Essentially all you need to do is set the source zone to your internal zone, the destination zone to your external facing zone, the destination interface to be "any", the source address to be your inside subnet/host, the destination address to be your webserver's PUBLIC IP address, the translated source to be your firewalls INSIDE interface address, and the translated destination to be your webserver's PRIVATE IP address.
You can see a better explanation of what's needed here