Cisco Cisco Firepower Management Center 4000
12-26
FireSIGHT System User Guide
Chapter 12 Using NAT Policies
Working with Different Types of Conditions in NAT Rules
Caution
If a network object or object group is being used by a NAT rule, and you change or delete the object or
group, it can cause the rule to become invalid.
group, it can cause the rule to become invalid.
You can add any of the following kinds of source network conditions to a dynamic NAT rule:
•
individual and group network objects that you have created using the object manager
See
for information on creating individual and group
network objects using the object manager.
•
individual network objects that you add from the Source Network conditions page, and can then add
to your rule and to other existing and future rules
to your rule and to other existing and future rules
See
for more information.
•
literal, single IP addresses, ranges, or address blocks
See
for more information.
The following procedure explains how to add source network conditions while adding or editing a
dynamic NAT rule. See
dynamic NAT rule. See
for
more detailed information.
To add network conditions to a dynamic NAT rule:
Access:
Admin/Network Admin
Step 1
Select the
Source Networks
tab on the rule Edit page.
The Source Network page appears.
Step 2
Optionally, click the
Search by name or value
prompt above the
Available Networks
list, then type a name or
value.
The list updates as you type to display matching conditions. See
for more information.
Step 3
Click a condition in the
Available Networks
list. Use the Shift and Ctrl keys to select multiple conditions,
or right-click and then click
Select All
.
Conditions you select are highlighted.
Step 4
You have the following choices:
•
To match traffic by original source network, click
Add to Original
.
•
To specify the translation value for traffic that matches the translated source network, click
Add to
Translated
.
Alternatively, you can drag and drop selected conditions into the
Original Source Network
or
Translated
Source Network
lists.
Conditions you selected are added.
Step 5
Optionally, click the add icon (
) above the
Available Networks
list to add an individual network object.
You can add multiple IP addresses, CIDR blocks, and prefix lengths to each network object.
Optionally, you can then select the object you added. See
and
Step 6
Optionally, click the
Enter an IP address
prompt below the
Original Source Network
or
Translated Source
Network
list; then type an IP address, range, or address block and click
Add
.