Filter Policies
7705 SAR OS Router Configuration Guide 309
action {forward | reject | nat}
action nat [destination ip-address port tcp-
udp-port]
limit
concurrent-sessions number
profile profile-id | profile-name
name policy-name
For the action nat command, destination ip-address and port tcp-udp-port parameters apply 
only to static destination NAT (port forwarding).
The following example displays a policy configuration for source NAT.
config>security# begin
config>security# policy 1 create
config>security>policy# name "inbound policy"
config>security>policy# description "common egress 
policy"
config>security# entry 1 create
config>security>policy>entry# description "Source NAT"
config>security>policy>entry# match
config>security>policy>entry>match# direction zone-
inbound
config>security>policy>entry>match# exit
config>security>policy>entry># limit
config>security>policy>entry># exit
config>security>policy>entry># action nat
config>security>policy>entry># profile 2
config>security>policy>entry># exit
config>security>policy># exit
config>security># commit
The following example displays a policy configuration for static destination NAT.
config>security# begin
config>security# policy 1 create
config>security# entry 2 create
config>security>policy>entry# description "Dest NAT"
config>security>policy>entry# match local protocol udp
config>security>policy>entry>match# dst-port eq 4000
config>security>policy>entry>match# exit
config>security>policy>entry># limit
config>security>policy>entry># exit
config>security>policy>entry># action nat destination 
10.10.10.1 port 4000
config>security>policy>entry># profile 2
config>security>policy>entry># exit
config>security>policy># exit
config>security># commit