@blancmange Thanks for the reply! The only difference I’m seeing is that for the wan zone you accept forwarding. Isn’t this circumventing the NAT? Feel free to correct me if I’ve misunderstood.