As the Sophos RED is not a “normal” router, you can simply not make a firewall rule, that allows ex. port 5801/tcp to a webserver you have behind a RED location, and then use the RED’s WAN IP, but what you can do, it to use your UTM’s WAN IP and make a FULL NAT rule to the webserver behind the RED.
This is simple achieved by making this one Full Nat Rule:

The “Change the source to:” has to be the “Internal (adresses)” interface of the UTM and not the RED.
HTH 🙂


