James, you don't say if you need to forward one port or all ports to that single 
machine. There is no way to forward from a single port on the firewall to *all* ports 
on the target host. You can, however, forward individual ports: say from port 8000 on 
the firewall to port 80 on the target host.

I did this successfully providing external SSH access to a collection of hosts on a 
private network. However for this to work, the hosts on the private net also need to 
be doing SNAT back out through the firewall.

Kirk Bocek

