https://support.sophos.com/support/s/article/KB-000035607?language=en_US
Overview
Administrators can NAT the traffic generated by the firewall so that the IP addresses of its interfaces are not exposed or change the NAT'd IP for traffic going to a set destination.
Product and Environment
Sophos Firewall
Translating the generated traffic
- Open the command line of Sophos Firewall.
- Go to Option 4. Device Console and run the following command:
set advanced-firewall sys-traffic-nat add destination <destination IP address> snatip <SNAT IP address>
Note: The destination host is 172.16.16.5 and the IP address that traffic is NATd to is 192.168.2.1.