In this example, security policies are configured from
the virtual wire zone named Trust to the virtual wire zone named
Untrust. Host 192.0.2.100 is statically translated to address 198.51.100.100.
With the Bi-directional option enabled, the
firewall generates a NAT policy from the Untrust zone to the Trust
zone. Clients on the Untrust zone access the server using the IP
address 198.51.100.100, which the firewall translates to 198.0.2.100.
Any connections initiated by the server at 192.0.2.100 are translated
to source IP address 198.51.100.100.