📝 Section Review: NAT
اہم نکاتKey TakeawaysKey Takeaways
- Dynamic PAT پوری private LAN کو ایک public IP share کرنے دیتا ہے — inside internet access کے لیے default۔Dynamic PAT poori private LAN ko ek public IP share karne deta hai — inside internet access ke liye default.Dynamic PAT lets a whole private LAN share one public IP — the default for inside internet access.
- Static NAT server کو inbound access کے لیے fixed one-to-one public mapping دیتا ہے۔Static NAT server ko inbound access ke liye fixed one-to-one public mapping deta hai.Static NAT gives a server a fixed one-to-one public mapping for inbound access.
- NAT rule order matter کرتا ہے: exemption/identity rules general PAT rules کے اوپر ہونے چاہیے۔NAT rule order matter karta hai: exemption/identity rules general PAT rules ke upar hone chahiye.NAT rule order matters: exemption/identity rules must sit above general PAT rules.
- `show nat` rule order دکھاتا ہے؛ `show xlate` live translations دکھاتا ہے — debugging میں دونوں use کریں۔`show nat` rule order dikhata hai; `show xlate` live translations dikhata hai — debugging mein dono use karo.`show nat` shows rule order; `show xlate` shows live translations — use both when debugging.
- صرف static NAT کافی نہیں — outside ACL کو mapped address تک traffic پھر بھی permit کرنا ہوتا ہے۔Sirf static NAT kafi nahi — outside ACL ko mapped address tak traffic phir bhi permit karna hota hai.Static NAT alone isn't enough — the outside ACL must still permit the traffic to the mapped address.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ Auto NAT، Manual NAT اور Twice NAT compare کریں۔Auto NAT, Manual NAT aur Twice NAT compare karo.Compare Auto NAT, Manual NAT, and Twice NAT.
Auto NAT network object پر ہی ہوتا ہے اور simplest ہے؛ Manual NAT NAT table section میں لکھا جاتا ہے، top-down process ہوتا ہے، complex cases کے لیے؛ Twice NAT ایک rule میں source اور destination translation define کرتا ہے۔Auto NAT network object par hi hota hai aur simplest hai; Manual NAT NAT table section mein likha jata hai, top-down process hota hai, complex cases ke liye; Twice NAT ek rule mein source aur destination translation define karta hai.Auto NAT lives on the network object itself and is simplest; Manual NAT is written in the NAT table section, processed top-down, for complex cases; Twice NAT defines source and destination translation in one rule.
❓ کون سی command سارے inside users کو PAT سے internet access دیتی ہے؟Kaun si command sare inside users ko PAT se internet access deti hai?What command gives all inside users internet access via PAT?
Inside network object پر `nat (inside,outside) dynamic interface` — سارے inside hosts outside interface IP share کرتے ہیں (PAT)۔Inside network object par `nat (inside,outside) dynamic interface` — sare inside hosts outside interface IP share karte hain (PAT).`nat (inside,outside) dynamic interface` on the inside network object — all inside hosts share the outside interface IP (PAT).
❓ VPN traffic کو NAT سے کیسے exempt کرتے ہیں؟VPN traffic ko NAT se kaise exempt karte ho?How do you exempt VPN traffic from NAT?
PAT rule سے پہلے identity twice-NAT (source static X X, destination static Y Y)، تاکہ VPN interesting traffic translation سے exempt ہو۔PAT rule se pehle identity twice-NAT (source static X X, destination static Y Y), taake VPN interesting traffic translation se exempt ho.An identity twice-NAT (source static X X, destination static Y Y) placed before the PAT rule, so VPN interesting traffic is exempted from translation.