well, it fiddles with iptables, and this likely interacts badly with the iptables rules generated by SuSEfirewall2. you can hook custom rules to SUSEfirewall2 via /etc/sysconfig/SuSEfirewall2 #FW_CUSTOMRULES="/etc/sysconfig/scripts/SuSEfirewall2-custom" FW_CUSTOMRULES="" but this will probably be tricky with above NAT rules.