I will soon be attempting to get IPP up and running on a server behind

our BM37sp2 firewall. I plan on using generic proxies to funnel the appropriate traffic (ports 80, 443 and 631) from a secondary IP on
public interface to the ip of the private-side IPP server.

However, I am concerned that I will have problems with ports 80 and
filters and rules as they already have filters set for the http(s)
service. These are statefull filters from public to public so that
proxy server can pass the traffic. So how do I design filters to
non-statefull traffic from public to private (and vise versa) while
keeping my proxy traffic running?? Will this be secure (assuming IPP

services is secure)??

Thanks much, Chris.