And why is there a LOG option in NAT rule when it is good for nothing?
"modulate state" works only for tcp - when i use that i have to multiply my rules, one for tcp, one for udp, icmp ..