Tood, I did reply to this thread before, but it seems that it was not accepted, so here goes again...
Please can explain why port 873 should be open to allow traffic from the public to reach the DSS on an internal network when it is the internal DSS that is replicating with a DSS on a public network. This just does not make sense. At the moment, it seems that I will have to configure a generic Linux with rsync running and use this as a backup destination rather than DSS, but I would prefer to use another DSS for this role.