We have an SSG 5. Both the default Trust and Untrust interfaces use Public IPs are configured in Route mode, so no NAT happens at all. We'd like to make use of a spare port to have some machines that ...