When the Cisco Secure Firewall Threat Defense (FTD) device is behind NAT and the real IP is hidden, a NAT ID must be used in the configure manager addcommand. This allows the FMC to uniquely identify and establish communication with the FTD device through NAT traversal. Without the NAT ID, the registration will fail.