I'm only a noob myself, but I think you're missing some inbound rules in the forward chain, something like: add chain=forward comment="port-forward tcp/3389 (ip after dst-nat)" dst-address=192.168.0.6 dst-port=3389 protocol=tcp You've set up the inbound NAT translations, you just haven't ...