Depends on your requirement and where are you Natting.
1- Incoming traffic from internet will be Natted at edge router.
2- Within two domains you can do it on either of them.
3- Between different segments like LAN and DMZ you do it on FW only.
So it depends on your requirement and location where you want to filter the traffic and apply rules.
Regards
Naveen