A system and method (Fig. 2) is described for providing policy-based Network Address Translation (NAT) configurations wherein each user/resource policy (260, 270/210, 220) within a network protection device (230, 240) may use a different set of address translation mappings.