To clarify, does this mean that dstnat happens before the firewall rules apply? Do all the NATs apply before the f/w?You need to enable the to port in filter forward chain. Dst nat rule changes packet header but does not allowing the packet to pass the firewall.