> For the complete documentation index, see [llms.txt](https://ccie-sp.gitbook.io/ccie-spv5.1-labs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ccie-sp.gitbook.io/ccie-spv5.1-labs/labs/nat/nat64-stateful-w-static-nat.md).

# NAT64 Stateful w/ Static NAT

Load **nat64.lab1.init.cfg**

```
#IOS-XE
config replace flash:nat64.lab1.init.cfg

#IOS-XR (XR1 only)
configure
load bootflash:nat64.lab1.init.cfg
commit replace
```

<figure><img src="https://3072390383-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkUz2C3GqnZcWhoVL6jfk%2Fuploads%2FsdAqd7G0V4BwinupJJga%2Fimage.png?alt=media&amp;token=838aec06-d52e-4e83-b26c-fc6b3f265bfc" alt=""><figcaption></figcaption></figure>

Configure NAT64 on R6 again. Use the same settings:

* Use 100.1.1.1 as the translated IPv4 address on R6
* Only allow traffic sourced from 2001::/64 to be translated for NAT64
* Use the prefix 64:ff96::/96 for NAT64

Also configure a static NAT so that IPv4-initiated traffic destined for 100.1.2.3 is translated to 2001::5:5:5:5.

## Answer <a href="#d4be6bf5-232a-4ae4-870c-00cb625cf30a" id="d4be6bf5-232a-4ae4-870c-00cb625cf30a"></a>

```
#R6
int GigabitEthernet2.36
 nat64 enable
int GigabitEthernet2.46
 nat64 enable
int GigabitEthernet2.56
 nat64 enable
int GigabitEthernet2.619
 nat64 enable
!
ipv6 access-list NAT64_SOURCES
 permit ipv6 2001::/64 any
!
nat64 prefix stateful 64:ff96::/96
nat64 v4 pool V4POOL 100.1.1.1 100.1.1.1
nat64 v6v4 list NAT64_SOURCES pool V4POOL overload
!
nat64 v6v4 static 2001::5:5:5:5 100.1.2.3
!
ipv6 router ospf 1
 redistribute static
```

## Explanation <a href="#f266a9bb-83d9-4533-8213-489e8f1475e9" id="f266a9bb-83d9-4533-8213-489e8f1475e9"></a>

This is the same lab as before, with one extra command:

```
nat64 v6v4 static 2001::5:5:5:5 100.1.2.3
```

This command creates a static NAT which allows IPv4 hosts to initiate traffic to an IPv6-only host. Traffic to/from 2001::5:5:5:5 will be translated to 100.1.2.3 instead of the 100.1.1.1 overload pool.

R6 automatically adds another static route for 100.1.2.3/32 pointing to the NVI:

<div align="left"><figure><img src="https://3072390383-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkUz2C3GqnZcWhoVL6jfk%2Fuploads%2FG824yAk9gBsmQef34YB2%2Fimage.png?alt=media&amp;token=0d2a2d53-6fb0-49d0-a5ba-d1be543881e7" alt=""><figcaption></figcaption></figure></div>

R6 pre-populates a NAT entry for 2001::5:5:5:5 translated to 100.1.2.3:

<div align="left"><figure><img src="https://3072390383-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkUz2C3GqnZcWhoVL6jfk%2Fuploads%2FyUbGjsnqEczII2MxlvZD%2Fimage.png?alt=media&amp;token=bdb1796b-34a9-494c-9bc6-9eab9dfaac21" alt=""><figcaption></figcaption></figure></div>

If we initiate a ping from XR1, R6 will translate 100.1.2.3 to 2001::5:5:5:5. Additionally, it will use the NAT64 prefix to translate the source address from 192.0.2.1 to 64:ff96::c000:201. This ensures that R5 will direct the traffic back to R6.

<div align="left"><figure><img src="https://3072390383-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkUz2C3GqnZcWhoVL6jfk%2Fuploads%2FnSInGb8MFsHHoO93LpvB%2Fimage.png?alt=media&amp;token=54db5fe7-4652-4027-b45c-ad428cfea041" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://3072390383-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkUz2C3GqnZcWhoVL6jfk%2Fuploads%2F2IcfgfV5kWUec9JU7Amp%2Fimage.png?alt=media&amp;token=a515be88-94f6-4cdb-a465-471bd4bc8dae" alt=""><figcaption></figcaption></figure></div>
