Nat Pool
set pool src-nat-pool-1 address 221.119.251.0 221.119.251.254
Nat Rule
[edit security nat source]
set rule-set rs1 from zone trust
set rule-set rs1 to zone untrust
set rule-set rs1 rule r1 match source-address 0.0.0.0/0
set rule-set rs1 rule r1 match destination-address 0.0.0.0/0
set rule-set rs1 rule r1 then source-nat src-nat-pool-1
Substitute a specific ip address range for the source-address if the translation is limited to only certain subnet in the trust zone. This rule will apply to all adress from the trust zone to the untrust zone.
Security policy
[edit security policies from-zone trust to-zone untrust]
set policy internet-access match source-address any destination-address any application any
set policy internet-access then permit
Substitute specific addresses and ports in both the trust and untrust zones as needed. This rule permits all traffic ip addresses on any port.
If you address pool were in the SAME subnet as the external interface you would also need to add proxy arp. But you specify here that the address pool is an extended range. Naturally, the routing for this subnet must sent the traffic to the SRX or the return traffic for the nat address will never hit the SRX.