If the firewall is using NAT (Network Address Translation) along with PAT (Port Address Translation), then Proxy mode should be used for all connections that use this firewall. The firewall must be configured for external connections to ports 80 (non-SSL) or 443 (SSL), 8080 and 2400 to be forwarded to CC-SG (since the PC Client will initiate sessions on these ports).
Note: It is not recommended to run non-SSL traffic through a firewall.
Connections using the firewall must be configured to use Proxy mode. See Connection Modes: Direct and Proxy. CC-SG will connect to the various targets on behalf of the PC Client requests. However, the CC-SG will terminate the PC Client to Target TCP/IP connection that comes through the firewall.