passive
This is true with all NAT or Firewalled servers.. I have mine on an outside address, but still have to open ports because we're running a Firewall on that box as well.. to prevent little kiddies Packet crap, its annoying to have to do, but will save your bacon in the long run.
|