> I didn't know you couldn't use DNAT if you used Masquerading.  Are you
> sure?

think about it. masquerade is used when you have a single dynamic IP.
if you had multiple IPs, then you don't have a dynamic IP connection,
which means that you should be using SNAT. and with a single IP, DNAT
is less interesting. it is possible (and i do it), for instance, to
redirect port 22004 to my machine .4, port 22, but even though that
uses the DNAT chain, it's really just port forwarding or relaying...

