$ 0 0 when your doing manual port forwarding DNAT is done before it hits the firewall. So you need to add a firewall fule allowing the local ip address.