You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于DNAT的技术问询:局域网双主机访问同一外网服务器的转发问题

How NAT Routers Distinguish & Forward Return Packets for Concurrent LAN Connections

Great question—this cuts to the heart of how NAT (and specifically Port Address Translation, which is critical here) handles concurrent connections from multiple LAN devices to the same external server. Let’s break it down simply:

The Core Mechanism: NAT Session Tables

When a LAN device sends an outgoing request to an external server, your router doesn’t just swap the source IP (from the device’s private IP to the router’s public IP). It also assigns a unique temporary source port to the outgoing packet. This creates a unique "session" that the router tracks in its NAT session table (sometimes called a translation table).

Each entry in this table stores a full set of identifying details for the connection, which the router uses to match return packets to the correct LAN device.

Key Information That Enables Correct Forwarding

The router relies on these critical pieces of data to avoid mixing up responses:

  • Five-Tuple Identifier: This is the golden ticket for distinguishing sessions. It includes:
    • Private source IP (the LAN device’s IP)
    • Private source port (a random port the LAN device uses for the request)
    • Public destination IP (the external server’s IP)
    • Public destination port (the server’s service port, e.g., 80 for HTTP, 443 for HTTPS)
    • Transport layer protocol (TCP or UDP; ports are independent across protocols, so TCP 80 and UDP 80 count as separate sessions)
  • Port Address Translation (PAT): This is the extension of NAT that lets multiple devices share a single public IP. By assigning a unique temporary public port to each LAN device’s outgoing request, even if two devices are connecting to the exact same server port, their router-side ports are different—making their session entries unique.
  • NAT Session Table State: The router keeps track of active sessions, including timestamps to clean up stale entries (so the table doesn’t get cluttered). For TCP connections, it might also track handshake state (SYN, ACK, etc.) to validate legitimate traffic.

A Quick Example to Make It Concrete

Let’s say you have two LAN devices:

  1. Device A (192.168.1.100) sends a request to 203.0.113.5:80 using its own random port 54321.
    • Router translates this to 123.45.67.89:10001 (router’s public IP + temporary port) and adds an entry to its session table mapping 192.168.1.100:54321 ↔ 123.45.67.89:10001 for the destination 203.0.113.5:80 (TCP).
  2. Device B (192.168.1.101) sends a request to the same 203.0.113.5:80 using its random port 65432.
    • Router translates this to 123.45.67.89:10002 and adds a second unique session entry.

When the server sends a response back to 123.45.67.89:10001, the router looks up its session table, finds the mapping to Device A, rewrites the destination IP/port to 192.168.1.100:54321, and forwards the packet. Responses to 10002 go straight to Device B—no mix-ups.

Note on DNAT

You mentioned DNAT specifically—while your scenario focuses on outgoing connections (handled by SNAT + PAT), DNAT works similarly but in reverse (forwarding incoming public traffic to a LAN device). The same five-tuple logic applies: DNAT relies on session tables to track which incoming packets belong to which internal device’s session.

内容的提问来源于stack exchange,提问作者DariushStony

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 19:07:35