IP Routing and NAT: How Packets Cross Networks
Learn how routers choose paths with routing tables, longest-prefix match, and gateways, then see how NAT and port translation change packets at network edges.
This guide follows packets through routing tables, next-hop selection, longest-prefix match, and common NAT and NAPT patterns. It explains how translation changes addresses or ports, why return traffic needs the right mapping, and how route choices, asymmetric paths, and stale forwards cause failures. Use the Linux commands and packet-level checks to distinguish routing, translation, and firewall problems before changing edge rules.
IP Routing and NAT: How Packets Cross Networks
Introduction
An IP packet starts with a destination address, but that address alone does not tell a host how to reach it. The host checks its routing table, chooses a next hop, and sends the packet toward that next hop. Routers repeat the same basic decision until the packet reaches its destination network.
At a network boundary, a router may also translate the packet’s address or port. That is Network Address Translation (NAT). Routing decides where a packet goes; NAT changes selected fields as it passes through a device. The two often appear together in home and enterprise networks, which is why their jobs are easy to blur.
This guide covers route selection, routing behavior, and common NAT patterns, then shows how to inspect paths and reason about failures such as asymmetric routing. It also compares the operational trade-offs of translation and routing choices.
When to Use
Routing tables are needed anywhere traffic must move between IP networks. A default gateway is useful for end hosts that have one ordinary path off their local subnet. More specific static routes fit small networks with stable topology, while dynamic routing helps routers adapt in larger or changing networks.
NAPT is commonly used when many private IPv4 devices need outbound access through a smaller number of public addresses. Static NAT or a port forward can expose a specific service when an inbound connection is required. In either case, pair the translation rule with explicit firewall policy and document which internal system receives the traffic.
When NOT to Use
Avoid adding NAT between networks when you can route the address space directly and both sides can use unique, reachable addresses. Translation makes packet traces and logs harder to interpret, and protocols or applications that embed IP addresses may need extra handling.
Do not create broad port forwards just to make a service reachable. Expose only the required destination and port, restrict source networks when practical, and protect the service itself. NAT does not fix overlapping address plans cleanly; renumbering or a deliberate routing design is usually easier to operate.
Production Failure Scenarios
A more specific route sends traffic the wrong way
A host has a default gateway and a stale /25 route for a destination that should follow the default. Because the /25 prefix is more specific, longest-prefix match selects it. Check ip route get <destination> on the source and inspect routes on each router along the path before changing NAT rules.
The return path differs from the outbound path
Traffic leaves through one edge router, but the reply returns through another device that has no matching translation state. The connection stalls even though outbound packets appear to leave successfully. Compare both directions of a packet capture and verify routing symmetry or configure the network and translation design to support asymmetric paths.
A port forward reaches the wrong host
An internal address changed after a DHCP lease or deployment, but the edge mapping still points to the previous host. Keep internal service addresses stable through reservations or static assignment, and verify the forward target after network changes.
Traceroute appears to stop early
The last visible hop may filter ICMP time-exceeded messages. Test the destination service directly, check firewall counters, and compare with another path measurement before declaring a routing failure. Traceroute reports responses to its probes, not a full inventory of routers.
Translation state exhausts or expires
A large number of short-lived connections or a long idle period can leave an application without a usable mapping. Inspect the translation table and its timeout behavior on the relevant device. If the service needs long idle sessions, tune timeouts deliberately and confirm that intermediate firewalls agree.
Trade-Off Table
| Choice | Useful when | Cost or risk |
|---|---|---|
| Static route | Topology is small and stable | Changes require an operator or automation to update routes |
| Dynamic routing | Many routers or paths can change | Protocol configuration and route policy add operational complexity |
| Direct routing | Networks have unique, reachable address space | Requires address planning and compatible routing between networks |
| NAPT/PAT | Many private IPv4 hosts share public IPv4 space | State, port limits, and address rewriting complicate inbound access and diagnostics |
| Static NAT or port forward | A particular internal service must accept inbound traffic | The exposed service needs explicit filtering and ongoing security maintenance |
Observability Checklist
- Use
ip routeto inspect installed routes andip route get <destination>to verify the host’s actual next-hop choice. - Run
traceroute -n <destination>ortraceroute -6 -n <destination>to compare the IPv4 or IPv6 path; treat silent hops cautiously. - Capture traffic on both sides of the translation device and compare source/destination address and port tuples.
- Check NAT or connection-tracking counters for new mappings, established flows, drops, and table pressure.
- Review firewall logs separately from translation logs. A successful NAT mapping does not prove a firewall permitted the intended traffic.
- Monitor route changes and interface state so a path change can be correlated with packet loss or asymmetric return traffic.
Security and Compliance Notes
Treat a port forward as a deliberate service exposure. Restrict its destination and port, limit who can connect where possible, and keep host-level controls in place. Review both IPv4 and IPv6 policy: NAT is common in IPv4 deployments, but IPv6 connectivity often uses globally routable addresses and still needs firewall rules.
Logs should preserve enough information to correlate a translated public flow with its private source, including timestamp, protocol, address, and port mapping. Retain that data only as long as operational and compliance requirements call for it, and protect it because connection metadata can reveal user activity. Follow your organization’s policy for access, retention, and incident response.
Common Pitfalls / Anti-Patterns
- Assuming a default route wins over every other route. A matching, more specific prefix takes precedence.
- Blaming NAT when a host has selected the wrong gateway or a router lacks a return route.
- Treating a successful outbound connection as proof that unsolicited inbound traffic is safely filtered.
- Building a chain of translations without documenting which device owns each mapping.
- Forgetting that a NAT mapping is stateful and that a different return path may reach a device without the required state.
- Reading traceroute’s unanswered hop as proof that the router cannot forward traffic.
- Assuming NAT removes the need for unique internal addressing. Overlapping networks still cause routing ambiguity.
Quick Recap Checklist
- A router uses a routing table to choose a next hop for a destination.
- Longest-prefix match selects the most specific matching route; a default route covers destinations without a more specific match.
- The IPv4 TTL and IPv6 Hop Limit decrease at each forwarding hop to prevent endless loops.
- NAT rewrites IP addresses; NAPT/PAT also rewrites transport ports so flows can share an address.
- Stateful translation maps replies to existing flows; inbound connections need an explicit mapping or another supported design.
- NAT and firewall filtering are separate functions. Configure and monitor both.
Interview Questions
It uses longest-prefix match: the route with the most prefix bits in common wins. A route for 10.20.0.0/16 is more specific than a default route, and 10.20.4.0/24 is more specific than the /16 for addresses inside that subnet.
A default route is the routing-table entry used when no more specific route matches. Its next hop is often called the default gateway on an end host. The route is the forwarding rule; the gateway is the router address that receives the packet.
Basic NAT translates IP addresses. NAPT, also called PAT, translates addresses and transport ports. Port translation lets multiple private hosts share one public IPv4 address while the device tracks distinct flows.
NAT changes packet addresses and may keep state for replies, but it does not express the full policy for which traffic should be allowed. A firewall applies explicit allow and deny rules, which remain necessary for both translated and directly routed networks.
Expected answer points:
- A router may filter or rate-limit the ICMP time-exceeded response used by traceroute while still forwarding ordinary traffic.
- Traceroute shows responses to its probes, not a complete list of forwarding devices.
- Test the destination service and compare other path measurements before treating a silent hop as an outage.
Expected answer points:
- The reply may reach an edge device that does not hold the outbound flow's translation state.
- That device cannot reverse the mapping to the private endpoint, so the connection may stall even though outbound packets left successfully.
- Compare captures and state on both edges, then verify path symmetry or use a design that shares or preserves the required state.
Expected answer points:
- It shows the host's selected route, next hop, interface, and source address for a destination.
- If that choice is unexpected, investigate local routes and policy before changing NAT rules.
- A plausible local choice does not prove that intermediate routers, firewalls, or the return path work; continue with path and packet evidence.
Expected answer points:
- The host or router must first select a route, and overlapping prefixes can make that destination ambiguous or send it to the wrong next hop.
- Ordinary outbound NAPT translates flows at an edge; it does not redesign every route between overlapping networks.
- Prefer unique address plans where possible; if translation is required, design and document the specific translated paths deliberately.
Further Reading
- RFC 1812: Requirements for IPv4 Routers
- RFC 3022: Traditional IP Network Address Translator
- RFC 4632: Classless Inter-domain Routing (CIDR)
- TCP, IP, and UDP: How Transport and Network Layers Work Together
- Network Ports and Firewalls
- The OSI and TCP/IP Network Models
Conclusion
Routing tables determine a packet’s next hop, with longest-prefix match choosing the most specific route and a default gateway handling destinations without a closer match. NAT changes addresses at a network edge; NAPT/PAT also changes ports and tracks flows so replies can return to private hosts. Use routing tools and packet captures to follow each direction, and keep firewall policy separate from translation.
Category
Related Posts
Ethernet, ARP, and Neighbor Discovery Explained
Learn how Ethernet frames, switches, VLANs, ARP, and IPv6 Neighbor Discovery deliver packets on a local link, with Linux diagnostics and failure examples.
TCP Congestion Control: Flow, Loss, and Fairness
Learn how TCP congestion control limits traffic, responds to ACKs and loss, and affects throughput, latency, and fairness, with Linux inspection commands.
Network Encapsulation: Follow a Packet Across the Stack
Follow an HTTPS request from a browser through transport, IP, and link layers, and learn how headers, MTU, routers, and packet captures fit together.