i beleive that DNAT comes before packet filter... so wouldnt that be redundant? unless there is another rule in place to explicitly reject or drop, i dont think any packet filter rule needs to be there. dnat should be fine.
i beleive that DNAT comes before packet filter... so wouldnt that be redundant? unless there is another rule in place to explicitly reject or drop, i dont think any packet filter rule needs to be there. dnat should be fine.