skip to content

NAT

Rewriting addresses and ports in flight so many private hosts share a public address, and everything that breaks as a result. Interviewers use it to test whether you understand end-to-end addressing.

on this pageshow

explore

questions

page 1 of 2

What is NAT hairpinning, and why does an inside host need it to reach a port-forwarded server by the network's public address?

level: juniorimportance: must knowfreq 40%

answer

  1. the packet must turn around
  2. the public address is the NAT's own
  3. relay inside to inside
  4. RFC 4787 Section 6

basics

~20 s

Hairpinning is a NAT relaying a packet from one inside host back inside to another host that was addressed by its public, translated endpoint. Without it, an inside client that resolves a service name to the public address cannot reach the server.

solid answer

~50 s

**Hairpinning** (also called NAT loopback or NAT reflection) is a NAT receiving, on its inside interface, a packet addressed to one of its own outside endpoints that maps to an inside host, translating it and sending it back inside. RFC 4787 defines it, and RFC 4787 REQ-9 (UDP) and RFC 5382 REQ-8 (TCP) say a NAT MUST support it; RFC 5508 REQ-7 adds ICMP requirements. An inside host needs it because public names and endpoints point at the public address: DNS returns `203.0.113.10` for the portal everywhere, a laptop roams between home and office, and peers behind one NAT learn each other's public endpoints from a rendezvous server. Many devices still do not hairpin, because their forward rule matches only outside traffic, so the fixes are enabling it, split-horizon DNS, or using the inside address.

go deeper

for a junior

Recall the picture: the inside packet goes to the NAT's public address and must be turned around and sent back inside to the server; without that, the public name fails from inside.

for a middle

Explain who sends what where: the client follows DNS to the public address, the packet reaches the NAT on its inside interface, and the NAT must apply the forward and relay it back.

for a senior

Show you know it is a MUST in RFC 4787 and RFC 5382 yet often missing, and name the deployments that hit it: published services, roaming laptops, peers behind one NAT, subscribers of one carrier-grade NAT.

for a principal

Weigh whether to depend on hairpinning at all, given patchy support, against keeping inside clients off public addresses with split-horizon DNS or moving services to IPv6.

## The situation hairpinning solves A small company runs a web portal on an inside server, `10.20.0.10`, port `443`. Its IPv4 NAT owns one public address, `203.0.113.10`, and a **port forward** maps `203.0.113.10:443` to `10.20.0.10:443`. Public DNS answers `portal.example.com` with `203.0.113.10`, so customers on the Internet reach the portal through the forward. Now an employee at `10.20.0.55`, on the same inside network, types the same name. Their resolver returns the same public answer, `203.0.113.10`. That address is not on the employee's subnet, so the packet goes to the default gateway, which is the NAT itself. The NAT now holds a packet that: - arrived on its **inside** interface, - is addressed to one of its own **outside** addresses and ports, - and should end up at another **inside** host. Delivering it means turning the packet around and sending it back the way it came, which is why the behaviour is called **hairpinning** (the industry also says **NAT loopback** or **NAT reflection**). ## The definition in the specifications RFC 4787 (the UDP behavioural requirements, BCP 127) defines it in Section 6: when two hosts X1 and X2 sit behind the same NAT and X2 has an external endpoint `X2':x2'`, traffic from X1 to `X2':x2'` "goes to the NAT, which must relay the traffic from X1 to X2". The point is that the two inside endpoints can communicate "even if they only use each other's external IP addresses and ports". | Specification | Requirement | Scope | |---|---|---| | RFC 4787 | REQ-9: a NAT MUST support hairpinning | UDP | | RFC 5382 | REQ-8: a NAT MUST support hairpinning for TCP | TCP | | RFC 5508 | REQ-7: hairpinned ICMP Query sessions (Basic NAT) and ICMP Error messages (all NATs) | ICMP | | RFC 6888 | REQ-1: a carrier-grade NAT MUST meet the behavioural requirements of each transport it forwards | CGN | | RFC 6296 | Section 4.3: NPTv6 translators MUST support hairpinning | IPv6 prefix translation | The UDP and TCP documents also say which source address the relayed packet must carry; that detail, and the reason the NAT has to rewrite more than the destination, is the mechanism behind the definition. ## Where an inside host meets it 1. **A published service used from inside.** The name resolves to the public address everywhere, so an inside client follows the public path. 2. **A roaming device.** A laptop configured with one name or address works at home and fails in the office, or the reverse. 3. **Peers that learned public endpoints.** Two applications behind the same NAT register with a rendezvous server, receive each other's public endpoints and try them. RFC 5128 notes that they can talk this way only if the NAT relays inside-to-inside sessions. 4. **Subscribers of the same carrier-grade NAT.** Two customers behind one provider's large NAT meet through public endpoints that both map to the same translator, so the provider's NAT must hairpin. ## Why so many devices fail The requirement is a MUST, yet real devices often lack it. RFC 5128 (Informational, 2008) reports that fewer than 25% of the NAT devices in the tests it cites passed the hairpinning checks. The usual implementation reason is simple: a port-forward rule is matched only against packets arriving on the **outside** interface. A packet from inside never matches it, so the device treats it as a packet for its own address. What the client sees depends on the device: - the router's own service on that port answers, such as its management page; - the router refuses or drops it, and the connection fails or hangs; - the router rewrites only the destination, and the connection hangs because the server's reply never returns through the NAT. ## The usual ways around it - **Turn hairpinning on**, where the device offers it, so the NAT relays inside traffic correctly. - **Split-horizon DNS**: the inside resolver answers the same name with `10.20.0.10`, so inside clients never use the public address. - **Use the inside address or an inside-only name** directly, which works but breaks the "one name everywhere" model. Under plain IPv6 the problem disappears: there is no NAT in IPv6's architecture, so a server's global address is the same inside and out, and inside traffic is routed straight to it.

  • Do two subscribers behind the same carrier-grade NAT need hairpinning to reach each other's public endpoints?
    Yes. Both public endpoints belong to the same translator, so traffic between them arrives on its inside and must be relayed back inside. RFC 6888 REQ-1 makes a carrier-grade NAT meet the UDP, TCP and ICMP behavioural requirements, which include hairpinning, and RFC 5128 notes that hosts behind different second-level NATs under one first-level NAT cannot reach each other by hole punching unless that first-level NAT hairpins.
  • Does an IPv6 network need hairpinning to reach its own servers by their global addresses?
    Not with ordinary global addressing. IPv6's architecture has no NAT, so a server's global address is the same inside and outside, and inside traffic is routed straight to it; a firewall may filter but does not translate. The exception is a site using NPTv6 prefix translation (RFC 6296, Experimental), whose Section 4.3 requires the translator to support hairpinning.

Calling your company's public switchboard number from a desk phone in the same building: a good switchboard notices the call came from inside and connects it back to the right desk, while one that only routes outside calls inward leaves you with a dead line.

saying these in an interview costs you the question

  • Hairpinning is a routing loop that a correctly configured router prevents.
  • If a port forward works from outside, it automatically works from inside as well.
  • Hairpinning is optional in the NAT behavioural requirements.
  • Inside hosts can never use the public address; that is simply how NAT works.
  • An IPv6 network with global addresses needs hairpinning just like IPv4 NAT.
open as a page

How does Port Address Translation (NAPT) let many private hosts share one public IPv4 address, and how does a reply reach the right host?

level: juniorimportance: must knowfreq 68%

basics

~20 s

A NAPT rewrites each outbound packet's private source address and port to the public address plus a port it assigns, records that binding, and uses a reply's destination port to find the binding and restore the private address and port.

open as a page

On a NAT router, what is port forwarding, and what happens to a packet when a rule maps public port 8443 to 192.168.1.10:443?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Port forwarding is a static inbound NAT mapping: packets for the router's public address on a chosen port get their destination rewritten to an internal host and port, and the replies get their source rewritten back.

open as a page

Why did NAT become standard on IPv4 networks, and what does it cost the Internet's end-to-end reachability between hosts?

level: juniorimportance: must knowfreq 62%

basics

~20 s

IPv4's 32-bit space (about 4.3 billion addresses) ran short, so NAT lets many privately addressed hosts share one public address. The cost: outside hosts cannot start connections to them, the translator holds critical per-flow state, and addresses inside payloads break.

open as a page

In network address translation, what is the difference between source NAT and destination NAT, and what happens to the reply packets in each case?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Source NAT rewrites the source address of outbound packets so inside hosts appear as a public address; destination NAT rewrites the destination of inbound packets so a public address reaches an inside server. Replies get the mirror-image rewrite from the stored mapping.

open as a page

Why can two peers behind different NATs not open a direct connection to each other, and what do STUN, TURN and ICE each contribute?

level: juniorimportance: must knowfreq 46%

basics

~20 s

A NAT creates a mapping only when an inside host sends first, so each peer's NAT drops the other's unsolicited packets. STUN reveals a peer's public address and port, ICE tests the candidate paths, and TURN relays when none works.

open as a page

When a NAT hairpins an inside client's TCP connection to an inside server, which addresses must it rewrite, and why is destination-only rewriting not enough?

level: middleimportance: must knowfreq 32%

basics

~20 s

A hairpinning NAT rewrites both the destination, to the server's inside endpoint, and the source, to the client's external mapped endpoint. Rewriting only the destination lets the server reply directly, so the client gets an answer from an unexpected address.

open as a page

A colleague says an IPv4 NAT is the network's firewall because outside hosts cannot reach internal ones; what is right and wrong about that claim?

level: middleimportance: must knowfreq 52%

basics

~20 s

Partly right: an IPv4 NAT drops unsolicited inbound packets only because no mapping matches them. That side effect is not policy: it inspects nothing, forwarding rules and inside-initiated mappings open paths in, and inside-out threats pass untouched.

open as a page

How does UDP hole punching open a direct path between two peers behind different NATs, and why does endpoint-dependent ('symmetric') mapping defeat it?

level: seniorimportance: must knowfreq 37%

basics

~20 s

A rendezvous server tells each peer the other's public mapping, then both send at once, so each NAT sees an outbound session and admits replies. Endpoint-dependent mapping uses a new public port toward the peer, so the advertised address fails.

open as a page

How does split-horizon DNS compare with enabling NAT hairpinning for inside clients that reach an inside server by its public name?

level: middleimportance: should knowfreq 28%

basics

~20 s

Split-horizon DNS answers inside clients with the server's private address, so their traffic goes direct and never touches the NAT. Hairpinning relays traffic sent to the public address. DNS cannot help literal addresses or outside resolvers; hairpinning hides real client addresses.

open as a page

Why do idle TCP connections and UDP flows through a NAPT break, and what do RFC 4787 and RFC 5382 require of mapping timers?

level: middleimportance: should knowfreq 42%

basics

~20 s

NAPT bindings expire after an idle period, and later packets then find no binding. RFC 4787 forbids UDP timers under two minutes; RFC 5382 forbids established-TCP timers under 2 hours 4 minutes, but many devices use far shorter ones.

open as a page

A NAPT gives 5,000 clients one public IPv4 address; how many concurrent flows can it carry, and what makes it run out of ports?

level: middleimportance: should knowfreq 38%

basics

~20 s

Using ports 1024-65535, one address offers 64,512 external ports per transport protocol, about 13 concurrent bindings per client across 5,000. Churn exhausts it: closed sessions keep their port for minutes, so short-lived connections drain the pool.

open as a page

In NAT, how does 1:1 NAT differ from single-port and port-range forwarding, and how can two internal hosts both serve public port 443?

level: middleimportance: should knowfreq 38%

basics

~20 s

1:1 NAT gives a host a whole public address, all ports, both directions; port forwarding maps one port or range of a shared address. A public address and port reach one host, so a second server needs another port, address or proxy.

open as a page

Why do protocols such as FTP and SIP break through an IPv4 NAT, and what does an application-level gateway do to repair them?

level: middleimportance: should knowfreq 34%

basics

~20 s

FTP's PORT and PASV messages and SIP's SDP bodies carry addresses and ports in the payload, which NAT does not rewrite. An ALG parses that payload, substitutes translated values, opens the matching mapping and fixes TCP sequence numbers.

open as a page

On an IPv4 NAT router, why is a destination address rewritten before the routing decision and a source address rewritten after it?

level: middleimportance: should knowfreq 22%

basics

~20 s

An IPv4 router chooses the next hop from the destination address, so a destination rewrite must happen first or the lookup uses the wrong address. A source rewrite waits until the outgoing interface is known, because that decides which public address to use.

open as a page

In Basic NAT, how does a static one-to-one source mapping differ from a dynamic address pool, and what happens when that pool runs out?

level: middleimportance: should knowfreq 40%

basics

~20 s

A static mapping binds one inside address to one public address permanently, so it also admits inbound sessions; a dynamic pool lends a free address from a host's first outbound session until its last one ends. An exhausted pool refuses new hosts.

open as a page

In ICE (RFC 8445), what are host, server-reflexive, peer-reflexive and relayed candidates, and how do connectivity checks choose the pair that is used?

level: middleimportance: should knowfreq 29%

basics

~20 s

Host candidates are local addresses, server-reflexive ones are NAT mappings learned from STUN, relayed ones are TURN addresses, and peer-reflexive ones appear during checks. Agents test candidate pairs with STUN requests by priority; the controlling agent nominates one.

open as a page

How does a STUN Binding request let a host behind a NAT learn its server-reflexive address, and why does the response XOR-encode that address?

level: middleimportance: should knowfreq 31%

basics

~20 s

The STUN server copies the source address and port it saw on the Binding request, the NAT's public mapping, into XOR-MAPPED-ADDRESS. XOR-encoding hides that value from NAT ALGs that would otherwise rewrite it inside the payload.

open as a page

Staff on the same subnet as a port-forwarded web server browse to the IPv4 NAT's public address and see a hang behind one NAT and the router's own login page behind another; why?

level: seniorimportance: should knowfreq 20%

basics

~20 s

The login page means the NAT never applies the port forward to inside traffic, so its own management service answers its own address. The hang means it rewrites only the destination, so the server replies directly and the client resets the unexpected reply.

open as a page

Why does carrier-grade NAT number the links to subscribers' routers from 100.64.0.0/10 rather than RFC 1918 space, and what changes for subscribers?

level: seniorimportance: should knowfreq 30%

basics

~20 s

RFC 1918 space may already be used inside the subscriber's home, so the provider uses RFC 6598 Shared Address Space, 100.64.0.0/10. Subscribers then share public addresses, lose unsolicited inbound reachability, face per-subscriber port limits and need port-level logs for attribution.

open as a page

What are the security costs of letting devices open NAT port mappings automatically with UPnP IGD or NAT-PMP, and how do you contain them?

level: seniorimportance: should knowfreq 24%

basics

~20 s

Automatic mapping lets any LAN software, including malware, expose itself to the internet without the owner's knowledge. Risks grow with mappings for other hosts, WAN-side requests and unlimited leases; contain it by disabling, restricting, leasing, segmenting and auditing.

open as a page

A port-forwarding rule on a home NAT router is correct, yet nothing outside can connect, and the router's WAN address is 100.64.12.9. Why, and what are the options?

level: seniorimportance: should knowfreq 33%

basics

~20 s

100.64.12.9 is in 100.64.0.0/10, the shared space for carrier-grade NAT, so inbound packets stop at the ISP's NAT, which has no mapping toward you. Fix it with a public address, a mapping on the CGN, IPv6 or an outbound tunnel.

open as a page

When a site's traffic is split across two stateful IPv4 NAT routers on separate uplinks, why do existing TCP sessions reset and inbound connections to a forwarded server hang?

level: seniorimportance: should knowfreq 24%

basics

~20 s

Each NAT holds its own mapping state. A flow shifted to the other NAT emerges from a different public address and port, which the peer rejects; a forwarded server's replies leaving through the wrong NAT carry the wrong source.

open as a page

An office's NAT edge router fails over to a standby with identical static and pool configuration but no session table; why do established connections stall while new ones succeed?

level: seniorimportance: should knowfreq 24%

basics

~20 s

Translation state lives only in the device that created it. The standby has the configuration but not the bindings and sessions, so replies to existing sessions match nothing and are dropped, while each new session's first packet builds fresh state.

open as a page

How does RFC 4787 describe a NAT's mapping and filtering behaviour, and why did it retire RFC 3489's full-cone, restricted-cone and symmetric labels?

level: seniorimportance: should knowfreq 27%

basics

~20 s

RFC 4787 splits NAT behaviour into mapping (when a public port is reused across destinations) and filtering (which outside senders may reach it), each endpoint-independent, address-dependent or address-and-port-dependent. RFC 3489's four labels mixed both axes and misdescribed real NATs.

open as a page

When does a TURN relay become unavoidable for two peers behind NATs, and what does relaying through a TURN server cost compared with a direct path?

level: seniorimportance: should knowfreq 24%

basics

~20 s

A TURN relay is unavoidable when no direct candidate pair passes ICE checks, typically because both NATs allocate per-destination ports and filter by port, or UDP is blocked. It costs server bandwidth, latency, per-packet overhead and credentialed state.

open as a page

An organisation enabling IPv6 is asked to put NAT at its edge so internal hosts stay hidden as they were under IPv4; how do you weigh that request?

level: principalimportance: should knowfreq 21%

basics

~20 s

Unbundle it: inbound protection comes from a stateful default-deny firewall, host privacy from temporary addresses, internal-only services from unique local addresses. NPTv6 (RFC 6296) solves renumbering and multihoming but adds no security, and the IETF does not recommend NAT for IPv6.

open as a page

How can a device behind a NAT create its own port-forwarding mapping with UPnP IGD, NAT-PMP or PCP, and how do the three differ?

level: middleimportance: nice to knowfreq 22%

basics

~20 s

The host asks the gateway directly. UPnP IGD is a UPnP Forum protocol using XML over HTTP; NAT-PMP (RFC 6886) is a small leased UDP protocol; PCP (RFC 6887), its Standards Track successor, adds IPv6, firewalls and carrier-grade NAT.

open as a page

Why is a stateful IPv4 NAT's session table a denial-of-service target, and what do the NAT RFCs require when it cannot create a new mapping?

level: seniorimportance: nice to knowfreq 16%

basics

~20 s

Every new flow costs translator memory and lingers for the RFC minimum timers, so one scanning or flooding host can fill the table for everyone. When full, a NAT drops the new packet with an ICMP error and keeps existing mappings.

open as a page

When an IPv4 NAT rewrites an address, which checksums must it fix, and why must it also rewrite the packet quoted inside ICMP error messages?

level: seniorimportance: nice to knowfreq 16%

basics

~20 s

An IPv4 NAT must adjust the IPv4 header checksum and the TCP or UDP checksum, whose pseudo-header includes both addresses. ICMP errors quote the translated packet, so the NAT reverts that quoted copy, or the inside host cannot match the error.

open as a page

showing 1–30 of 31