Re: easy one guys In terms you NAT you only need one rule: LAN | FTP server | any | Hide IP | = | = Hide IP should be an host object with the IP you want to hide behind. This object should be added on the rule with the option Hide NAT. Of course you need to also worry about routing and possibly ARP, to make sure this IP "comes back" to your firewall. You will need to make sure that the VPN isn't avoiding the NAT rules, so check the VPN community and make sure you haven't prevented NAT (basically untick that box). Hope that works, let me know if you need anything else. |