Cisco Cisco Firepower Management Center 4000

Page of 1844
 
12-26
FireSIGHT System User Guide
 
Chapter 12      Using NAT Policies 
  Working with Different Types of Conditions in NAT Rules
Caution
If a network object or object group is being used by a NAT rule, and you change or delete the object or 
group, it can cause the rule to become invalid.
You can add any of the following kinds of source network conditions to a dynamic NAT rule:
  •
individual and group network objects that you have created using the object manager
See 
 for information on creating individual and group 
network objects using the object manager.
  •
individual network objects that you add from the Source Network conditions page, and can then add 
to your rule and to other existing and future rules
See 
 for more information.
  •
literal, single IP addresses, ranges, or address blocks
See 
 for more information.
The following procedure explains how to add source network conditions while adding or editing a 
dynamic NAT rule. See 
 for 
more detailed information.
To add network conditions to a dynamic NAT rule:
Access: 
Admin/Network Admin
Step 1
Select the 
Source Networks
 tab on the rule Edit page.
The Source Network page appears.
Step 2
Optionally, click the 
Search by name or value
 prompt above the 
Available Networks
 list, then type a name or 
value.
The list updates as you type to display matching conditions. See 
 for more information.
Step 3
Click a condition in the 
Available Networks
 list. Use the Shift and Ctrl keys to select multiple conditions, 
or right-click and then click 
Select All
Conditions you select are highlighted.
Step 4
You have the following choices:
  •
To match traffic by original source network, click 
Add to Original
.
  •
To specify the translation value for traffic that matches the translated source network, click 
Add to 
Translated
.
Alternatively, you can drag and drop selected conditions into the 
Original Source Network
 or 
Translated 
Source Network
 lists.
Conditions you selected are added.
Step 5
Optionally, click the add icon (
) above the 
Available Networks
 list to add an individual network object.
You can add multiple IP addresses, CIDR blocks, and prefix lengths to each network object.
Optionally, you can then select the object you added. See 
 an
 for more information.
Step 6
Optionally, click the 
Enter an IP address
 prompt below the 
Original Source Network
 or 
Translated Source 
Network
 list; then type an IP address, range, or address block and click 
Add
.