How to only translate selected ports:

If you only want to translate selected ports (f.e. http) and leave the rest intact, you may use ipchains to fwmark a class of packets. Suppose you did and all the packets from destined for port 80 are marked with marker 0x1234 in input fwchain. In this case you may replace rule #320 with:
320:	from fwmark 1234 lookup main map-to
and translation will only be enabled for outgoing http requests.