NAT (Network Address Translation) explained
Kort antwoord
NAT (Network Address Translation) lets multiple servers on a private network share one public IP address. As traffic passes through the device doing the translation, each private address is swapped for the shared public one on the way out, and swapped back on the way in for the reply. The two directions you'll meet most often are outbound NAT, where many private servers reach the internet through one public IP, and port forwarding, where a specific inbound port on a public IP is mapped through to a specific private server.
What NAT actually does
A private network uses addresses that aren't routable on the public internet, ranges like 10.0.0.0/8 or 192.168.0.0/16. Those addresses only mean something inside that network. For a server on it to reach the internet, or to be reached from the internet, something has to translate between its private address and a public one, and that's the whole job of NAT.
The device doing the translation, usually a router, firewall or gateway, keeps a translation table while it does this. When a private server sends a packet out, the gateway rewrites the source address to its own public IP and records the mapping. When the reply comes back addressed to that public IP, the gateway looks up the table, works out which private server the reply belongs to, and rewrites the destination address before forwarding it on. The private server never sees its own address changed and the remote server on the other end never sees the private address at all, it only ever talks to the public one.
Outbound NAT: many servers, one public IP
Outbound NAT, sometimes called source NAT, is the direction most people mean by default when they say "NAT". A group of servers on a private network all share one public IP for anything they initiate outward, software updates, API calls, DNS lookups, anything where the private server is the one starting the connection. The gateway tracks each of those outbound connections individually, usually by also rewriting the source port, so replies for dozens or hundreds of simultaneous connections all come back to the same public IP without getting mixed up.
This is why outbound NAT alone doesn't let anything on the internet reach a private server unprompted: there's no rule mapping an unsolicited inbound connection to any particular private address, so it has nowhere to go and gets dropped.
Port forwarding: reaching a private server from outside
Port forwarding, technically destination NAT, is the direction that makes the previous paragraph's limitation useful on purpose rather than a restriction to work around. It's a rule that says: traffic arriving on a specific port of the public IP should be forwarded to a specific private server, on a specific port. Everything else on that public IP stays closed, only the port you've explicitly mapped is reachable.
This is how something behind NAT can still be reached from outside without giving it its own public IP. A web server on a private network might have port 443 on the public IP forwarded to port 443 on its private address, so it's reachable for HTTPS while the rest of the private network, and the rest of that server's ports, stay unreachable from outside.
| Direction | Also called | What it does | Typical use |
|---|---|---|---|
| Outbound NAT | Source NAT (SNAT) | Many private addresses share one public IP for traffic they initiate | Servers on a private network reaching the internet for updates, APIs, DNS |
| Port forwarding | Destination NAT (DNAT) | One port on a public IP is mapped through to one private server and port | Exposing a specific service, such as a web or SSH port, on a server that otherwise has no public IP |
Reading NAT rules in a firewall
This distinction matters in practice whenever you're reading a firewall's NAT configuration, because the two directions are usually shown separately. On the Worldstream firewall, NAT lives on its own NAT Rules tab, separate from the Firewall Rules tab. See Firewall basics in Portal for how to work with it.
NAT and private networking
NAT is what makes a private network usable at the internet boundary: the servers behind it keep private addresses among themselves, and the gateway is the only point where translation to a public address happens. See Connecting servers over a private VLAN for how a private segment between dedicated servers gets set up, separately from how it reaches, or is reached from, the internet. For Flexible VPS instances, Portal's own term for that private segment is a Local Network.