-
If you want to have all addresses assigned to router (instead of routing them somewhere else), you need to add them all. Unless you’d choose to not add them at all.
-
You do need extra hairpin NAT rule with your other current rules, but with a small change you can get rid of it. See below.
-
Advantage of forwarding only selected ports is that you can be sure that nothing else will pass. The same can be achieved with firewall on target device, but sometimes you may not have enough trust in that, or in device’s admin, so doing it on router is sure way.
-
Your srcnat rule for rest of clients has out-interface=ether1-gateway. If you remove this condition, it will also start working as hairpin NAT rule. Depending on what other config you’ll have, it may or may not cause some problems. For example, if you’d have other networks that should be accessible from 10.0.0.x without NAT (another LAN, VPN, …) it would affect traffic to them. But that could be solved too, for example with accept rule for this traffic earlier in srcnat chain.
-
If your other srcnat rules cover everything you need, you don’t need default masquerade.