives the device its own public address.