Hi, This would be a destination NAT, so you would configure a NAT rule that has an original packet source & destination zone of 'outside' , destination address of your public IP and the port the outside user is connecting to. You would then configure in the translated packet part of the rule the destination side, put in the private IP & port that the traffic is to be translated to. You can watch this video to help as well: https://live.paloaltonetworks.com/t5/Videos/How-to-Configure-Destination-NAT-on-the-PAN-OS-UI/ta-p/57211 For the security rule, you will need to use the source zone of the pre-NAT zone, in this case 'outside' and the destination zone will be the post-NAT zone, DMZ. hope this helps, Ben
... View more