A toy outbound NAT rewrite changes the source address used for replies.

highlighted = computed this step

NAT changes the source address

Before NAT, the source address is 192.168.1.10. After NAT, the source address is 203.0.113.5.

source IP changes\text{source IP changes}
Source address rewriteThe before and after IP headers show the source address rewrite.Before IP header160 bits / 20 bytes0x4500001e2222400040112c92c0a8010ac6336435byte 0byte 1byte 2byte 301000101000000000000000000011110byte 4byte 5byte 6byte 700100010001000100100000000000000byte 8byte 9byte 10byte 1101000000000100010010110010010010byte 12byte 13byte 14byte 1511000000101010000000000100001010byte 16byte 17byte 18byte 1911000110001100110110010000110101version4ihl5dscp-ecn0x00total-length30identification0x2222fragment-offset0ttl64protocol17->UDPheader-checksum0x2c92source192.168.1.10destination198.51.100.53reserved: clear df: set mf: clearAfter IP header160 bits / 20 bytes0x4500001e222240004011b23ecb007105c6336435byte 0byte 1byte 2byte 301000101000000000000000000011110byte 4byte 5byte 6byte 700100010001000100100000000000000byte 8byte 9byte 10byte 1101000000000100011011001000111110byte 12byte 13byte 14byte 1511001011000000000111000100000101byte 16byte 17byte 18byte 1911000110001100110110010000110101version4ihl5dscp-ecn0x00total-length30identification0x2222fragment-offset0ttl64protocol17->UDPheader-checksum0xb23esource203.0.113.5destination198.51.100.53reserved: clear df: set mf: clear

Destination stays put

The destination address stays 198.51.100.53. NAT is changing the return address here.

destination unchanged\text{destination unchanged}
Source address rewriteThe before and after IP headers show the source address rewrite.Before IP header160 bits / 20 bytes0x4500001e2222400040112c92c0a8010ac6336435byte 0byte 1byte 2byte 301000101000000000000000000011110byte 4byte 5byte 6byte 700100010001000100100000000000000byte 8byte 9byte 10byte 1101000000000100010010110010010010byte 12byte 13byte 14byte 1511000000101010000000000100001010byte 16byte 17byte 18byte 1911000110001100110110010000110101version4ihl5dscp-ecn0x00total-length30identification0x2222fragment-offset0ttl64protocol17->UDPheader-checksum0x2c92source192.168.1.10destination198.51.100.53reserved: clear df: set mf: clearAfter IP header160 bits / 20 bytes0x4500001e222240004011b23ecb007105c6336435byte 0byte 1byte 2byte 301000101000000000000000000011110byte 4byte 5byte 6byte 700100010001000100100000000000000byte 8byte 9byte 10byte 1101000000000100011011001000111110byte 12byte 13byte 14byte 1511001011000000000111000100000101byte 16byte 17byte 18byte 1911000110001100110110010000110101version4ihl5dscp-ecn0x00total-length30identification0x2222fragment-offset0ttl64protocol17->UDPheader-checksum0xb23esource203.0.113.5destination198.51.100.53reserved: clear df: set mf: clear

Protocol stays UDP

The protocol field stays 17, the IP protocol number for UDP.

protocol=17\text{protocol}=17
Source address rewriteThe before and after IP headers show the source address rewrite.Before IP header160 bits / 20 bytes0x4500001e2222400040112c92c0a8010ac6336435byte 0byte 1byte 2byte 301000101000000000000000000011110byte 4byte 5byte 6byte 700100010001000100100000000000000byte 8byte 9byte 10byte 1101000000000100010010110010010010byte 12byte 13byte 14byte 1511000000101010000000000100001010byte 16byte 17byte 18byte 1911000110001100110110010000110101version4ihl5dscp-ecn0x00total-length30identification0x2222fragment-offset0ttl64protocol17->UDPheader-checksum0x2c92source192.168.1.10destination198.51.100.53reserved: clear df: set mf: clearAfter IP header160 bits / 20 bytes0x4500001e222240004011b23ecb007105c6336435byte 0byte 1byte 2byte 301000101000000000000000000011110byte 4byte 5byte 6byte 700100010001000100100000000000000byte 8byte 9byte 10byte 1101000000000100011011001000111110byte 12byte 13byte 14byte 1511001011000000000111000100000101byte 16byte 17byte 18byte 1911000110001100110110010000110101version4ihl5dscp-ecn0x00total-length30identification0x2222fragment-offset0ttl64protocol17->UDPheader-checksum0xb23esource203.0.113.5destination198.51.100.53reserved: clear df: set mf: clear

Summary

The IP source address is rewritten; the destination and protocol are preserved.

IP rewrite only changes source here\text{IP rewrite only changes source here}
Source address rewriteThe before and after IP headers show the source address rewrite.Before IP header160 bits / 20 bytes0x4500001e2222400040112c92c0a8010ac6336435byte 0byte 1byte 2byte 301000101000000000000000000011110byte 4byte 5byte 6byte 700100010001000100100000000000000byte 8byte 9byte 10byte 1101000000000100010010110010010010byte 12byte 13byte 14byte 1511000000101010000000000100001010byte 16byte 17byte 18byte 1911000110001100110110010000110101version4ihl5dscp-ecn0x00total-length30identification0x2222fragment-offset0ttl64protocol17->UDPheader-checksum0x2c92source192.168.1.10destination198.51.100.53reserved: clear df: set mf: clearAfter IP header160 bits / 20 bytes0x4500001e222240004011b23ecb007105c6336435byte 0byte 1byte 2byte 301000101000000000000000000011110byte 4byte 5byte 6byte 700100010001000100100000000000000byte 8byte 9byte 10byte 1101000000000100011011001000111110byte 12byte 13byte 14byte 1511001011000000000111000100000101byte 16byte 17byte 18byte 1911000110001100110110010000110101version4ihl5dscp-ecn0x00total-length30identification0x2222fragment-offset0ttl64protocol17->UDPheader-checksum0xb23esource203.0.113.5destination198.51.100.53reserved: clear df: set mf: clear