Firewall rules

Hi all, I'm new to Tipping Point, coming from a Cisco FWSM. I've got a rule for inbound traffic on port 80 & 443 to a specific externally facing address, and a corresponding Destination NAT to reach the internal address.


The rule doesn't work unless I also include the internal destination address in the rule. So now the rule says any source zone, any source address, any destination zone, internal and external destination addresses, tcp 80 & 443 etc


In Cisco land, and in anything I've ever understood about this, the procedure is to allow traffic to pass through the external interface and then NAT it, which sets up bidirectional communication.


Can anyone see what I'm doing wrong, or is this normal operation in HP land?