I have a NAT question for everyone. At work i have a single static IP address that all of the computers in the LAN uses for the outside world. My firewall is also acting as a dns server. Question 1: When i try to ssh in to a computer from the outside world it follows the first rule. But when i change ssh to listen to a certain address and port it still defaults to the first rule? Question 2: if the DNS server was running on a server behind the firewall would this help sloves this problem? thanks john