Why don't you just create a standard SNAT rule through the UI with Source of your LAN subnet, Destination of GREEN/ORANGE, Service ANY, NAT to Auto? Works fine here in 2.3, without having to go through any gyrations at the command line.
Scott
Doesn't seem to work through the UI.
Can you show step by step how to do this through the UI and confirm it works? I'm also concerned that others on the forum say it "works for me" and assume that those with the problem are doing something wrong. There is a real bug here (more than a few are experiencing the same problem) unless somebody can show how it can be done via the UI.
I'm no noob when it comes to firewalls, I work with a few in my time: pix, netscreen, efw 2.2 (works great by the way). So I'm not sure why this is such a problem in efw 2.3