DNAT in SuSEFirewall2

Ok, I'm fighting with this for hours now. Here is the story: I have a server with a XEN Virtual Machine. The VM uses the address The same server uses two more network cards - one with the IP and one with the IP Now - what I want to do is make a simple port redirection: --> So, all the traffic that jumps into port 80 on gets to the VM and the way back. This is how I tried to achieve this: iptables -t nat -I PREROUTING -p tcp -d --dport 80 -j DNAT --to This doesn't work. Can you give me any clue, any idea, solution - how can I manage to get this working? (Distributions)