NOTE: If the outbound NAT address is different than the primary interface address you need to specify the NAT address as "Source Address". This is probably the case in clustered setups with CARP.
Isn't it more logical to make the proxy listening on for example 192.168.1.1 f.e., if this is considered the internal gateway on the LAN side ?