All these questions are arising mainly because I so far 'feel' that, maybe, all that iptables should have done was provided us with a bare minimum set of hook-points (like, e.g. pre- and post-routing hooks), and an ability to do arbitrary packet processing (in any sequence that we deemed fit and any number of times - a custom state machine) instead of stipulating the detailed sequence of steps as