hello silver_surfer

before your kind response i have solved the problem. and for the sake of documentation here are the things i did:
1. transferred lan connection of 172.xxx.xxx.xxx to wan_2_ip instead of lan_172_ip.
2. created another object, wan_2_ip
3. ARP publish this wan_2_ip to wan
3. made route to this new entry: core wan_2_ip metric:0
wan 172.24.0.0/16 metric:100
4. made SAT rule with dest IP going to my private server IP: 165.158.xxx.xxx
5. made corresponding Allow rule
I tried calling technical support in our area via dlink singapore but got lost in translation

. the Dlink-USA website has a FAQ which gave me the idea about multiple IPs for wan. so now i have both 192.168.xxx.xxx and 172.24.xxx.xxx series as my public ips. and my citect server is now the single computer connected at the protected side of the firewall, being now communicated outside wan at different subnets..
anyway, thanks silver_surfer...
