Configure NAT for threat defense

The NAT policy is a shared policy. Assign it to devices that need similar NAT rules.

Each rule applies to a device if its interface objects (security zones or interface groups) include an interface for that device. When the interface objects include one or more interface for the device, the rule is deployed to the device. You can target subsets of devices within a shared policy by designing interface objects accordingly. Rules using the "any" interface object apply to all devices.

If you change an interface type to one not valid for NAT on an assigned device, the policy marks the interface as deleted. Click Save in the NAT policy to automatically remove the interface from the policy.

You can configure multiple NAT policies if groups of your devices require significantly different rules.

Procedure


Step 1

Navigate from Security Cloud Control to Cloud-Delivered Firewall Management Center

Step 2

Select Policies > Network policies > NAT.

  • Click New Policy > Threat Defense NAT to create a new policy. Give the policy a name, optionally assign devices to it, and click Save.

    You can change device assignments later by editing the policy and clicking Policy Assignments.

  • Click Edit (edit icon) to edit an existing threat defense NAT policy. Note that the page also shows Firepower NAT policies, which are not used by Firewall Threat Defense devices.

    If View (View button) appears instead, the configuration belongs to an ancestor domain, or you do not have permission to modify the configuration.

Step 3

Decide what kinds of rules you need.

You can create dynamic NAT, dynamic PAT, static NAT, and identity NAT rules. For an overview, refer to NAT types.

Step 4

Decide which rules should be implemented as manual or auto NAT.

For a comparison of these two implementation options, refer to Auto NAT and Manual NAT.

Step 5

Decide which rules should be custom per device.

Because you can assign a NAT policy to multiple devices, you can configure a single rule on many devices. However, you might have rules that should be interpreted differently by each device, or some rules that should apply to a subset of devices only.

Use interface objects to control on which devices a rule is configured. Then, use object overrides on network objects to customize the addresses used per device.

For detailed information, refer to Customize NAT rules for multiple devices.

Step 6

Create the rules as explained in these sections.

Step 7

Do these to manage your NAT policy:

  • To edit the policy name or description, click in those fields, type in your changes, and click outside the fields.

  • To view only those rules that apply to a specific device, click Filter by Device and select the desired device. A rule applies to a device if it uses an interface object that includes an interface on the device.

  • To view any warnings or errors in the policy, click Show Warnings, then choose a Device. Warnings and errors mark configurations that could adversely affect traffic flow or prevent the policy from deploying.

  • To change the devices to which the policy is assigned, click the Policy Assignments link and modify the selected devices list as desired.

  • To change the number of rules displayed on the page, use the Rows Per Page drop-down list.

Step 8

Do these to manage your NAT rules:

  • To add a rule, click the Add Rule button.

  • To edit a rule, click the Edit (edit icon) icon next to the rule.

  • To delete a rule, click the Delete (delete icon) icon next to the rule.

  • To enable or disable a rule, right-click the rule and choose Enable or Disable from the State menu. You can temporarily disable a rule without deleting it using these controls.

  • To select more than one rule to enable, disable, or delete, click the checkbox for the rules, or the checkbox in the header, then perform the action.

Step 9

Click Save.

You can now go to Deploy > Deploy and deploy the policy to assigned devices. The changes are not active until you deploy them.