Of course it is.
The main issue is that the "Source" for the rule can't be "Any".
You also can't use negation in the NAT rulebase either.
To achieve the desired result, you'll need two rules:
The first rule ensures the internal networks are NOT translated when they connect to the IP address (in this case, AR70).
"Protected Networks" is a group I created with my internal networks.
The second rule says "anyone connecting to AR70 with appear as if it's coming from foo and going to e7".
"All_Internet" should be a preexisting object.
After you add the object to the Translated Source, you will need to need to right-click on it and change the NAT Method to Hide.