Fixed ...
After a bit of fiddling around (reading out of date manuals! Cisco can't you at least update your manuals!)
The answer is in Firewall -> Access Rules
Add rule
Connection Type - Inbound WAN > LAN
Action - Always Allow
Service - Any
Source IP - Any
Send to Local Server (DNAT IP) -
Use Other WAN (Internet) Address - Enable
WAN (Internet) Destination IP -
It's also possible to fix the outbound IP address using rules:
Connection Type - Outbound Lan > WAN
Action - Always Allow (or you can schedule it)
Service - Any (or you can allow specific services)
Source IP - Any
Destination IP - Any
Use this SNAT IP Address - Enable
SNAT IP -