Dragons! of course I broke something on the way: sticky-addr option for rdr-to to multiple addresses makes sure each src IP is always redirected to the same destination IP for stupid webapps mostly