Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Networking
  4. NAT (Network Address Translation) explained

NAT (Network Address Translation) explained

Applies to General networking concept, FirewallAudience Server administrators, developersLast reviewed September 2026

Quick answer

NAT (Network Address Translation) lets multiple servers on a private network share one public IP address. As traffic passes through the device doing the translation, each private address is swapped for the shared public one on the way out, and swapped back on the way in for the reply. The two directions you'll meet most often are outbound NAT, where many private servers reach the internet through one public IP, and port forwarding, where a specific inbound port on a public IP is mapped through to a specific private server.

On this page
  • What NAT actually does
  • Outbound NAT: many servers, one public IP
  • Port forwarding: reaching a private server from outside
  • Reading NAT rules in a firewall
  • NAT and private networking

What NAT actually does

A private network uses addresses that aren't routable on the public internet, ranges like 10.0.0.0/8 or 192.168.0.0/16. Those addresses only mean something inside that network. For a server on it to reach the internet, or to be reached from the internet, something has to translate between its private address and a public one, and that's the whole job of NAT.

The device doing the translation, usually a router, firewall or gateway, keeps a translation table while it does this. When a private server sends a packet out, the gateway rewrites the source address to its own public IP and records the mapping. When the reply comes back addressed to that public IP, the gateway looks up the table, works out which private server the reply belongs to, and rewrites the destination address before forwarding it on. The private server never sees its own address changed and the remote server on the other end never sees the private address at all, it only ever talks to the public one.

Outbound NAT: many servers, one public IP

Outbound NAT, sometimes called source NAT, is the direction most people mean by default when they say "NAT". A group of servers on a private network all share one public IP for anything they initiate outward, software updates, API calls, DNS lookups, anything where the private server is the one starting the connection. The gateway tracks each of those outbound connections individually, usually by also rewriting the source port, so replies for dozens or hundreds of simultaneous connections all come back to the same public IP without getting mixed up.

This is why outbound NAT alone doesn't let anything on the internet reach a private server unprompted: there's no rule mapping an unsolicited inbound connection to any particular private address, so it has nowhere to go and gets dropped.

Port forwarding: reaching a private server from outside

Port forwarding, technically destination NAT, is the direction that makes the previous paragraph's limitation useful on purpose rather than a restriction to work around. It's a rule that says: traffic arriving on a specific port of the public IP should be forwarded to a specific private server, on a specific port. Everything else on that public IP stays closed, only the port you've explicitly mapped is reachable.

This is how something behind NAT can still be reached from outside without giving it its own public IP. A web server on a private network might have port 443 on the public IP forwarded to port 443 on its private address, so it's reachable for HTTPS while the rest of the private network, and the rest of that server's ports, stay unreachable from outside.

DirectionAlso calledWhat it doesTypical use
Outbound NATSource NAT (SNAT)Many private addresses share one public IP for traffic they initiateServers on a private network reaching the internet for updates, APIs, DNS
Port forwardingDestination NAT (DNAT)One port on a public IP is mapped through to one private server and portExposing a specific service, such as a web or SSH port, on a server that otherwise has no public IP

Reading NAT rules in a firewall

This distinction matters in practice whenever you're reading a firewall's NAT configuration, because the two directions are usually shown separately. On the Worldstream firewall, NAT lives on its own NAT Rules tab, separate from the Firewall Rules tab. See Firewall basics in Portal for how to work with it.

NAT and private networking

NAT is what makes a private network usable at the internet boundary: the servers behind it keep private addresses among themselves, and the gateway is the only point where translation to a public address happens. See Connecting servers over a private VLAN for how a private segment between dedicated servers gets set up, separately from how it reaches, or is reached from, the internet. For Flexible VPS instances, Portal's own term for that private segment is a Local Network.

Related articles

  • Firewall basics in Portal
  • Connecting servers over a private VLAN
  • CIDR notation: reading an IP range like 192.168.1.0/24
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure