Todd,

Have now got to the bottom of this, by dedicating a whole public IP address to the internal DSS using static NAT/PAT. It turns out that after the internal DSS (the source DSS on an internal IP address) initiates the replication, that the remote DSS sends an icmp packet back to the source DSS. Once this is allowed, the replication starts fine. The tcp/873 is utterly irrelevant in this scenario.

Surely someone at Open-E knows this perfectly well. Why did I have spend so many hours discovering this for myself?

I hope this post can help someone else...