Home > Ticket 4 – NAT ACL

Ticket 4 – NAT ACL

May 3rd, 2018 in TSHOOT v2 Go to comments

Note: Although in our ticket we cannot ping the Web server from DSW1 (as the NAT configuration is wrong) but in the exam we can. This is a bug in the exam so be careful with it.

Configuration of R1

interface Serial0/0/1
ip address
ip nat inside
interface Serial0/0/0
ip address
ip nat inside
ip ospf message-digest-key 1 md5 TSHOOT
ip ospf authentication message-digest

Ans1) R1
Ans2) NAT
Ans3) Under interface Serial0/0/1 delete the ip nat inside command and add the ip nat outside command.

Comments (50) Comments
Comment pages
1 5 6 7 8 28
  1. passed2k18
    January 14th, 2018

    Pass Friday with perfect score. This question is still bugged where the Show Run is S0/0/1 as outside interface, but the show ip nat statistics exposes the NAT issue with s0/0/0 and s0/0/1 as both inside.. Trust show ip nat statistics not show run.

  2. bubu2018
    January 16th, 2018

    all tickets were like at 9tut? it’s something changed?

  3. passed2k18
    January 16th, 2018

    @bubu2018 Well Networktut, not 9tut :) All MCP, BGP Sim, and Tickets are valid. There are 2 bugs though. This Nat question and the OSPF to EIGRP question. Look at the comments on both tickets and you will be fine.

  4. Hunter
    February 9th, 2018

    Anyways trust the “sh ip nat statistics” on R1 which will show no outside interface.. Easiest way to solve this TT. But this is a very tricky TT to spot as pings from everywhere else except client1..

  5. Run
    February 28th, 2018

    Copy below Link:

    thnku all
    passed with 9xx no removed lab..
    12 ticket
    4 dnd
    2 mcq
    i lab bgp

    thnx all who cmnt and share experience here..
    All this files in link above enough to secure pass easily.

  6. Anonymous
    March 1st, 2018

    I’m not understanding the problem here…sh run shows s0/0/1 as an inside interface as does sh ip nat stat…so the answer is:

    1) R1
    2) NAT
    3) Under s0/0/1 delete “ip nat inside” and add “ip nat outside”?

  7. Will
    March 4th, 2018

    In the exam, when you enter show ip nat statistic both interface are in nat inside. You need to change interface s0/0/1 to ip nat outside.

  8. hresp
    March 26th, 2018

    Hi, I pass the exam yesterday and in this ticket I found both interfaces s0/0/0 and s0/0/1 with “ip nat outside” configuration. Have changed the s0/0/0 to inside.

  9. this is…
    March 29th, 2018

    under NAT access list, enter the command permit”

  10. Anonymous
    March 29th, 2018

    The config for this ticket is f-ked up and misleading and leaves no alternative but to learn by heart like parrot!!!

    Regardless, this is way ping is failing: on R1 NAt access list won’t allow traffic from the network 10.2.0/24 to pass:
    ip access-list standard Nat_Traffic

    Add : permit to the access list and ping form the Client 1 will be successful.

    If you want to mimic exam environment, on the interface connecting to ISP replace ip nat outside with ip nat inside.

    config t 0
    interface Serial 0/0/0/1
    no ip nat outside
    ip nat inside


    wr mem

    The above config change will cause ping from any device to fail.

    There is no such thing as bug in exam, everything is very intentionally tricky

    show ip nat will show the miss configuration

  11. O_sal
    April 3rd, 2018

    Yesterday I got this ticket in the exam, exactly as it is here, the only thing confused me was DSW1 was pinging the internet server, while R4, R3, & R2 were not, I thought there was some other issue or a change, it took me 40 minutes to check everything from A to Z.

    At the end I decided to go with nat out side as an issue for the local interface of R1.

    I guess that was a bug.

  12. lucifuge21
    April 3rd, 2018

    Passed today with perfect score. In my exam both interfaces had outside NAT so I had to choose the inside option.
    If ping from client to R1 is successful, check “ip nat stat”. If both interfaces are outside, check inside.

    Good luck.

  13. Asbestos Watch Adelaide
    April 23rd, 2018

    Youre so cool! I dont suppose Ive read something like this before. So nice to find somebody with some original thoughts on this subject. realy thank you for beginning this up. this web site is one thing that’s needed on the web, somebody with a bit of originality. helpful job for bringing one thing new to the internet!


  14. phylon
    May 1st, 2018

    Presented today the ticket they inverted the simulation now the 2 interfaces are nat inside and the s0/0/1 need to be change to NAT outside instead NAT inside

  15. smk
    May 3rd, 2018

    Pass with 97x/1000

    Thanks for all your comments,
    the Tickets are still vaild.
    had total 22Q
    new D&D & MCQ – valid
    HSRP SIM – valid (including the 4q R5 & R4 – DHCP issue)
    Other tickets were
    Ticket 1 – IPv4 OSPF Routing (R1: Add “ip ospft Authentication message-digest” under S0/0/0/0)
    Ticket 3 – BGP (R1: wrong Neighbor address)
    Ticket 4 – NAT (R1: IP NAT inside on S0/0/0/1 (both interfaces IP NAT Inside)
    Ticket 8 – Access VLAN (ASW1: switchport mode trunk; change to switchport mode access)
    Ticket 9 – Switch to switch connectivity (ASW1: Switchport trunk allowed vlan 10 200)
    Ticket 11 – IPV4 Redistribution (R4: Wrong Route-map name OSPF->EIGRP changed to OSPF_TO_EIGRP)
    Ticket 12 – IPv6 OSPF routing (R2: add “ipv6 ospf 6 area 0” under S0/0/0/0.23)
    Ticket 13 – DHCP Helper (DSW1: wrong address based on what R4 loopback – change to
    Ticket 15 – IPv6-IPV4 connectivity (R3: Remove “tunnel mode ipv6 under tunnel34)
    Ticket 16 – IPV6 RIPng OSPFv3 Redistribute

  16. Marty
    May 7th, 2018

    SMK – which D&D did you get? Did you have the GRE packet/header sequence? If so, what order did you place it in? Thanks

  17. Anonymous
    May 7th, 2018

    SMK , can you please share the link for the dump you studied ?

  18. Anonymous
    May 8th, 2018

    Is anyone else not able to see the questions and answers or is it just me?

  19. ccnpbotswana
    May 9th, 2018

    if both interfaces in the configuration in the exam are IP NAT INSIDE which answer do we choose on the third option when selecting answers.???

  20. ccnpbotswana
    May 9th, 2018

    if both interfaces in the configuration in the exam are IP NAT INSIDE which answer do we choose on the third option when selecting answers.???

    which is the correct option between the two;

    under the interface s0/0/0 configuration enter the ‘ip nat inside’ command


    under the interface s0/0/1 configuration enter the ‘ip nat outside’ command

  21. 46598dasd
    May 14th, 2018

    2018 Latest Update CCNP Dumps 300-135 100% Valid

  22. CCNP2k
    May 24th, 2018

    This IP NAT inside ticket #4 is actually a Nat access-list issue.

    The broken access list:
    ip access-list standard Nat_Traffic
    access-list 30 permit
    access-list 30 permit host
    access-list 30 permit host
    access-list 30 deny
    access-list 30 deny

    Good access-lists
    ip access-list standard Nat_Traffic
    access-list 30 permit
    access-list 30 permit host
    access-list 30 permit host
    access-list 30 deny
    access-list 30 deny
    This caused the traffic from vlan10 to get all the way to R1 interface but no further.

  23. Yammer
    May 28th, 2018

    For those who have this ticket recently, has this changed?

  24. X
    June 6th, 2018

    @ ccnpbotswana May 9th, 2018

    “if both interfaces in the configuration in the exam are IP NAT INSIDE which answer do we choose”

    under the interface s0/0/1 configuration enter the ‘ip nat outside’ command

    @CCNP2k May 24th, 2018
    Thank you for the feedback. It looks like this is an NAT ACL issue and that makes sense, the fist ACL “ip access-list standard Nat_Traffic” does not allow the network (hit the implicit deny at the end of the ACL), the second one has an explicit permit entry:

    ip access-list standard Nat_Traffic

    ip access-list standard Nat_Traffic
    permit <<<

    Thank you team.

  25. X
    June 6th, 2018

    Does anyone know if in the same ticket we can skip question 1 and 2 so that we can have an insight in question 3 were the issue might be and troubleshoot from there?

  26. sybabe
    July 7th, 2018

    Did anyone notice that the network command statement area 12 was missing from R1?

  27. Network Tut Help me
    August 3rd, 2018

    WHat is the question of this ticket?

    How will i find this answer belongs to which ticket if question is not available?

  28. CCNP Boy
    August 3rd, 2018

    TIP :

    Client 1 : can ping R1, DSW1 and
    NO ping web server
    DSW1 : can ping R1, Client 1
    Traceroute to COMPLETE

    R1 : can ping Client 1, DSW1 and web server
    sh run ==> check inteface s0/0/0 and s0/0/1 ==> change IP NAT OUTSIDE for IP NAT INSIDE

    Hope this can help someone or if im wrong please let me know

  29. Anonymous
    August 8th, 2018

    @Network Tut
    Dear Team,
    My account is going to expire and I have 5 tickets left
    4 , 8 , 9 , 11 and 17 does not have a problem question.How will I be able to identify if no question is stated.

    Problem: Client 1 is able to ping but can’t ping the Web Server

  30. detective
    September 8th, 2018


    ticket #4 and 25 will confuse premium users.

    ticket 4 = both se0/0/0 and se0/0/1 has “ip nat INSIDE” = the answer is to change se0/0/1(link to ISP) to “ip nat OUTSIDE”, which is correct


    ticket #25 = both se0/0/0 and se0/0/1 has “ip nat INSIDE” = the answer is to change se/0/0/0(link to r2) to “ip nat INSIDE”, which is confusing,

    please update the ticket!!

  31. networktut
    September 8th, 2018

    @detective: Thanks for your detection, we have just fixed ticket 25.

  32. NetworkDisa
    September 11th, 2018


    Please check ticket no 4, The selections …
    Question1: R1
    Question2: IP NAT
    Question3: Under the interface S0/0/1 configuration enter the “ip nat outside”

    But according to the simulation configuration the answer would be…
    Under the interface S0/0/0 configuration enter the “ip nat inside”

    Please correct this.

  33. network
    September 16th, 2018

    Guys dont forget to check the address assigned to the end clients as that what the issue is within the ACL. One may think that client 1 is within which is allowed in Nat ACL but client 1 and client 2 both have 10.2.x.x addresses. This holds true with everything else that has been said here which is to also check the interfaces for IP nat inside/outside. Adding did the charm for me.

    BTW i havent taken the exam, still preparing….

  34. bestb
    September 16th, 2018

    Where I can find ticket 25? I can see 17 ! I have premium

  35. networktut
    September 17th, 2018

    @bestb: You can find all tickets at https://www.networktut.com/all-tickets

  36. Anonymous
    October 4th, 2018

    Packet tracer was an ACL issue. 3:33 to fix. Pings work everywhere but client.

  37. akj
    October 11th, 2018

    What is APIPA address?

  38. AMER
    October 17th, 2018


  39. Anonymous
    October 17th, 2018

    where are finished the solutions? i have the exam the 19 october!

  40. Soka
    October 17th, 2018

    can i ask one thing? pls next time write ” we are working on a new ticket” instead of nothing, i wasted hours trying to solve the ticket 25 whit the old aswers.

  41. Mr H
    October 17th, 2018


    (Automatic Private IP Addressing) The Windows function that provides DHCP autoconfiguration addressing. APIPA assigns a class B IP address from to to the client when a DHCP server is either permanently or temporarily unavailable.

  42. Holdon
    November 26th, 2018

    now ticket 4 error is both Inside/Outside NAT interface (not missing “permit” command any more) .. Ticket 4 is still not updated as per New Exam can anybody please update ..

  43. G_naher
    November 27th, 2018

    can someone fix this
    in Premium account ticket 4 answer is wrong option, where option suppose to be
    Under interface Serial0/0/0.12 delete the ip nat outside command and add the ip nat inside command
    but there is no option like this and answer getting correct on
    Under the Interface Serial0/0/1 configuration enter the ‘ip nat outside’ command

  44. networktut
    November 27th, 2018

    @Holdon, @G_naher: Thanks for your information. We have just updated this ticket.

  45. Ciscoman
    December 1st, 2018

    With this configuration,
    Would you ping to
    I dont think so,
    What do you think?

    Thanks in advance!

  46. Tharos
    December 9th, 2018

    no validation on this ticket at the moment? can anyone please confirm and share the actual answer for this ticket?

    networktut group, any input on this?

  47. Goku123
    December 12th, 2018

    missing permit

    add permit

  48. Sunny
    December 18th, 2018

    @Networktut team. have you updated tkt #4 ? there is a lot of confusion here about this NAT tkt and it does’t look like you updated it based on all the comments here.

    please assist

  49. Anonymous
    December 20th, 2018

    i think i failed an exam because of this stupid question, both interfaces were ip nat outside, just submitted bug report to cisco

  50. Winter
    January 7th, 2019

    What is the problem statement for this ticket?

Comment pages
1 5 6 7 8 28