Got it,
So, is your current policy a simple Permit policy or have you called NAT in it? ( Trust to HTT, permit)
Easiest solution I can think of:
- move trust interface to Route mode
- Configure 2 policies:
a. Trut to HTT, internal machines to server subnet, permit
b. Trust to HTT, Any Any Any permit, NAT-SRC, use interface IP