"other" won't generate any layer2 messages. This can be useful if the IPs are routed to you anyway. If you need to answer with ARP for your VIPs you have to use ProxyARP or CARP.
Try a recent snapshot, FTP should work out of the box now. seems to fix all the problems people were having.
http://snapshots.pfsense.com/FreeBSD6/RELENG_1/
As hoba said, 1:1 NAT is not a security issue unless you want to make it one. If you have as many IP's as internal servers, it's usually preferable to use 1:1 NAT over port forwarding.
From pm discussion, I've confirmed those ports aren't really open on his firewall, and it's behaving as his shown firewall ruleset should, proving it was something to do with the network of the person who scanned him originally.
There is an ftp-helper build in that you can enable/disable per interface for these kind if situations. Besides that no other protocol is proxied to rewrite IPs.
Others have asked about this a few times in the past, and numerous times on the m0n0wall list, and nobody has ever been able to find a solution. It's certainly a desirable feature, if you can find a way to implement it I'm sure patches would be accepted.
You can manually edit the config.xml and exchange the interfacename with the IP-Adress and reupload the config. Just don't touch this pool with the gui again and it should work with the newer versions.
That would be great if you found that solution for me.
Of course changing the internal modem IP to be the same network range as the LAN, eg 10.0.209.2 is not a problem…
I try to stay as far away from Appletalk as possible, but AFAIK trying to to encapsulate it in IP and route it somewhere is much more trouble than it's worth. Most of the old Laserwriters I have seen support IP/LPR printing. Just my 2c, but I think you would be better off getting rid of any Appletalk only devices and getting something made in the last fifteen or so years…
Thanks Hoba,
I enabled "NAT Reflection" then added the Port forwarding as you said and it just works!!!
Then I think I don't need my old firewall box again.
Thanks again to all psSense team. Let me know if there's anything you think I can help.
Tony.