I figured it out myself. Is there a more descriptive explanation of all of the firewall options other than the existing 2.9 docs? I pieced together the answer by looking through other forum posts, but (unless I am not seeing it) a simple "port forwarding" example in the docs would have solved it immediately. Not that the MT guys don't have a million more important things to document
Anyway, I set it up like this:
0 I chain=dstnat in-interface=pptp-in1 protocol=tcp dst-port=80 action=dst-nat to-addresses=10.100.3.1 to-ports=8080
Interestingly, the "I" comes up next to the rule when the pptp user is not connected. I guess it is invalid since the tunnel is not up.
Is this how this should be done?
Also, does pptp work correctly in 2.9.10?
It seems that periodically (or soon after I added the firewall rule) it decided to not route traffic to the hotspot after their tunnel would be closed. Then if I reconnected the tunnel, it routed traffic again. I had to reboot the router, and then it seemed to work fine. It has not exhibited the problem since the last reboot.
Anybody heard of a problem like this?
Also, can more than one person use the same pptp settings (user/pass) at the same time. Is that what the "only-one=no" allows?