Traffic Source: Internal (Network)
Traffic Service: {new service definition instead of HTTPS}
Traffic Destination: Internal (Address)
NAT mode: DNAT (Destination)
Destination: {a non-existent IP}
Destination Service: {leave blank!}
Traffic Source: Internet
Traffic Service: HTTPS
Traffic Destination: External (Address) [{name of additional address}]
NAT mode: DNAT (Destination)
Destination: {Host defnition for internal server}
Destination Service: {leave blank!}
Traffic Source: Internal (Network)
Traffic Service: {new service definition instead of HTTPS}
Traffic Destination: Internal (Address)
NAT mode: DNAT (Destination)
Destination: {a non-existent IP}
Destination Service: {leave blank!}
Traffic Source: Internet
Traffic Service: HTTPS
Traffic Destination: External (Address) [{name of additional address}]
NAT mode: DNAT (Destination)
Destination: {Host defnition for internal server}
Destination Service: {leave blank!}
The Remote Access servers not based on IPsec cannot be bound to an interface.
If you really want to block connection internally with the SSL VPN,
Check out Astaro Gateway Feature Requests - you can vote for one-time passwords and page-knocking capabilities.