Monitoring NAT
This section explains how to view NAT license information, NAT statistics, NAT translation entries, NAT address pool information, and NAT inside and outside rule settings.
Displaying the NAT License Key
The show license nat command displays the NAT license key.
show license nat
host1#show license natNat license is nat_licenseDisplaying Translation Statistics
The show ip nat statistics command displays internal statistics that apply to NAT operation.
show ip nat statistics
- Last dynamic allocation failureCompletion level of any dynamic allocation failures; the number of times the router attempted dynamic allocation but reached the dynamic allocation entry limit
- Current static translation entries
- Inside Source SimpleNumber of inside source simple static translations
- Outside Source SimpleNumber of outside source simple static translations
- Inside Source ExtendedNumber of inside source extended static translations
- Outside Source ExtendedNumber of outside source extended static translations
- Dynamic Translation TypeType of dynamic translation (inside source simple, outside source simple, inside source extended)
- CurrentCurrent number of dynamic translations of the associated translation type
- PeakPeak number of dynamic translations of the associated translation type
- AccumulatedAccumulated number of dynamic translations of the associated type; this value reflects the accumulation of dynamic translations since the last router reboot operation
- FailedTotal number of installation attempts that failed for an associated translation type
- Forwarding statistics for packets received on inside or outside interfaces
- forwarded directlyNumber of packets forwarded directly (that is, without the need of translation)
- forwarded through translatorNumber of packets forwarded through the NAT translator
- discardedNumber of packets discarded immediately upon receipt
- discarded by translatorNumber of packets discarded by the NAT translator when no matching translation could be located
host1#show ip nat statisticsNAT database statistics for virtual router vr1:--------------------------------------------------------------Last dynamic allocation failure: normal, successful completionDynamic entry limit was reached 10318 timesCurrent static translation entries:-----------------------------------------Inside Source Simple: 10Outside Source Simple: 3Inside Source Extended: 8Outside Source Extended: 12DynamicTranslation Type Current Peak Accumulated Failed---------------------- ---------- ---------- ----------- ----------Inside Source Simple 69999 69999 69999 12568Outside Source Simple 4518 4518 4518 25Inside Source Extended 70000 70000 70000 568Fully Extended 26855 26855 26855 2565Forwarding statistics for virtual router vr1:------------------------------------------------------------------------Packets received on inside interface andforwarded directly 8forwarded through translator 111763104discarded 2discarded by translator 28524565Bytes received on inside interface andforwarded directly 544forwarded through translator 5141098074Packets received on outside interface andforwarded directly 7forwarded through translator 1031624discarded 3discarded by translator 578961Bytes received on outside interface andforwarded directly 476forwarded through translator 47454704Displaying Translation Entries
The show ip nat translations command displays current translations that reside in the translation table.
Simple translation entries appear with inside/outside and local/global address information. Extended entries appear with added protocol and port numbers (or query IDs).
Using verbose mode additionally provides the time since creation and time since last use for each translation entry.
show ip nat translations
- ProtProtocol (TCP, UDP, ICMP, or GRE) for this translation entry; this field appears only for extended table entries
- Inside localInside local IP address for this translation entry; this field also provides the port number, separated by a colon ( : ) for extended entries
- Inside globalInside global IP address for this translation entry; this field also provides the port number, separated by a colon ( : ) for extended entries
- Outside globalOutside global IP address for this translation entry; this field also provides the port number, separated by a colon ( : ) for extended entries
- Outside localOutside local IP address for this translation entry; this field also provides the port number, separated by a colon ( : ) for extended entries
- Time since creationAmount of time elapsed since the translation entry appeared in the translation table
- Time since last useAmount of time elapsed since the translation entry was used
host1#show ip nat translationsProt Inside local Inside global Outside global Outside local---- --------------- --------------- -------------- ----------------GRE 13.1.2.1:* 20.0.0.1:* --- ---ICMP 13.1.2.2:4 20.0.0.2:4 --- ---TCP 13.1.2.3:20 20.0.0.3:50 --- ---
NOTE: Because they are not NAPT translations, port numbers for GRE translations appear as asterisks (*).
host1#show ip nat translations verboseTime TimeInside Outside Outside since sinceProt Inside local global global local creation last use---- ------------ ----------- ----------- ----------- ------------ ------------20.0.0.3 30.0.0.3 --- --- 00:04:50 00:00:0121.0.0.3 30.208.0.3 --- --- 00:02:12 00:00:0121.0.0.4 30.208.0.4 --- --- 00:02:12 00:00:01--- --- 50.0.0.3 70.0.0.3 00:03:24 Never--- --- 51.0.0.3 70.208.0.3 00:01:44 00:00:01--- --- 51.0.0.4 70.208.0.4 00:01:44 00:00:01UDP --- --- 50.50.0.3:8 70.50.0.3:8 00:03:10 Never7 108UDP 22.0.0.4:63 30.224.0.3: --- --- 00:02:12 00:00:014097UDP 22.0.0.3:63 30.224.0.3: --- --- 00:02:12 00:00:014096TCP --- --- 50.50.0.3:8 70.50.0.3:8 00:03:10 Never0 008UDP 20.50.0.3:87 30.50.0.3:8 --- --- 00:03:35 Never108Displaying Address Pool Information
The show ip nat pool command displays NAT address pool information. The command output displays configuration (mask and address ranges) of all address pools, unless you supply a specific pool name.
show ip nat pool
- poolName of the address pool
- netmaskNetwork prefix associated with the NAT address pool
- prefix lengthPrefix length associated with the NAT address pool
- rangeAddress ranges used by this NAT address pool
host1#show ip nat poolpool: pool1 netmask: 255.255.255.0 prefix length: 24range: 3.3.3.1 to 3.3.3.255range: 4.4.4.1 to 4.4.4.32pool: pool2 netmask: 255.255.255.0 prefix length: 24range: 1.1.1.1 to 1.1.1.24range: 2.2.2.1 to 2.2.2.55Example 2 host1#show ip nat pool pool1pool: pool1 netmask: 255.255.255.0 prefix length: 24range: 3.3.3.1 to 3.3.3.255range: 4.4.4.1 to 4.4.4.32Displaying Inside and Outside Rule Settings
The show ip nat inside rule and show ip nat outside rule commands display access list and pool usage for all dynamic translation rules configured for the virtual router. If you do not specify an access list, the output displays address pool associations for each of the access lists for either inside or outside translation rules in the virtual router. Specifying an access list filters the output to display only the address pool associated with the specified list.
show ip nat inside rule
- Use to display NAT access list and pool usage information for inside source translation rules.
- Field descriptions
- access list nameName of the access list
- pool nameName of the address pool
- rule typeType of rule assigned
host1#show ip nat inside ruleaccess list name: list1 pool name: poolA rule type: inside sourceaccess list name: list2 pool name: poolB rule type: inside sourceaccess list name: list3 pool name: poolC rule type: inside source overloadshow ip nat outside rule
- Use to display NAT access list and pool usage information for outside source translation rules.
- Field descriptions
- access list nameName of the access list
- pool nameName of the address pool
- rule typeType of rule assigned
host1#show ip nat outside ruleaccess list name: list4 pool name: poolD rule type: outside source