关于DNAT的技术问询:局域网双主机访问同一外网服务器的转发问题
Great question—this cuts to the heart of how NAT (and specifically Port Address Translation, which is critical here) handles concurrent connections from multiple LAN devices to the same external server. Let’s break it down simply:
The Core Mechanism: NAT Session Tables
When a LAN device sends an outgoing request to an external server, your router doesn’t just swap the source IP (from the device’s private IP to the router’s public IP). It also assigns a unique temporary source port to the outgoing packet. This creates a unique "session" that the router tracks in its NAT session table (sometimes called a translation table).
Each entry in this table stores a full set of identifying details for the connection, which the router uses to match return packets to the correct LAN device.
Key Information That Enables Correct Forwarding
The router relies on these critical pieces of data to avoid mixing up responses:
- Five-Tuple Identifier: This is the golden ticket for distinguishing sessions. It includes:
- Private source IP (the LAN device’s IP)
- Private source port (a random port the LAN device uses for the request)
- Public destination IP (the external server’s IP)
- Public destination port (the server’s service port, e.g., 80 for HTTP, 443 for HTTPS)
- Transport layer protocol (TCP or UDP; ports are independent across protocols, so TCP 80 and UDP 80 count as separate sessions)
- Port Address Translation (PAT): This is the extension of NAT that lets multiple devices share a single public IP. By assigning a unique temporary public port to each LAN device’s outgoing request, even if two devices are connecting to the exact same server port, their router-side ports are different—making their session entries unique.
- NAT Session Table State: The router keeps track of active sessions, including timestamps to clean up stale entries (so the table doesn’t get cluttered). For TCP connections, it might also track handshake state (SYN, ACK, etc.) to validate legitimate traffic.
A Quick Example to Make It Concrete
Let’s say you have two LAN devices:
- Device A (192.168.1.100) sends a request to
203.0.113.5:80using its own random port54321.- Router translates this to
123.45.67.89:10001(router’s public IP + temporary port) and adds an entry to its session table mapping192.168.1.100:54321 ↔ 123.45.67.89:10001for the destination203.0.113.5:80(TCP).
- Router translates this to
- Device B (192.168.1.101) sends a request to the same
203.0.113.5:80using its random port65432.- Router translates this to
123.45.67.89:10002and adds a second unique session entry.
- Router translates this to
When the server sends a response back to 123.45.67.89:10001, the router looks up its session table, finds the mapping to Device A, rewrites the destination IP/port to 192.168.1.100:54321, and forwards the packet. Responses to 10002 go straight to Device B—no mix-ups.
Note on DNAT
You mentioned DNAT specifically—while your scenario focuses on outgoing connections (handled by SNAT + PAT), DNAT works similarly but in reverse (forwarding incoming public traffic to a LAN device). The same five-tuple logic applies: DNAT relies on session tables to track which incoming packets belong to which internal device’s session.
内容的提问来源于stack exchange,提问作者DariushStony

