Which destination address shall I specify in a security policy on an FW configured with NAT server

Specify a private address (destination address) in a security policy on an FW. The private address is the one used after NAT Server is performed.
The FW matches packets with server-map entries before enforcing a security policy. After the FW translates destination addresses based on the server-map entries, the FW processes the packets based on the security policy.

