Firewall has rules to DNAT incoming traffic to a port on a DMZ box.
iptables -t mangle -A FORWARD AND iptables -t nat -A PREROUTING ???