Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


show security nat incoming-table



Display Network Address Translation (NAT) table information.


The incoming dip NAT table is replaced with ALG cone NAT binding table and the show security nat incoming-table command is obsolete from Junos OS Release 11.2 onward. The show security nat incoming-table command works as is in the previous releases.


  • none—Display all information NAT incoming table.

  • node—(Optional) For chassis cluster configurations, display incoming table information on a specific node.

    • node-id —Identification number of the node. It can be 0 or 1.

    • all—Display information about all nodes.

    • local—Display information about the local node.

    • primary—Display information about the primary node.

Required Privilege Level


Output Fields

Table 1 lists the output fields for the show security nat incoming-table command. Output fields are listed in the approximate order in which they appear.

Table 1: show security nat incoming-table Output Fields

Field Name

Field Description

In use

Number of entries in the NAT table.


Maximum number of entries possible in the NAT table.

Entry allocation failed

Number of entries failed for allocation.


Destination IP address and port number.


Host IP address and port number that the destination IP address is mapped.


Number of sessions referencing the entry.


Timeout, in seconds, of the entry in the NAT table.


Name of source pool where translation is allocated.

Sample Output

show security nat incoming-table

Release Information

Command introduced in Junos OS Release 8.5. The node options added in Junos OS Release 9.0.