Why would you double-NAT?

If the Draytek does NAT, it should have a private IP (ie - 192.168.0.1) on the inside. Configure your inside firewall to route, with 192.168.0.2 on the outside and another private network address on the inside. This effectively creates a DMZ whether you want it or not, but prevents the double-NAT situation. I have used ISA or TMG firewalls in such a configuration in the past when business Internet service was not available. Have the Draytek forward all ports/protocols to the inside firewall and let that device forward to or publish inside servers as appropriate.

My earlier comment was more to using a home-brew firewall in a business environment and the potential exposure to you. With commercial equipment available used/refurbished at $200 US, why build a PC (even an old desktop), take time to install the O/S and iptables module, and subject you and your company to the potential risk that everything you've used and configured is 100%? If you choose a well-known and respected commercial product, the customer cannot bring into question the integrity of the design. Your liability exposure is limited to the configuration of the device, and even then your exposure is minimal unless you grossly misconfigure it.

We use refurbished equipment at many smaller businesses to provide enterprise quality at bargain prices. We buy an extra device or module and pay for it through maintenance contracts to insure same-day recovery for clients, even though in 5 years we've not had a single failure. We also maintain copies of any config files in-house to pre-load the spares to minimize on-site time. It might take 30 minutes to set up and load it at the office, but when we walk in and swap the box and things work, the client "sees a duck" - moving gracefully on the water but doesn't see how hard we're paddling below. It's an appearance that breeds confidence.. other vendors arrive and take an hour or more to install and configure a replacement, we do it in 10-15 minutes because of the back-office preparation and standards across clients.

Another perspective is control - the more you have, the less risk you take on. Control comes through standards across clients, recognized equipment, and learning how to "say no - but..." when appropriate. Also, if a new client has technology that we don't consider appropriate, we'll suggest a replacement. If they choose not to, they must sign a "hold-harmless" document stating that we don't recommend that device or configuration and cannot be held responsible for any effect that may result from its continued use.

Glenn
_________________________
Actually I am a Rocket Scientist! \:D