Re: reply back to public NAT behind FW issue "For testing, they want to be able to get to both the internal (private) IP of the WWW server, and also to the Public-NAT IP from behind their FW, so they can simulate what their customers will see." This won't accomplish anything of value. Tell them to put in a cable modem or DSL modem and use it to test. The only way to see what people on the Internet see is to be on the Internet. Making their rulebase more complex is making it easier to make a mistake in configuration. Ray |