Please consider the future inclusion of Divert Sockets to the iptables package (and to ipchains, and kernel). Divert sockets look fairly cool. http://sourceforge.net/projects/ipdivert/ http://www.anr.mcnc.org/~divert/index.shtml
This would need to be in the kernel first before we'd ship it in iptables.
Well, the divert sockets code went nowhere fast. The homepage is a 404, the sourceforge site hasn't seen any updates since 2003, there is no 2.6 version. Thankfully, it looks like Netlink Sockets will provide equivalent functionality. Closing this one as WONTFIX.