Your dstnat rules use in-interface=ether1-wan, while your srcnat masquerade rule uses out-interface=beogrid Since your internet is working, you should probably change your dst-nat rules to use the beogrid interface. Remember, this interface is the IP interface, not the physical interface, so if beo...