I have a machine on the DMZ. Works beautifully but there is a big problem. Occasionally we want to allow this host to hit the Internet and then later close it back off. The problem is, to make this happen I am having to enable a NAT that breaks what is already working (users hitting it from the outside and the host itself talking to private nets on the other side of the firewall). I do not want this box to NAT when it goes across the firewall to other local nets here. I want it to NAT ONLY when it goes to the Internet. I can't make this happen.
This thread was automatically locked due to age.