RMerlin,
I'm afraid that's not the case. I ain't too familiar with the ctstate matching, but from what I gather the last rule would only match and accept those packets that have already been DNAT'ed per conntrack's state entries.
I have observed in my tests that none of these FORWARD...