Firewall Access Policy Setup for Private IP to Public IP

I am attempting a work around and not sure if it is the best way, but I am trying to remove a NT4 server from our network, but still allow access to it only from our network.  The reason is I want to raise the secuirty level on our domain controller and once I do, access to NT4 apparently will be lost in our private network... so I was going to use a public IP to access NT4 server.

I have a public IP address I have routed to the Private NT4 Server IP address.  I can access the server as expected, but so cant everyone else.

I want to create an access rule to allow our network of Private IP addresses to access the public IP address of the NT4 server, but block all other users.

Can someone point me in the right direction?
Can you clarify your question:

Only one machine in your local network can access the NT4 machine, but others can't?  Is your private network using NAT?


I will try to clarify...

I have NT4 server set to Private IP xxx.5 in our network.

I have a public IP routed to the NT4 IP using our Router which I believe uses NAT... since I requests in and out of our network appear to come from the same public IP xxx.138

If I set a policy on the router to allow all traffic to access the NT4 public IP, I have no issues accessing the server (good and bad).

I now want to setup a policy that allows access from our Private IPs to the Private IP of the NT4 server, using the public NT4 IP.

The problem I am finding is that all traffic appears to come from the name xxx.138 IP that the router uses.  So, allowing and blocking access affects everyone else.

Maybe I need to setup another interface on another port on the router, instead of using the port interface assigned to xxx.138 ?

