Address translation is configured as part of the Firewall Policy using NAT rules.
NAT rules are configured on the IPv4 NAT and IPv6 NAT tabs in Firewall Policy and Firewall Template Policy elements. Firewall Sub-Policies cannot contain NAT rules.
Note: NAT rules are applied only after a packet matches an Access rule and is allowed by the firewall. The Access rule must have connection tracking enabled (default).
The following illustration shows a NAT rule that has just been inserted into a policy. The Source, Destination, and
Service cells are set to <None> and they must be changed to something else for the rule to match any traffic. The Used
on cell is also used for traffic matching: you can add specific Firewall elements to this cell to make the rule valid only on those firewalls, or you can leave it to the
default ANY to make the rule valid on all firewalls where the policy is installed. The columns are in the default order, but you can drag and drop them to your
preferred order.