The potential bug you found is definately a possiblity. Try this, like I did, to see more: On the rule that you copied, and is now a masq rule with no to-ports listed... change it back to dst-nat and you will see that it STILL HAS YOUR OLD DST-NAT TO-PORT VALUES LISTED!!! So, the masq rule is defin...