I think, you need SNAT
SAT wan/all-nets core/wan_ip yourservice, SAT: new destination = yourprivatehost
Allow wan/all-nets core/wan_ip yourservice
If public and private ports are different, use public port in service, set private port in SAT tab
If DFL is not default gw for internal server, use NAT instead of Allow in second rule