Sophos can do following.
src_address-any destination_address-public_ip1 service-port 6880
Change source to - public_ip2
Change destination to - public-ip in internet
public_ip1 and 2 are in same subnet on the firewall.
So traffic comes in on port and is redirected to go out to a public ip in untrust.
How can I achieve this with ssg5.