Let's say I have a service running on privateIP on privatePort and wish to enable connections to it via publicIP on publicPort. That easy, we just set up a dst-nat action on dstnat chain in the NAT table from dst-address=publicIP dst-port=publicPort to to-address=privateIP to-port=privatePort. And n...