$ 0 0 DNAT happens BEFORE firewall. Firewall does not block DNAT. Associated firewall rule for DNAT must match on translated addr/port.