:> You are aware that only the first packet of a connection is processed in
:> the nat table, right? The rest will automatically get whatever action
:> was taken on the first packet, but wont be seen by any rule in the nat
:> table.
:Actually I wasn't aware of this despite seeing this with what was logged.
:Thank you, I truly am a n00b

I highly recommend Oskar Andreasson's excellent _IPtables_Tutorial_,
available in several formats from .

