See an example topology and a destination NAT rule for a virtual wire destination NAT
example.
Where Can I Use This?
What Do I Need?
NGFW (Managed by PAN-OS or Panorama)
Clients in the Untrust zone access the server using
the IP address 198.51.100.100, which the firewall translates to
192.0.2.100. Both the NAT and security policies must be configured
from the Untrust zone to the Trust zone.