Thanks for the suggestions sten and tgrand. Since the connection is initiated by the clients, the src-nat idea with marking allowed me to simplify the individual src-nat rules. I could not find a way to do it with less than 1 src-nat rule per client IP. If anyone knows of a more elegant way to do th...