In your host definition for the device, change the interface back to the default of Any. Binding to a specific interface is generally considered bad and will block traffic that you want to allow, due to the way the setting works.
Also, make certain that you are testing the DNAT from a host out on the internet and not from your LAN.
__________________ ACE v8/SCA v9.3
...still have a v5 install disk in a box somewhere.
PS, If you select Automatic firewall rule you do not need to create the firewall rule and no you will not see it in the firewall rule section but the firewall will pass the trafic