Software Secure Firewall Threat Defense
Platform Secure Firewall Threat Defense Virtual
Activity Onboard

Translate a Pool of Inside Addresses to a Pool of Outside Addresses

Before you begin

Create a network object for the pool of private IP addresses you want to translate and create a network object for the pool of public addresses you want to translate those private IP addresses into.


 

For the ASA FTD, the network group that defines the pool of "translated address" cannot be a network object that defines a subnet.

When creating these address pools, use Create or Edit a Firepower Network Object or Network Group for instructions.

For the sake of the following procedure, we named the pool of private addresses, inside_pool and name the pool of public addresses, outside_pool.

Procedure

1

In the left pane, click Security Devices.

2

Click the Devices tab to locate the device or the Templates tab to locate the model device.

3

Click the appropriate device type tab.

4

Select the device you want to create the NAT rule for.

5

Click NAT in the Management pane at the right.

6

Click > Network Object NAT.

7

In section 1, Type, select Dynamic and click Continue.

8

In section 2, Interfaces, set the source interface to inside and the destination interface to outside. Click Continue.

9

In section 3, Packets, perform these tasks:

  • For the Original Address, click Choose and then select the inside_pool network object (or network group) you made in the prerequisites section above.

  • For the Translated Address, click Choose and then select the outside_pool network object (or network group) you made in the prerequisites section above.

10

Skip section 4, Advanced.

11

For an FDM-managed device, in section 5, Name, give the NAT rule a name.

12

Click Save.

13

Review and deploy now the changes you made, or wait and deploy multiple changes at once.