If you have NAT already configured, you must open proper ports, for example if you are mean by connecting a ssh, do on NAT machine:
Code:
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 22 -d $IP_OF_NAT_MACHINE -j DNAT --to $IP_OF_SSH_SERVER:22
iptables -A FORWARD -i eth0 -o eth1 -p tcp --dport 22 -d $IP_OF_SSH_SERVER -j ACCEPT
Where $IP_OF_NAT_MACHINE and $IP_OF_SSH_SERVER are yours IP addresses and eth0 is your WAN port (where ssh clients are connecting) and eth1 is LAN (where ssh server is connected).