Port forwarding without 'MASQUERADE' may cause problems (since the source-destination at seen endpoint appears asymmetric then). Best practice: to avoid this is when using part forwarding simply to configure
iptables -t nat -A POSTROUTING -j MASQUERADE
for having MASQUERADE unconditionally...