If the 300 has its own internet link, it will send the reply back out the internet link, and as such comms will fail.
If it does not have an internet link and is internal behind the 530, you will need to port forward on the 300 as well.
If the link between the 530 and the 300 is over an IPSec tunnel, the phase two networks will have to include the source IP.
An easy way to achieve these options is to also source nat the connection on the 530 so that it appears to come from the 530 LAN interface.
hope this helps.