I have installed Ubuntu server, when NAT is configured on the router it is then directed to the Ubuntu server. All IP access records in webserver logs, SSH and all other accesses are in the name of the router. Not in the name of the client’s public IP.
The main scenario is following (I will put it with below test rig information, in order to be easier to follow, please don’t mind the non-public link IP):
Yeah, if you have a fixed/static WANIP, then you need to delete that first rule, its getting in the way.
The fourth rule below is just a duplicate of the second rule, and should be removed as well.
You should only need two rules.
Question: Is there a reason on the SOURCENAT RULE, why you feel the need to stipulate the src-address???