Thanks, that helps. I had done some more (re)reading and was begging to come to that conclusion. So basically, for my simple SOHO router situation, a packet is either destined for the router itself (ping, port scan attempts, etc) which "input" would apply to, or it's dst-nat'ed in which ca...