How to kill DNAT'ed connection

Hi again,

Another problem. I have set up a firewall rules to have my router DNAT
some destination IPs and Ports to another. There are also some scripts
used when the client is authorized (connected with authorization
software) and disconnected to bring up forwarding (routing for its IP)
and some DNATs for internal servers.

When the client disconnects, the rules are deleted and new connection
are being rejected. But the problem is that existant DNAT'ed connection
are continue to operate.

That has raised a question: How to kill DNAT'ed connection?

...or there are any other suggestions/technics?

Pokotilenko Kostik <casper@meteor.dp.ua>

