I would also like to get this same thing working! If you have two IPs on the trust interface and I am visuizing this right then your public machines will be able to see all the traffic on the private network assuming no switchs just hubs are used! Not sure if the ports on the Netscreen are a switch or a hub....