I would prefer to add support for actions in the masq file like I did
> in the mangle file. Inline actions provide a superset of the
> functionality of macros.

I don't worry at all. I'm fully confident that soon enough, you'll come up
with a well designed and evolutive way to make this easier :-)

> This is an inconsistency in iptables that shows through in Shorewall,
> but I can map '-' to ':' in DPORT and SPORT columns.

It never crossed my mind to think that it was Shorewall's fault :) A simple
"man iptables" clearly shows the culprit.

