Internal access for NAT

I have an external ip NATed to but when another
workstation behind the firewall tries to connect to they are
unable to connect. Here is my little nat:

$IPTABLES -I PREROUTING -p tcp -t nat -d --dport 80 -j DNAT --to
$IPTABLES -I PREROUTING -p tcp -t nat -d --dport 443 -j
DNAT --to
$IPTABLES -I FORWARD -p tcp -i eth0 -d -m state --state NEW -j
$IPTABLES -I FORWARD -p tcp -o eth1 -d -m state --state NEW -j

What do I have to add to get an internal machine to access
Some answers to obvious questions:
Forward NAT works I can connect from the outside to
Internal access to the internal ip works, I can connect to

Thanks for your help.


