What is NAT, and why does every home network use it?
Network Address Translation lets many devices share one public IP address, by rewriting addresses and ports as traffic passes through the router.
Why it exists. IPv4 provides around 4.3 billion addresses, far fewer than the number of connected devices. NAT was adopted as a stopgap and became universal — and it is why the address shortage has been survivable for decades without forcing IPv6 adoption.
How it works. Inside your home, devices have private addresses — typically 192.168.x.x — which are not routable on the internet. When a device sends a packet out:
The router rewrites the source address to its own public address, and rewrites the source port to a unique value.
It records the mapping in a translation table: this internal device and port corresponds to that external port.
When a reply arrives addressed to that external port, the router looks up the table and rewrites the destination back to the internal device.
Because the port is what distinguishes the sessions, the technique is more precisely PAT — port address translation — though everyone calls it NAT.
The consequence that shapes everything. The mapping is created by outbound traffic. An unsolicited inbound packet has no table entry, so the router does not know where to send it and discards it.
This produces two effects:
A crude firewall. Nothing outside can reach devices inside unprompted. This is genuinely useful security, though it is a side effect rather than a designed protection, and it is not a substitute for a firewall — it does nothing about outbound traffic or anything already inside.
Inbound services need explicit configuration — port forwarding, which manually creates a permanent mapping, or UPnP, which lets applications request one automatically. UPnP is convenient and a recognised security risk, since malware can use it too.
NAT traversal techniques — STUN, TURN and ICE — let two devices behind separate NATs establish direct connections, which is how video calling and peer-to-peer applications work at all.
IPv6 removes the need for NAT, giving every device a routable address and requiring a real firewall instead.