Hi,
I've got an e-smith box at a different location from where I normally work.  For purposes of discussion - call the remote location "Branch", and my office "HQ"  
I need to administer the "Branch" firewall/server over the internet, but don't want it "wide" open - I wanted to limit it to the address range at HQ.  I can SSH to Branch from HQ, but the Web interface doesn't work - I get "forbidden".
I tried activating the "additional local networks", but that has side affects at that location - I.E. when the windows users need to get to resources at HQ, it doesn't work.  I'm guessing, but,I think, from reading the masq file in etc/rc.d/init.d that it is trying to route directly between the local net and the HQ address range on the internet without using masq'ing.
so, How is the best way to allow administration without breaking everything else?
Eventually, I'm going to get VPN going, but (because of HQ issues) that may be months away.
Thanks
Richard