I suggest you to use Arno's IPTables Firewall Script. It supports NAT as well as it is a stateful firewall....
Separate names with a comma.