...The DNAT rule does that; however, after authentication, users can get out using all protocols permitted by the firewall *except* http which continues to be routed to 192.168.1.1
What I'm puzzling over is whether or not I can, on a per-ip basis, override this rule. I'm beginning to think that...