Re (2): routing

> You also need to do masquerading. That you don't is the reason why no
> answers get back to host 1.

My network has masquerading.  Some of notes configuration might help.

