$ 0 0 I believe I've seen somewhere that dnat happens before going through the firewall rules. maybe it is something to do with that.