I think I might have answered my own question re getting ipmasq to recalculate the firewall rules when a connection is made or dropped. I spotted on a website last night that ipmasq gets started early in the boot sequence (init 2 I think) and so getting the rules recalculated when a connection is made 'updates' it. Can you confirm that I am right? Thanks Mike