firewall: properly handle negated ports in nat reflection