Use a global -m conntrack --ctstate DNAT rule to accept all port forwards of a given...