Title: NAT / PAT & Firewall rules
bit of a newbie question, but this operates differently to what i'm used to.

It would appear that when passing traffic through the firewall it goes through the following path

Is this as expected?  I'm used to it being the Firewall allows connection to the external IP and then gets passed to NAT to redirect.

I have also struggled with PAT, when using PAT what do I enable on the Firewall as the destination IP & port?  Is it the IP/Port pre-NAT or post-NAT?

I'm sure this is noted somewhere but I just can't find it written as a simple flow of how the traffic is processed and am struggling to get a working system in this way?

Thanks for any guidance.