You can deploy the VM-Series firewall on Azure Stack Edge to secure
inter-subnet traffic between applications in a multitier architecture and
outbound traffic from servers within your Azure Stack Edge deployment.
The NAT appliance is required because in Azure Stack
deployments you can't assign a public IP address to a nonprimary interface
or a virtual machine, such as the VM-Series firewall. This NAT appliance
receives inbound traffic and forwards it to the VM-Series firewall.
To deploy the VM-Series firewall on Azure Stack Edge: