Is the WAN a DHCP interface? Is the host you're trying to connect from in the WAN subnet? If yes and yes, try 'disable reply-to' in the firewall rules.